Who.
DocumentationModeration & Protection
WHO DOCS

Moderation & Protection

Set up moderation, filters, spam and raid protection to suit your community.

7 guidesDocumentation updated: October 2026
01
GUIDE 1

Moderation and cases

Configure moderator roles, default actions and escalations.

5 mins

Set roles and protocol

  1. 1

    Open Moderation in the dashboard.

  2. 2

    Select the roles that are allowed to use moderation features.

  3. 3

    Set a moderation log channel that the team can read.

  4. 4

    Decide whether affected members should be informed via direct message.

Set up escalations carefully

Alerts can trigger a stronger action above a set threshold. Set the timeout duration and escalation action to suit your server rules.

Back to top of page ↑
02
GUIDE 2

AutoMod and Anti-Spam

Test rules, set exceptions and reduce false positives.

6 mins

Activate rules

AutoMod offers control areas for spam, repeats, caps, mentions, links, invitations, phishing and other suspicious content. Anti-Spam adds limits for message sequences, duplicates and mentions.

  1. 1

    First, only activate the rules that your server really needs.

  2. 2

    Choose threshold and time window.

  3. 3

    Set exceptions for trusted roles, channels or accounts.

  4. 4

    Specify an action and the protocol channel.

  5. 5

    Test harmless sample messages before broadly deploying the rule.

Control exceptions

If legitimate messages are affected, check the exception lists first, then the threshold and time window. Don't disable all protection across the board if just one rule is too strict.

Back to top of page ↑
03
GUIDE 3

Raid protection and verification

Recognize waves of joining and activate new members in a controlled manner.

5 mins

Anti Raid

Anti-Raid can detect a noticeable number of joins within a time window and trigger a temporary protection measure. Set the threshold, observation time and duration and enter team exceptions.

Verification

  1. 1

    Choose a channel for the verification panel.

  2. 2

    Determine method and role for verified members.

  3. 3

    Check that new members only see the intended channels until they are approved.

  4. 4

    Publish the panel and test the entire process with a test account.

Back to top of page ↑
04
GUIDE 4

Ghost Ping and honeypot

Track deleted mentions and use a decoy channel.

4 mins

Ghost Ping

Ghost Ping detects messages whose mentions are removed or deleted shortly after sending and logs the original content. You can consider role mentions as well as @everyone and @here separately.

  • Set an additional ghost ping destination if desired.
  • Enter roles, accounts and channels that should be ignored.
  • Note that Discord only provides limited time or permissions for some message details.

Honeypot

A honeypot is a bait channel that normal members are not supposed to write to. Anyone who posts there can trigger a configured reaction. Block the channel in Discord for normal roles and clearly state in the warning embed that it is being monitored.

Back to top of page ↑
05
GUIDE 5

AutoMod rules in detail

Understand which rule checks which messages and how actions work.

5 mins

Control areas

Each rule can be activated individually and has its own thresholds, time window, action and exceptions. The word list and permitted domains are also maintained in the AutoMod module.

  • Spam and repetitions: Limit message sequences and similar content.
  • Caps, mentions and emoji: capture noticeable formatting or ping amounts.
  • Links, invitations and phishing: Filter URLs and Discord invitations.
  • Swear words and Zalgo: Check the word list or distorted writing.
  • Join spam and raid: take suspicious joining waves into account.

Actions and safe tests

Depending on the rule, Delete, Warn, Timeout, Kick, Softban or Ban are available. A higher impact action should only be turned on after testing and with reliable exceptions.

  1. 1

    Start with a single rule and a mild action.

  2. 2

    Test in a private channel with clearly harmless examples.

  3. 3

    Check the configured log channel and exceptions.

  4. 4

    Only then increase threshold or action strength.

Back to top of page ↑
06
GUIDE 6

Account protection and young accounts

Set minimum age, trust roles and reaction to new accounts.

3 mins

Use account age as a signal

Security can check a minimum age of the Discord account and perform the specified action on younger accounts. Age refers to Discord account creation, not server membership duration. Trust roles can be excluded from the review.

  • Choose a minimum age that fits your community's usual membership requirements.
  • Check whether new members should receive a notification via DM.
  • Set a private security log channel for team checks.

Avoid false alarms

A young account alone is not evidence of abuse. Use Accountalter as an additional signal and choose your reaction carefully. Test with a fresh test account before enabling the feature for all members.

Back to top of page ↑
07
GUIDE 7

Set up Anti-Nuke

Detect destructive server actions and protect trusted people with exemptions.

5 mins

What Anti-Nuke detects

Anti-Nuke counts suspicious actions per person and action type within a time window: creating or deleting channels or roles, banning or kicking members, granting dangerous permissions, changing webhooks, and adding bots. The default window is ten seconds, with a separate threshold for each action type.

Choose Monitor or Protect

Monitor logs reached thresholds without making automatic changes. Protect attempts to ban the person who triggered the threshold. You can also temporarily prevent @everyone from sending messages in writable text channels; the lockdown is lifted after the configured duration.

  1. 1

    Enable Anti-Nuke in Protection.

  2. 2

    Start with Monitor, or configure Protect with thresholds you have reviewed.

  3. 3

    Add trusted users and roles as exemptions.

  4. 4

    Choose a private alert channel and make sure Who can post there.

Permissions and limits

Who needs access to the Discord audit log for detection. Protect also needs “Ban Members”; channel lockdown needs “Manage Channels”. Discord role hierarchy can prevent a ban if the actor has a role equal to or higher than Who. The server owner and Who are exempt.

Back to top of page ↑