Auto-moderating comments
Built-in spam lists, ad-only rules, an allowlist, and a full activity log.
How it works
Start with a bundle rather than a blank page. Essentials covers bot spam, scams and profanity on everything you post; Ad shield applies link, promo-code and contact-harvesting rules to ads and dark posts only; Zero tolerance (Max) deletes instead of hiding and adds AI screening.
Rule types: built-in lists for Profanity, Comment spam and Scams (no pattern to write, and they match through obfuscation such as "f*ck", "c h e c k m y b i o" and "ch3ck my b1o"); Any link/URL, which also catches bare domains and "site (dot) com"; Competitor promo codes; Contact harvesting (emails, phone numbers, "message me on WhatsApp"); your own Keyword, Custom banned word or Regex; and AI: hate, harassment & threats, a Max-only rule that reads intent instead of matching words (needs an OpenAI API key and the AI toggle in Settings).
Each rule chooses an action — Hide, Delete, or Flag for review — and a scope: all posts, organic only, or ads only. When several rules match one comment the strictest action wins, so a Delete rule is never shadowed by a Hide rule.
The allowlist is checked before any rule and always wins. Add your own domain so a customer sharing your link is never treated as a spammer, your own promo code so a competitor rule cannot catch it, and your team’s handles so their replies stay up.
Every action is recorded in the Activity tab with the comment text and the exact word that matched, so a false positive is diagnosable rather than mysterious. Hidden comments can be put back with one click. Flagged comments collect in "Needs review", where you decide to hide them or leave them up.
An account that keeps tripping your rules is escalated automatically from hidden to deleted after three catches in 30 days.
Pause (top of the page) switches every rule off at once without deleting them, useful if you need to see a burst of comments unfiltered. Turn back on restores them exactly as configured.
How it flows
Set it up
- 1
- 2
Add a bundle
Click "Add these rules" on Essentials, and on Ad shield too if you run paid posts. Both are one click and need no configuration.
- 3
Protect your own links and codes
In "Never touch these", add your domain, your active promo codes, and any teammate who replies from their own account.
- 4
Try a comment
Paste something a spammer would write into "Try a comment" and check what your rules would do. Nothing is posted to Instagram.
- 5
Check Activity weekly
The Activity tab shows what was hidden and why. Anything caught wrongly can be put back from there.
Tips to get the most out of it
- Start with Hide rather than Delete for anything you’re not 100% sure about, hidden comments are invisible to other visitors but can be restored from the Activity tab, deleted ones cannot — Instagram has no undelete.
- On paid posts, use Ad shield instead of an account-wide link rule. Links under an ad are almost always competitors or scams; links under an organic post are often your own community sharing something.
- Use Flag for review on a rule you are unsure about. It records the comment without touching it, so you can judge a week of real matches before switching it to Hide.
- Add your promo codes to the allowlist before turning on the competitor promo-code rule, otherwise your own campaign comments get caught.