Back to blog

Stop Discord Spam: 4 Copy Paste AutoMod Rules for Server Owners

Abstract geometric AutoMod protection title card
Abstract geometric AutoMod protection title card

Effective discord spam rules combine AutoMod triggers set to send an alert with selective block or timeout actions, all logged to a staff-only channel and backed by tightened server permissions. A moderation bot adds real-time detection and cleanup on top of that base. To configure it yourself, you need MANAGE_GUILD for AutoMod and MODERATE_MEMBERS for timeouts.

TL;DR: - Setting AutoMod to send alerts before blocking allows safe tuning of rules without risking legitimate messages being deleted. - Mention spam triggers should be prioritized during raid waves, with keyword and regex filters used for phishing links and scams. - Timeout actions are limited to a maximum of four weeks, requiring careful consideration for repeated offenders versus manual bans. - Automations should route flagged messages to staff-only channels to enable review and maintain transparency, reducing public conflicts. - Regular ongoing maintenance—weekly log reviews and monthly rule adjustments—is essential to adapt to evolving spam tactics and minimize false positives.

Table of Contents

Core AutoMod trigger types and what each catches

Discord AutoMod filters messages through five trigger categories, and each one is built for a different kind of attack. Keyword triggers catch specific words or phrases you define, useful for known scam terms or slurs. Preset triggers use Discord's maintained lists for profanity, sexual content, and slurs without you building anything from scratch. Spam triggers look for patterns typical of bulk unwanted content, while mention spam triggers flag messages that ping an unusual number of users or roles at once, the signature move of a raid. Member profile triggers scan usernames, nicknames, and status text for problem keywords before a bad actor even posts.

Every trigger type has metadata limits worth knowing before you configure one, according to Discord's Auto Moderation documentation:

  • Keyword rules cap the number of keyword and regex patterns you can add per rule.
  • Mention spam rules use a mention_total_limit field to define how many pings trigger a flag.
  • Preset rules draw from fixed Discord-maintained categories rather than custom lists.

For a mention-raid wave, prioritize mention spam. For phishing links, keyword or regex triggers do the heavier lifting.

AutoMod actions and permission requirements

Once a trigger fires, AutoMod can respond four ways: block message, send alert, timeout, or block interactions. Each has a distinct job and a different permission gate.

  • Block message deletes the offending content before it posts, ideal for clear-cut spam or slurs.
  • Send alert routes a copy of the flagged message to a staff channel without taking action, the safest choice while you tune a new rule.
  • Timeout silences a member for a set period and requires MODERATE_MEMBERS, on top of the MANAGE_GUILD permission needed to build the rule in the first place.
  • Block interactions stops a flagged member from using reactions or slash commands temporarily.

The timeout action tops out at a maximum duration of 2419200 seconds, equivalent to 4 weeks, per Discord's AutoMod API documentation. That ceiling matters when you are deciding between a timeout and a manual ban for repeat offenders. During the first week of any new rule, lean on send alert only. It lets you see what would have been blocked without risking a legitimate member's message.

Practical rule templates and sample settings you can copy

These four templates cover the attack patterns most servers see, ready to adapt to your own trigger configuration.

  1. Mention-raid rule: set mention_total_limit low (many servers use 4 to 6 mentions per message), pair with timeout and send alert so staff see every hit.
  2. Link and phishing rule: build a keyword or regex list targeting common scam domains and free-nitro phrasing, action set to block message plus send alert.
  3. Message flood rule: use the spam trigger type with block message active, and apply a short timeout (start at 10 to 60 minutes) for repeat triggers within a short window.
  4. New-account keyword rule: combine member profile triggers with keyword lists to catch suspicious usernames before the account posts at all.

Exempt your moderator and bot roles, plus announcement or support channels where false positives cause the most friction, from every rule you deploy.

Pro Tip: Start every new template in send-alert-only mode for a few days before switching on block or timeout, so you can confirm it catches real spam without also catching regular members.

Staged moderation rule rollout illustration

Integrating automated rules with human moderation

Automation should feed information to your team, not replace their judgment. Route every AutoMod flag to a private, staff-only channel rather than acting visibly in public chat. That keeps a record for later review and avoids turning a moderation action into a public spectacle that invites pushback.

  • Log flagged content privately so staff can norm decisions across cases.
  • Use private nudges instead of public removals for borderline behavior.
  • Keep an appeals path open through a ModMail bot or a small appeals server.

Research on the Chillbot system found that private, customizable nudges reduced visible conflict and helped protect moderators from retaliation while still correcting behavior.

Private, prewritten nudges can correct behavior without the public friction of a visible removal or ban.

A compact appeals flow, built around a ticketing bot or separate appeals server, keeps context attached to each case instead of scattering it across DMs.

Privileged intents, data handling, and what your bot actually needs

Any bot that scans message content for keywords or links needs the Message Content privileged intent, which requires an application to Discord once your server crosses the verification threshold. Guild Member intent is similarly gated and needed for features that track joins or scan profiles at scale.

When you submit for review, be specific rather than generic:

  • Describe the exact moderation feature the intent powers.
  • Request only the intents that feature needs, not a broad set "for future use."
  • Explain how flagged content is stored, for how long, and who can access it.

Discord's privileged intent review guidance also suggests considering slash commands or context menus for features that do not strictly need to read every message.

Layering automated rules with server permissions

AutoMod works best when the server itself is already hardened. Start by disabling @everyone and @here for regular member roles, so a compromised or new account cannot ping the whole server even if a rule momentarily misses it.

  • Set a higher Verification Level to slow down mass-join raids before they reach chat.
  • Restrict new-member permissions until an account has been present for a set period.
  • Use channel-scoped rules and exempt roles so AutoMod does not misfire in announcement or bot-command channels.

Discord's own raid protection guidance recommends exactly this pairing: AutoMod plus tightened permissions, so one layer covers the other's gaps.

Quick best-practices checklist and maintenance schedule

Rules decay as spam tactics shift, so treat this as ongoing maintenance rather than a one-time setup.

  1. Weekly: review the staff alert log for missed spam or false positives.
  2. Monthly: adjust keyword lists and mention limits based on recent incidents.
  3. Quarterly: audit exempt roles and channels for anyone who no longer needs the exception.
  4. After any incident: run a short review of what the rule caught, missed, and how fast staff responded.

Track blocked messages, false positives, alert response time, and appeals volume to see whether a rule is actually working.

Pro Tip: Launch every rule change in alert-only mode again after a major edit, the same way you did the first time, since even small metadata tweaks can shift what gets caught.

Author perspective: balancing automation with human judgment

Automation should absorb the repetitive part of moderation, the flood of near-identical spam messages, so human moderators can spend their attention on judgment calls: context, intent, appeals. A bot that only blocks and never explains itself to your team just moves the workload instead of reducing it. Tools like specialized moderation bots earn their keep during an actual raid, when channel locks and automatic cleanup buy staff the minutes they need to assess what is happening and decide the next step.

— Adam

How Better Antispam implements these patterns

Some moderation bots build the workflow described above directly into one tool: real-time spam wave detection, automatic channel clean-up after a raid, and permission management that can lock channels the moment mass joins spike. They pair detection with response, silencing spammers and restoring order without requiring custom AutoMod rules for every new attack pattern.

Betterantispam

If you would rather deploy a system built for this than assemble one from individual AutoMod rules, Better Antispam adds verification options, onboarding automation, and case handling on top of the detection layer, and you can also read a tactical walkthrough on how to stop a Discord raid or the steps to delete all messages in a channel during cleanup. Set it up on your server to see the layers work together.

Sources

FAQ

What permissions do I need to set discord spam rules?

You need MANAGE_GUILD to create or edit AutoMod rules, and MODERATE_MEMBERS specifically to use the timeout action, according to Discord's raid protection guidance. Without MODERATE_MEMBERS, a rule can still block messages or send alerts but cannot silence a member.

How do I report spam on a Discord server?

Use Discord's built-in report feature on the message or user profile, or flag it to your server's staff channel if AutoMod has already logged it there. Servers using automated alerts typically catch and log spam before a manual report is needed.

How long can an AutoMod timeout last?

The maximum timeout duration is 2419200 seconds (equivalent to 4 weeks), as documented in Discord's Auto Moderation API. Most spam-related timeouts are set far shorter, often under an hour, to avoid over-penalizing a false positive.

Should I start with block message or send alert?

Start with send alert while tuning a new rule, since it shows you what would be caught without risking legitimate members' messages. Once the rule proves accurate over a few days, switch to block message or timeout for a stronger response.

Does my moderation bot need the Message Content intent?

Yes, if it scans message text for keywords, links, or phishing patterns, your bot needs the privileged Message Content intent approved through Discord's review process. The intent review guidance recommends requesting only the specific access your feature needs and documenting your data handling clearly.

Made with BabyLoveGrowth to attract links

BetterAntispam on Nick LaunchesFeatured on ToolFameFeatured on Startup FameVerified on DANG!ToolpilotToolpilotFeatured on SaaSGrowFeatured on ShowMeBestAIFazierSubmit AI ToolsFeatured on Twelve ToolsFeatured on Wired BusinessFeatured on Findly.toolsListed on Turbo0Featured on SaaSFameFeatured on neeed.directoryFeatured on Dofollow.ToolsGood AI ToolsAI Agents DirectoryAura++SideProjectorsFoundrListShinyLaunchStartup FastNextGen ToolsFind-Us-HereDeepLaunchAcid ToolsStartupBaseNewToolUFindWhatsYourHoursOpenHuntsMarketingDBStartup InspireStarter BestTiny StartupsFeatured on aitoolfame.comFeatured on IndieHuntShinyLaunchLaunched on LaunchPandaFeatured on WhatsthebigdataFeatured on Yo.directoryAs seen on Launch Llama Newsletterbetterantispam.com Domain RatingVerified DR - Verified Domain Rating for betterantispam.comFeatured on ToolfioBetterAntispam | Firsto LaunchFeatured on DailyPingsFeatured on DanielLaunchesFeatured on ShipBoostFeatured on AgentWork.ToolsFeatured on SaaSCityFeatured on WayfindioFeatured on DodoDirectoryFeatured on TinyLaunchpadFeatured on ListMySaaSVerified on directreeFeatured on Submit HuntFeatured on VibeCodingListFeatured on NoonlaunchFeatured on LaunchItListed on MaidensailVerified on Endors — BetterAntispamMarked on IndieAscentListed on CurlShipListed on PublishYourSaaS