---
title: "Fraud Prevention Rules"
description: "The Fraud Prevention Rules feature helps you protect your referral program from malicious partners, fake sign-ups, and bad traffic. By evaluating referral events, partner details, and payout method..."
last_updated: "2026-10-05T05:09:52.151483+00:00"
canonical_url: "https://www.doc0.dev/docs/934e554a-e6a1-476f-bb2f-23e62d86c3fd/guide/configuration/fraud-prevention-rules"
---

## Overview

### Introduction

The Fraud Prevention Rules feature helps you protect your referral program from malicious partners, fake sign-ups, and bad traffic. By evaluating referral events, partner details, and payout methods against automated risk rules, the system flags suspicious activity, automatically holds commissions for review, and gives you tools to review risk scores or ban malicious partners.

---

### Understanding Fraud Rules

### Rule Categories

#### Conversion-Event Rules
- **Matching customer email (`customerEmailMatch`)**: Triggers when a referred customer's email matches the partner's email, matches the partner's email domain, or matches a previously referred customer by the same partner.
- **Suspicious customer email domain (`customerEmailSuspiciousDomain`)**: Triggers when a referred customer uses a temporary or disposable email domain.

#### Referral Source Rules
- **Paid traffic (`paidTrafficDetected`)**: Triggers when a click, event, or conversion originates from paid advertising traffic.
- **Banned referral source (`referralSourceBanned`)**: Triggers when a referral comes from a domain explicitly included on your banned sources list.

#### Partner-Level Rules
- **Network-level ban (`partnerCrossProgramBan`)**: Triggers when a partner has been banned from another program in the network due to confirmed fraudulent behavior or terms of service violations.
- **Duplicate account detected (`partnerDuplicateAccount`)**: Triggers when a partner is flagged for operating two or more accounts, sharing payout methods, or sharing cryptographic wallet addresses.
- **Email domain mismatch with website (`partnerEmailDomainMismatch`)**: Low-severity signal triggered when a partner's email domain does not match their website domain.
- **Masked email address (`partnerEmailMasked`)**: Low-severity signal triggered when a partner uses an anonymized or masked email address.
- **No website or social links added (`partnerNoSocialLinks`)**: Medium-severity signal triggered when a partner provides no web or social presence.
- **No verified website or social links (`partnerNoVerifiedSocialLinks`)**: Low-severity signal triggered when a partner's social links or website remain unverified.

---

### Managing Commissions and Hold Periods

When a fraud rule triggers, the system automatically protects your program budget by placing affected commissions on hold.

- **Pending Commissions**: If a partner-level or customer-level rule triggers while a commission is pending, its status automatically moves to `hold`.
- **Processed Commissions**: Processed commissions awaiting a pending payout will also be moved to `hold` and detached from their payout batch. Payout amounts are then automatically recalculated.
- **Expirations**: Unresolved fraud event groups automatically expire after 30 days (excluding non-expiring rules like network-level bans). When a fraud group is resolved or expires, held commissions that are no longer blocked by other pending rules are automatically released back to `pending` status.

---

### Reviewing Risk Scores and Fraud Events

You can inspect flagged activity and manage risk events directly from your program's risk center or partner profiles.

- **Risk Severity Levels**: Rules are evaluated and categorized into `low`, `medium`, and `high` severity ranks. Partners applying with high-severity risks display warning banners on their application views.
- **Risk Review Sheet**: Click on any flagged risk group to open the review sheet. Here you can inspect partner details, check network activity, review associated commissions, and take immediate action.

---

### Managing Malicious Partners

When you identify fraudulent activity, you can take action against the partner:

1. Navigate to the partner or risk event you want to address.
2. Choose to **Ban Partner** or **Reject Program Application**.
3. Provide a reason for the ban. Optionally flag the partner for fraud with an explicit fraud reason if necessary.
4. Confirm the action. Banning a partner automatically resolves all pending fraud events for that partner in the current program and propagates network-level alerts to other programs where the partner is enrolled.

> [!TIP]
> You can configure paid traffic platforms and whitelisted campaign IDs under your program's fraud rule settings to prevent false positives from legitimate marketing campaigns.

> [!WARNING]
> Disabling a fraud rule with pending events can automatically resolve related risk groups and release associated held commissions back to pending status. Review pending items carefully before disabling active rules.

## Related

- [Commissions and Payouts](https://www.doc0.dev/docs/934e554a-e6a1-476f-bb2f-23e62d86c3fd/guide/how-to-guides/commissions-and-payouts)
- [Partner Program Management](https://www.doc0.dev/docs/934e554a-e6a1-476f-bb2f-23e62d86c3fd/guide/core-features/partner-program-management)


## Sitemap

See the full [sitemap](https://www.doc0.dev/docs/934e554a-e6a1-476f-bb2f-23e62d86c3fd/llms.txt) for all pages in this wiki.
