Raxx · internal docs

internal · gated

DET-SIGNUP-002 — email pattern anomaly

Rule ID: DET-SIGNUP-002 Title: N waitlist signups within 5 minutes sharing an email subdomain or local-part pattern Category: signup Last validated: 2026-06-04 (initial catalog) State: live — queries waitlist_signups directly

Telemetry source

Statistical method + baseline window

Threshold + expected FP rate

Alert route

Escalation owner

Test fixture / synthetic positive

See _fixtures/email_pattern_anomaly_positive.json for a synthetic 6-signup cluster sharing domain tempmail-X9.test within 4 minutes.

What to do when this fires

  1. Inspect the email cluster. Look-alike service domain? Disposable-email provider? Synth pattern?
  2. Cross-check with DET-SIGNUP-001 — co-fire = bot.
  3. If confirmed bot: do not delete rows automatically; tag the rows as suspected-bot (operator-only column or comment) and leave for batch cleanup decision.
  4. If confirmed organic small-business cluster: log to _log/ as known FP, do not tune the rule down.

What NOT to do