Docs / Platform
Custom rules
Custom rules let you adjust Gurdx results with your own business logic, such as blacklisting a country or overriding a score, without changing your integration code.
What a rule is#
A rule belongs to one endpoint group and has a title, a list of conditions, a match mode and one action. When a request is processed, Gurdx builds the response, then evaluates every enabled rule of that group in the order shown in the dashboard. Each rule whose conditions hold runs its action on the response. Because rules run in order, a later overwrite_score wins over an earlier one.
Rules do not apply to test-mode data in a meaningful way, since test responses are fake.
Match mode#
- Match all: every condition must be true.
- Match any: at least one condition must be true.
A rule with no conditions never matches.
Conditions and operators#
A condition is a field, an operator and a value. Fields are either request inputs (input.*) or values from the response (result.*). The dashboard offers only the operators that fit the field type.
| Operator | Meaning | Field types |
|---|---|---|
equals, not_equals |
Case-insensitive comparison | string, number, country |
in, not_in |
One of a comma-separated list | string, number, country |
contains, starts_with, ends_with |
Text matching | string |
gt, gte, lt, lte |
Numeric comparison | number |
is_true, is_false |
Boolean check | bool |
in_cidr |
IP inside one or more CIDR ranges | ip |
Groups, fields and actions#
| Group | Endpoints | Actions | Action changes |
|---|---|---|---|
ip |
geoip, IP lookup, bulk lookup | blacklist, whitelist |
security.blacklisted |
ip_reputation |
IP reputation | blacklist, whitelist |
threats.blacklisted |
payment |
payment | overwrite_score |
score |
email |
overwrite_score, mark_valid, mark_invalid |
score, isValid |
|
phone |
phone | mark_valid, mark_invalid |
isValid |
bin |
BIN lookup | mark_valid, mark_invalid |
isValid |
iban |
IBAN lookup | mark_valid, mark_invalid |
isValid |
Fields available for conditions, by group:
- ip:
result.ip,result.countryCode,result.continentCode,result.regionName,result.cityName,result.asn.asn,result.asn.name,result.security.isProxy,proxyType,isTor,isBot,isHosting,isRelay. - ip_reputation:
result.ip,result.countryCodeandresult.threats.isProxy,proxyType,isTor,isBot,isHosting,isRelay. - payment:
input.data.action,transaction_amount,transaction_currency,customer_id,customer_email,customer_phone,customer_ip,customer_country,billing_country,shipping_country,payment_type,isDigitalProducts,website_domain, plusresult.scoreandresult.rulesDetected. - email:
input.email,result.domain.name,result.score(0 to 3),isDisposable,isFree,isRoleBased,isEducational. - phone:
input.phone,input.countryCode,result.carrier,result.isValid. - bin:
input.bin,result.info.scheme,type,isPrepaid,isCommercial,country.alpha2,bank.name. - iban:
input.iban,result.countryCode,result.isValid.
Profanity detection, ASN, country and domain lookups do not support custom rules.
Example#
Raise the score for large first-time digital purchases coming from a country you do not serve:
- Group:
payment, match: all input.data.isDigitalProductsis trueinput.data.transaction_amountgreater than 200input.data.billing_countryis not one ofSA, AE, KW- Action:
overwrite_scoreto90
In the API response#
Every response from a rule-capable endpoint contains custom_rules_applied, even when nothing matched:
{
"status": "success",
"data": {
"score": 90,
"custom_rules_applied": {
"total": 1,
"rules": [ { "id": "CR12", "message": "Large digital order from unserved country" } ]
}
}
}
The id is the rule code shown in the dashboard (CR plus the rule number) and message is the rule title. For IP reputation the object sits inside data.threats.
Tip: Use the "Test rule" button in the dashboard to dry-run a rule against sample data before enabling it.
Warning: An
overwrite_scoreormark_validrule replaces what Gurdx computed. Keep conditions narrow so you do not hide real signals.
See also Blacklists and Events and alerts.
Found a mistake? Tell us on the contact page. Contact