Allowlist vs denylist

A denylist (blocklist) forces BLOCK for listed customers, devices, or IPs. An allowlist (whitelist) can override other rules for trusted identifiers. Most traffic should still go through scoring and named rules.

Denylist well

List fingerprints, IPs, or customers you have already confirmed abusive. Naiza supports blocking by email, device fingerprint, or IP with a reason trail. Do not dump entire countries into a denylist.

Allowlist carefully

Product copy mentions whitelist override support. Use it for your own QA devices and a short list of trusted partners. An allowlisted stolen session is worse than a false REVIEW.

The middle path

ALLOW / REVIEW / BLOCK from rules and scores. Lists are the sharp edges. Measure false positives before promoting a REVIEW rule to a denylist entry.

Frequently asked questions

Short answers written so search and answer engines can cite them.

What is a fraud denylist API?

It lets you persist identifiers that must fail closed—device, IP, or customer—so later events BLOCK without re-litigating the case.

What is an allowlist in fraud?

A set of identifiers permitted to pass even if other signals are noisy. Keep it small and audited.

Does Naiza support both?

Public feature copy includes blocklist management and whitelist override. Confirm the current list APIs in docs.