minFraud Release Notes
Email Now Available as Custom Rules Parameter
September 14, 2020We have released an additional input parameter for use with custom rules. Customers of minFraud Score, minFraud Insights, and minFraud Factors can now use email address to serve as the basis when creating a custom rule:
- Email address:
/email/address/– a valid email address or an MD5 of the lowercased email used in the transaction.
For more information on implementing custom rules, see the Custom Rules Guide on our Support Center.
Billing and Product/Service Permission Types for Standard Users
September 10, 2020We have added a new permission category for the Standard User type. The Product/Service permission grants a Standard User access to product and service related functionality in the account portal without having access to user management and billing functionality. For more information, consult our Multi-User Account Access Guide.
Update to minFraud service server locations
August 10, 2020Effective August 17, 2020, we will no longer serve minFraud service queries from our London-area servers. These queries will automatically be re-routed to our US-East servers. You do not need to take any action as a result of this change. Customers who have previously had queries routed to these servers may see an increase of 100 – 150 ms in the response time for your queries.
New minFraud Factors risk factors
August 6, 2020We have released three additional risk-factor outputs. Customers of minFraud Factors can now access the following risk factors:
/subscores/device– Risk associated with the device./subscores/email_local_part– Risk associated with the part of the email before the @ symbol./subscores/shipping_address– Risk associated with the shipping address.
Our client APIs have been updated to support these outputs so you may need to refresh yours if you are not interfacing directly with our rest API.
Report transaction support in minFraud client APIs
June 24, 2020The minFraud Score, Insights, and Factors client APIs now support sending transaction feedback to our Report Transaction endpoint. This will allow you to more easily report fraud, suspected fraud, spam/abuse, and false positives to improve scoring. You can find more details on using this functionality in the documentation for the specific client API you use.
FIDO2 Support for Two-Factor Authentication
June 22, 2020We’ve updated our Two-Factor Authentication (2FA) implementation to the FIDO2 standard, which supports more web browsers and more types of security keys (e.g. supported biometrics keys). See our Two-Factor Authentication (2FA) User Guide for more information.
Data Changes to GeoIP Legacy and minFraud Legacy Web Services
June 15, 2020We are planning to make a number of data changes to the minFraud Legacy Standard and Premium, and GeoIP Legacy City and Insights (formerly Omni) web services at the end of May 2022. Please see our blog post for more information, and how to prepare.
Anonymous IP flags as parameters for custom rules
May 14, 2020Customers of minFraud Insights and minFraud Factors can now use the following Anonymous IP outputs as parameters to serve as the basis when creating a custom rule:
/ip_address/traits/is_anonymous/ip_address/traits/is_anonymous_vpn/ip_address/traits/is_hosting_provider/ip_address/traits/is_public_proxy/ip_address/traits/is_tor_exit_node
Retirement of legacy minFraud SOAP API
May 8, 2020On May 8, 2020, we discontinued our legacy minFraud SOAP API in order to focus our development on our newer current APIs. We initially announced this retirement in April 2019.
Other client APIs for legacy minFraud services (not recommended) will continue to be supported. We recommend either integrating with the legacy minFraud service directly, or using our current minFraud services.
Billing fields and is disposable email as input parameters for custom rules
April 27, 2020We have released additional input parameters for use with custom rules. Customers of minFraud Score, minFraud Insights, and minFraud Factors can now use the following inputs to serve as the basis when creating a custom rule:
/billing/address– The first line of the user’s billing address./billing/address_2– The second line of the user’s billing address./email/is_disposable– This field is true if MaxMind believes that the email address is from a disposable email provider. It is false if the address is not from a known disposable email provider.
New /credit_card/is_business output
April 6, 2020The /credit_card/is_business output is now available in minFraud Insights and
Factors. This field is true if the issuer ID number is for a business card.
New /email/domain/first_seen output
March 24, 2020The /email/domain/first_seen output is now available in minFraud Insights and
Factors. This output is a date string (e.g. 2020-03-24) indicating the date the
email address domain was first seen by MaxMind. The earliest date that may be
returned is January 1, 2019.
minFraud Query Form
March 2, 2020Users of the minFraud Score, Insights, and Factors services can now manually submit minFraud queries (with a subset of inputs) through the new minFraud Query Form [login required]. The results of the query are displayed in our minFraud Interactive user interface.
New /email/is_disposable output
February 19, 2020The /email/is_disposable output is now available in minFraud Insights and
Factors. The output is a boolean indicating whether the email address is from a
disposable email provider.
More outputs on transaction details screen
February 4, 2020We’ve added the following outputs to the Transaction Details screen in minFraud Interactive to assist you with manual review of minFraud transactions:
- Subdivision name
- Registered country name
- Represented country name
- Represented country type
- Country, city, and subdivision confidence
- ISP
- Organization
- Domain
- Anonymous IP flags
- User count
- Static IP score
You can find descriptions of these outputs here.
Retirement of legacy IIN (BIN) API
January 31, 2020On January 31, 2020, we discontinued our legacy IIN (BIN) API in order to focus
development and maintenance efforts on our core services. The affected endpoint
is /app/bin_http.
We continue to support the IIN (BIN) manual look-up form on our website [login required].
Tag transactions from transaction details screen
January 29, 2020minFraud service users can now tag transactions (e.g. chargeback, not fraud, spam/abuse, suspected fraud) directly from the Transaction Details screen for an individual transaction in minFraud Interactive.
Tagging transactions allows us to detect 10-50% more fraud for you. You may also tag transactions outside of minFraud Interactive by using this form.
The USER_ID_REQUIRED error code is now ACCOUNT_ID_REQUIRED
December 23, 2019Our web services, including
GeoIP web services and
minFraud services,
now return the error code ACCOUNT_ID_REQUIRED instead of USER_ID_REQUIRED
when the account ID parameter is missing.
Query usage report license key filter
December 17, 2019You can now filter by license key when viewing the query usage report [login required] in your account portal.
Toggle minFraud Transactions Access
December 11, 2019Account administrators can now enable or disable access to the minFraud Transactions page [login required], which is accessible from the account portal. You can manage account access to this feature here [login required].
The minFraud Transactions page is used for review, dispositioning, tagging, and exporting transactions. See our guide for more info.
Changes to Japan Postal Codes
December 11, 2019Effective December 16, 2019, we will return 1 as the last digit for all 7
digit postal codes in Japan. The last digit refers to
street-level resolution
and should not be relied upon for IP geolocation.
Changes to Portugal Postal Codes
November 8, 2019Effective November 12, 2019, we will return -001 as the last 3 digits for all
7 digit postal codes in Lisbon, Portugal. Our postal code resolution in Portugal
is accurate for the first 4 digits and we include the -001 at the end for
backwards compatibility for customers to join the data with 7 digit Portuguese
postal code databases. We may extend this convention to other large Portuguese
cities in the future.
Retirement of TLS 1.0/1.1 and unencrypted http minFraud requests
October 16, 2019We retired support for TLS v1.0/v1.1 and unencrypted HTTP requests to minFraud services today, as part of our commitment to securing and protecting your data. Please ensure you are using TLS v1.2+ to connect to MaxMind services.
New static_ip_score output in web services
October 15, 2019The following output has been added to the GeoIP Insights web service, and minFraud Insights and Factors web services:
static_ip_score– An indicator of how static or dynamic an IP address is. The value ranges from 0 to 99.99 with higher values meaning a greater static association. For example, many IPs with auser_typeofcellularhave a score under one. Static Cable/DSL IPs typically have a score above thirty.This indicator can be useful for deciding whether an IP address represents the same user over time.
The static_ip_score output is present in the traits object.
Final reminder of security-related retirements
October 14, 2019This is a reminder that we are retiring support for requests using TLS 1.0/1.1, and unencrypted HTTP requests to MaxMind minFraud services on October 16, 2019. After October 16, 2019, these types of requests will always fail with an error. Please update to TLS 1.2+ to avoid service disruption. You may need to upgrade your technology stack to a later version, or make code changes to do so.
Contact us for support or if you have questions.
Improved cellular IP detection
October 3, 2019We have made improvements to how we identify cellular IPs for the
connection_type field provided in the
GeoIP Connection Type database,
and the user_type field provided in the
GeoIP Insights web service
and
minFraud services.
Accuracy for cellular identification should now be about 95% accurate globally.
Account activity log
October 2, 2019You can now view a log of your MaxMind account activity, which includes a time stamp, requester, and subject, for the each of the following actions:
- Creation of a new user
- Deactivation of a user
- User password changes
- Email address / username changes
Account administrators can see activity across the whole account, while non-administrators will only see their own activity. You can find the account activity log in your account portal under ‘Account Information’ or here [login required].
High risk IP country deprecation
September 30, 2019We’ve deprecated the /ip_address/country/is_high_risk output in
minFraud Insights and minFraud Factors (and highRiskCountry output
in legacy minFraud services) because it provides
limited value. You can find the IP country in the /ip_address/country/names
output.
New network and user_count outputs in web services
September 19, 2019The following outputs have been added to the GeoIP Insights web service, and minFraud Insights and Factors web services:
network– The network in CIDR notation associated with the record. This is the largest network where all of the fields besidesip_addresshave the same value.user_count– The estimated number of users sharing the IP/network during the past 24 hours. For IPv4, the count is for the individual IP. For IPv6, the count is for the /64 network.
Both of these outputs are present in the traits object.
Planned warning interruption (September 2019)
September 16, 20198-hour interruption of old TLS and unencrypted minFraud requests on September 25, 2019
There will be a planned service interruption for all requests to MaxMind services that use TLS versions 1.0 and 1.1, and for unencrypted HTTP requests to MaxMind legacy minFraud services (e.g. minFraud Standard, minFraud Premium, Proxy Detection web service, IIN service). This will take place for up to 8 hours from 14:00-22:00 UTC on September 25, 2019.
During the interruption, requests using TLS v1.0 and v1.1 and unencrypted HTTP requests to legacy minFraud endpoints will fail with an error.
To avoid service interruption, you may need to upgrade some part of your technology stack to a later version, or you may need to make code changes. If you have any questions, please do not hesitate to contact us. Additional info is available on our blog.
IP and email tenure deprecation
August 29, 2019Effective August 29th, 2019, we have deprecated the /subscores/ip_tenure and
subscores/email_tenure risk-factor outputs in the minFraud Factors service
because they provided limited value. The subscores will default to 1 and will be
removed in a future release. The IP tenure is reflected in the overall risk
score. The user tenure on email is reflected in the /subscores/email_address
output.
Improved business IP detection
August 21, 2019We have made improvements in how we detect business IPs for the user type field provided as part of the GeoIP Insights web service and minFraud services. Approximately 1% of residential IPs were recently corrected to the appropriate business user type as a result of these improvements.
Planned warning interruption (August 2019)
August 20, 20198-hour interruption of old TLS and unencrypted minFraud requests on August 28, 2019
There will be a planned service interruption for all requests to MaxMind services that use TLS versions 1.0 and 1.1, and for unencrypted HTTP requests to MaxMind legacy minFraud services (e.g. minFraud Standard, minFraud Premium, Proxy Detection web service, IIN service). This will take place for up to 8 hours from 14:00-22:00 UTC on August 28, 2019.
During the interruption, requests using TLS v1.0 and v1.1 and unencrypted HTTP requests to legacy minFraud endpoints will fail with an error.
To avoid service interruption, you may need to upgrade some part of your technology stack to a later version, or you may need to make code changes. If you have any questions, please do not hesitate to contact us. Additional info is available on our blog.
Retirement of legacy IIN (BIN) API service
August 5, 2019We are discontinuing the legacy IIN (BIN) API on January 31, 2020 in order to focus development and maintenance efforts on our core services. This means that the service will no longer function if you are querying the URL below: https://minfraud.maxmind.com/app/bin_http
Please note that we continue to support the IIN (BIN) look-up form on our website [login required], so that remains an option for your use. If you require an API because of volume considerations, we recommend either using our minFraud Insights API (IP address is a required input field) or integrating an alternative commercially available solution.
Planned warning interruption
July 24, 2019There will be a planned service interruption for all requests to MaxMind services that use TLS versions 1.0 and 1.1, and for unencrypted HTTP requests to MaxMind legacy minFraud services (e.g. minFraud Standard, minFraud Premium, Proxy Detection web service, IIN service). This will take place for up to 2 hours starting at 14:00 UTC on the three dates below:
- Monday, July 29, 2019
- Wednesday, July 31, 2019
- Friday, August 2, 2019
During the interruption, requests using TLS v1.0 and v1.1 and unencrypted HTTP requests to legacy minFraud endpoints will fail with an error.
To avoid service interruption, you may need to upgrade some part of your technology stack to a later version, or you may need to make code changes. If you have any questions, please do not hesitate to contact us. Additional info is available on our blog.
Disable IP Risk
July 22, 2019You can now manage a list of IP addresses and networks that you want to exempt from IP risk scoring. This is helpful when the IP address is known to be unrelated to the end-customer, such as when you have transactions coming from a call center or agent. Adding an IP address or network to the exclusion list will ensure IP risk is neither calculated nor considered when determining the riskScore for transactions associated with excluded IPs. Learn more
Initial release of minFraud-node
June 14, 2019We have added Node.js as a MaxMind Supported minFraud API (NPM, GitHub). It provides an API for the minFraud Score, Insights, and Factors services.
Security-related retirements 2019
April 18, 2019In order to ensure your data is as safe and secure as possible, we will be retiring support for TLS v1.0 and 1.1, unencrypted HTTP requests to our legacy minFraud services, and our legacy minFraud SOAP API in the coming months. Please see our blog for more info.
2FA release
April 8, 2019To enhance the security of your MaxMind account, Chrome users can enable two-factor authentication (2FA). You can now add and require a (FIDO U2F) security key on top of your account credentials for a more secure log-in. See our support center user guide for information on how to set up 2FA.
Changes to US coordinate data
September 21, 2018On Monday, October 1st, we will be changing a large amount of our U.S. coordinate (latitude & longitude) data* to use GeoNames coordinates for postal codes. This change will ensure greater consistency during our build processes. Around 95% of US coordinates will change with most moving about 1 mile. About 5 to 10% of US coordinates will move by more than 10 miles.
* Coordinate data is approximate and is not precise. It should not be used to identify a particular street address or household as it refers to a larger geographical area instead of a precise location.