Phishing detection
Remove links to phishing, scam and malware sites the moment they are posted.
What it does
Every link in a message is checked against a live, constantly updated list of phishing, scam and malware sites. When a link is on it, the rule fires through the same pipeline as any other automod rule. It is built for the scams that spread through chat: fake Nitro gifts, cloned Steam and wallet logins, and "verify your account" pages sent from hijacked accounts.
Turn it on
Open Automod in your server dashboard and find Phishing detection under Built-in rules. It is off until you enable it. Out of the box it deletes the message, alerts your staff and logs the catch. It does not ban, because the member posting a scam link is usually a victim whose account was taken over, not the scammer.
Malware links
Also block malware links is on by default and extends the check to sites known for malware and unwanted software, such as fake game cheats and free download pages. Switch it off in the rule if you only want phishing handled.
Your own lists
Never flag these domains keeps a domain safe no matter what the threat list says, for example a partner site. Also block these domains adds scams aimed at your community that are not listed yet. Both include subdomains.
Customize it
Because it is an ordinary automod rule, everything else in Automod applies: limit it to certain channels, skip trusted roles or permission groups, raise the punishment to a timeout or ban, or add the phishing trigger to your own rule next to other triggers. Rule order decides which rule acts first.
Speed and reliability
Checks take a fraction of a second and never hold up chat. Repeated links, which is what a scam wave looks like, are answered from a short cache. If the threat list cannot be reached, the link goes through rather than freezing the conversation, and the Security page tells you if phishing detection is running on its smaller backup list.