Flood protection
Catch someone posting too fast, or posting the same thing over and over, and clean up the whole burst.
Flood protection watches how much one person is posting, not what is in it. Two separate detectors, each turned on and tuned on its own:
- Rate: too many messages, too fast.
- Duplicate: the same message over and over, even with other messages in between.
Where message filters judge a single message on its content, this judges a pattern across several. They work well together: a filter catches one bad link, flood protection catches the same harmless-looking line pasted into nine channels.
Note
Not to be confused with the trap channel, which punishes anyone who posts in a channel nobody should ever post in. That one is about where; this one is about how much.
Both detectors start off, and configuring them is Server Owner only, the same bar as anti-nuke, and for the same reason. This can ban someone automatically based on a pattern, so it does not sit behind a permission that can be handed out.
Start with the summary
,antispam list shows everything at once, and
it is the fastest way to see what a server is actually running.
Syntax
,antispam list
Example
,antispam list
Catch someone posting too fast
Syntax
,antispam rate <on|off> [++punish <p>] [++threshold <n>] [++window <s>] [++duration <t>]
Example
,antispam rate on ++threshold 6 ++window 5 ++punish timeout
| Flag | Means | Accepts | Default |
|---|---|---|---|
++punish | what happens when it trips | warn, timeout, mute, jail, kick, softban, ban | timeout |
++threshold | how many messages trip it | 3 to 50 | 6 |
++window | how many seconds they have to arrive inside | 2 to 120 | 5 |
++duration | how long a timeout lasts | e.g. 5m, 1h | 5m |
The count is across the whole server, not per channel. Someone posting once in fifteen channels is the shape this is really for, and a per-channel counter would see fifteen separate ones.
Catch someone repeating themselves
Syntax
,antispam duplicate <on|off> [++punish <p>] [++threshold <n>] [++window <s>]
Example
,antispam duplicate on ++threshold 4 ++window 30
| Flag | Means | Accepts | Default |
|---|---|---|---|
++punish | what happens when it trips | warn, timeout, mute, jail, kick, softban, ban | timeout |
++threshold | how many identical messages trip it | 3 to 50 | 4 |
++window | how many seconds they have to arrive inside | 2 to 120 | 30 |
They do not have to be consecutive. Typing something else in between does not reset the count, which is the point: alternating two messages is the oldest way around a naive duplicate check.
"Identical" is judged after tidying the text up: capitals, extra spaces and invisible characters are
ignored, and lookalike alphabets are folded back to normal letters, so 𝗳𝗿𝗲𝗲 𝗻𝗶𝘁𝗿𝗼 and
free nitro count as the same message. It is not fuzzy beyond that: yes and yea are two
different messages, deliberately.
Messages with no text (a bare image, for instance) are ignored by this detector. Four screenshots in a row is normal.
Try it without punishing anyone
Set the punishment to warn for the first week:
Syntax
,antispam rate on ++punish warn
Example
,antispam rate on ++punish warn
Nothing happens to the member. You still get the log entry every time it would have fired, which is how you find out whether your thresholds match how your server actually talks before they cost somebody a timeout.
Clean up the whole burst
By default, tripping either detector deletes every message in the burst, not just the one that crossed the line. Turn it off if you would rather keep them:
Syntax
,antispam settings [++purge <on|off>] [++commands <on|off>] [++duration <t>]
Example
,antispam settings ++purge on
| Flag | Means | Default |
|---|---|---|
++purge | delete the whole burst rather than one message | on |
++commands | don't count messages that are Righteous commands | on |
++duration | how long a timeout lasts | 5m |
++commands on is why running ,fm six times in a row does not get you timed out.
Warning
If your server uses custom command aliases, those are not recognised here: invoking one counts as an ordinary message. Use an exempt channel if that becomes a problem.
Exempt a channel
Syntax
,antispam ignore <add|remove|list> [#channel]
Example
,antispam ignore add #spam
Naming a category exempts everything in it, threads included. This is the first thing to reach
for after a false positive: a #counting or #spam channel is meant to look like flooding.
Punish repeat offenders harder
Syntax
,antispam escalation <on|off> [++punish <p>] [++days <n>]
Example
,antispam escalation on ++punish ban ++days 7
| Flag | Means | Accepts | Default |
|---|---|---|---|
++punish | what a repeat offender gets instead | any punishment | ban |
++days | how far back a previous offence still counts | 1 to 90 | 7 |
Offences are remembered in the server's punishment history, so this survives the bot restarting. After the window passes, the slate is clean: someone who flooded once two months ago is not banned for a second slip today.
Who never gets caught
- The server owner and the bot owner.
- Anyone on your
,filter whitelist, one list, shared with the message filters, so you do not maintain two.
Note that moderator permissions alone do not exempt anyone. If you want your staff exempt, put their role on the filter whitelist. This is deliberate, and it is the same choice the trap channel makes: a protection every mod is invisible to is one nobody ever notices is misconfigured.
Start over
Syntax
,antispam reset
Example
,antispam reset
Clears everything and turns both detectors off.
If it fires on the wrong people
In order:
,antispam ignore addthe channel where it happened, if that channel is meant to be busy.- Raise the threshold or shorten the window. A server with a very active general channel may
want
++threshold 10 ++window 5rather than the default 6. - Switch to
++punish warnwhile you tune, so you keep the logs without the consequences. - Put your staff role on the filter whitelist if the false positives are all moderators.
If it fires on nobody at all, check ,antispam list first: both detectors ship off, and turning
the feature "on" means turning a detector on.