> For the complete documentation index, see [llms.txt](https://dfend.gitbook.io/documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://dfend.gitbook.io/documentation/developer-api/bans.md).

# Bans

Events may include [Recommendations](/documentation/developer-api/types/event/recommendation.md) of type BAN\_IP, BAN\_ACTION, or BAN\_DEVICE. In these cases, you should enforce the ban according to your best judgment and using the tools you have available.

## Expiration

[Ban](/documentation/developer-api/types/event/recommendation/ban.md) objects on [Recommendations](/documentation/developer-api/types/event/recommendation.md) may contain an expiration time on the `until` property. This gives you a recommended time limit on the ban.

## Configure

{% hint style="info" %}
Coming soon.
{% endhint %}

You can set your preferences on how bans are handled and what type of ban recommendations you receive in your **Dashboard.**

## Handling false positives

Rarely, a user undergoing normal activity might be operating on an IP that was previously identified as a threat. We are expanding our API to support IP whitelisting, and this functionality is coming soon.
