Skip to content
Gurdx

Docs / Platform

Blacklists

Blacklists are lists of values you never want to accept, checked automatically on the endpoints that handle that kind of value.

How blacklists work#

Each blacklist belongs to your account, has a type, can be enabled or disabled and contains any number of items. During a request, Gurdx performs an exact, indexed lookup of the value against the items of your enabled blacklists. If it is found, the response is flagged as blacklisted (the blacklisted field in IP, email and phone results) and the result is treated as high risk.

Values are normalised before they are stored and before they are compared, so you do not need to worry about formatting:

Type Normalisation
ip Canonical IPv4/IPv6 form
email Trimmed, lowercase
email_domain Trimmed, lowercase (e.g. mailinator.com)
phone Digits only, leading zeros removed
customer_id Trimmed, lowercase
card_bin Digits only, first 8
card_country Two-letter code, uppercase

Types and where they apply#

Type What you add Endpoints affected
ip IP addresses geoip, IP lookup, bulk lookup, IP reputation, payment
email Email addresses email, payment
email_domain Domains such as example.org email, payment
phone Phone numbers phone, payment
customer_id Your own customer identifiers payment
card_bin Card BINs (6 to 8 digits) BIN lookup, payment
card_country Issuing country codes BIN lookup, payment

An email is checked twice: once as a full address and once by its domain, so blacklisting a domain covers every address on it.

Effect on scoring#

A blacklist match is a strong signal but Gurdx still returns the whole result. For payment scoring it counts as a detected rule and pushes the score up. For lookup endpoints the blacklisted flag is set, and you can read it in your own code:

const res = await fetch('https://gurdx.cretip.com/api/scoring/email?email=' + encodeURIComponent(email), {
  headers: { Authorization: 'Bearer ' + process.env.GURDX_KEY },
});
const { data } = await res.json();
if (data.blacklisted) {
  // reject or send to manual review
}

Blacklist matches also raise the corresponding event, so they appear in the dashboard and reach your webhooks and chat alerts.

Managing blacklists#

  • Create as many lists as you need, for example one per team or per campaign, and turn a list off to stop it from applying without deleting it.
  • Add items one by one or in bulk from the dashboard.
  • Custom rules with the blacklist action can flag values dynamically. See Custom rules.
  • Team members need the Blacklists permission to change lists.

Tip: Prefer email_domain over many single emails for disposable providers, and card_bin over card_country when you only want to stop a specific issuer.

Warning: Blacklisting a shared IP (a corporate NAT or mobile carrier) can block many innocent customers. Review before adding wide ranges.

Related reference pages: IP reputation, Email scoring, Phone validation, BIN lookup and Payment fraud.

Found a mistake? Tell us on the contact page. Contact