Docs / Platform
Blacklists
Blacklists are lists of values you never want to accept, checked automatically on the endpoints that handle that kind of value.
How blacklists work#
Each blacklist belongs to your account, has a type, can be enabled or disabled and contains any number of items. During a request, Gurdx performs an exact, indexed lookup of the value against the items of your enabled blacklists. If it is found, the response is flagged as blacklisted (the blacklisted field in IP, email and phone results) and the result is treated as high risk.
Values are normalised before they are stored and before they are compared, so you do not need to worry about formatting:
| Type | Normalisation |
|---|---|
ip |
Canonical IPv4/IPv6 form |
email |
Trimmed, lowercase |
email_domain |
Trimmed, lowercase (e.g. mailinator.com) |
phone |
Digits only, leading zeros removed |
customer_id |
Trimmed, lowercase |
card_bin |
Digits only, first 8 |
card_country |
Two-letter code, uppercase |
Types and where they apply#
| Type | What you add | Endpoints affected |
|---|---|---|
ip |
IP addresses | geoip, IP lookup, bulk lookup, IP reputation, payment |
email |
Email addresses | email, payment |
email_domain |
Domains such as example.org |
email, payment |
phone |
Phone numbers | phone, payment |
customer_id |
Your own customer identifiers | payment |
card_bin |
Card BINs (6 to 8 digits) | BIN lookup, payment |
card_country |
Issuing country codes | BIN lookup, payment |
An email is checked twice: once as a full address and once by its domain, so blacklisting a domain covers every address on it.
Effect on scoring#
A blacklist match is a strong signal but Gurdx still returns the whole result. For payment scoring it counts as a detected rule and pushes the score up. For lookup endpoints the blacklisted flag is set, and you can read it in your own code:
const res = await fetch('https://gurdx.cretip.com/api/scoring/email?email=' + encodeURIComponent(email), {
headers: { Authorization: 'Bearer ' + process.env.GURDX_KEY },
});
const { data } = await res.json();
if (data.blacklisted) {
// reject or send to manual review
}
Blacklist matches also raise the corresponding event, so they appear in the dashboard and reach your webhooks and chat alerts.
Managing blacklists#
- Create as many lists as you need, for example one per team or per campaign, and turn a list off to stop it from applying without deleting it.
- Add items one by one or in bulk from the dashboard.
- Custom rules with the
blacklistaction can flag values dynamically. See Custom rules. - Team members need the Blacklists permission to change lists.
Tip: Prefer
email_domainover many single emails for disposable providers, andcard_binovercard_countrywhen you only want to stop a specific issuer.
Warning: Blacklisting a shared IP (a corporate NAT or mobile carrier) can block many innocent customers. Review before adding wide ranges.
Related reference pages: IP reputation, Email scoring, Phone validation, BIN lookup and Payment fraud.
Found a mistake? Tell us on the contact page. Contact