Skip to content
Gurdx

Docs / Platform

Custom rules

Custom rules let you adjust Gurdx results with your own business logic, such as blacklisting a country or overriding a score, without changing your integration code.

What a rule is#

A rule belongs to one endpoint group and has a title, a list of conditions, a match mode and one action. When a request is processed, Gurdx builds the response, then evaluates every enabled rule of that group in the order shown in the dashboard. Each rule whose conditions hold runs its action on the response. Because rules run in order, a later overwrite_score wins over an earlier one.

Rules do not apply to test-mode data in a meaningful way, since test responses are fake.

Match mode#

  • Match all: every condition must be true.
  • Match any: at least one condition must be true.

A rule with no conditions never matches.

Conditions and operators#

A condition is a field, an operator and a value. Fields are either request inputs (input.*) or values from the response (result.*). The dashboard offers only the operators that fit the field type.

Operator Meaning Field types
equals, not_equals Case-insensitive comparison string, number, country
in, not_in One of a comma-separated list string, number, country
contains, starts_with, ends_with Text matching string
gt, gte, lt, lte Numeric comparison number
is_true, is_false Boolean check bool
in_cidr IP inside one or more CIDR ranges ip

Groups, fields and actions#

Group Endpoints Actions Action changes
ip geoip, IP lookup, bulk lookup blacklist, whitelist security.blacklisted
ip_reputation IP reputation blacklist, whitelist threats.blacklisted
payment payment overwrite_score score
email email overwrite_score, mark_valid, mark_invalid score, isValid
phone phone mark_valid, mark_invalid isValid
bin BIN lookup mark_valid, mark_invalid isValid
iban IBAN lookup mark_valid, mark_invalid isValid

Fields available for conditions, by group:

  • ip: result.ip, result.countryCode, result.continentCode, result.regionName, result.cityName, result.asn.asn, result.asn.name, result.security.isProxy, proxyType, isTor, isBot, isHosting, isRelay.
  • ip_reputation: result.ip, result.countryCode and result.threats.isProxy, proxyType, isTor, isBot, isHosting, isRelay.
  • payment: input.data.action, transaction_amount, transaction_currency, customer_id, customer_email, customer_phone, customer_ip, customer_country, billing_country, shipping_country, payment_type, isDigitalProducts, website_domain, plus result.score and result.rulesDetected.
  • email: input.email, result.domain.name, result.score (0 to 3), isDisposable, isFree, isRoleBased, isEducational.
  • phone: input.phone, input.countryCode, result.carrier, result.isValid.
  • bin: input.bin, result.info.scheme, type, isPrepaid, isCommercial, country.alpha2, bank.name.
  • iban: input.iban, result.countryCode, result.isValid.

Profanity detection, ASN, country and domain lookups do not support custom rules.

Example#

Raise the score for large first-time digital purchases coming from a country you do not serve:

  • Group: payment, match: all
  • input.data.isDigitalProducts is true
  • input.data.transaction_amount greater than 200
  • input.data.billing_country is not one of SA, AE, KW
  • Action: overwrite_score to 90

In the API response#

Every response from a rule-capable endpoint contains custom_rules_applied, even when nothing matched:

{
  "status": "success",
  "data": {
    "score": 90,
    "custom_rules_applied": {
      "total": 1,
      "rules": [ { "id": "CR12", "message": "Large digital order from unserved country" } ]
    }
  }
}

The id is the rule code shown in the dashboard (CR plus the rule number) and message is the rule title. For IP reputation the object sits inside data.threats.

Tip: Use the "Test rule" button in the dashboard to dry-run a rule against sample data before enabling it.

Warning: An overwrite_score or mark_valid rule replaces what Gurdx computed. Keep conditions narrow so you do not hide real signals.

See also Blacklists and Events and alerts.

Found a mistake? Tell us on the contact page. Contact