# Flagging mass postings from SPAM attacks is onerous

**URL:** https://meta.discourse.org/t/flagging-mass-postings-from-spam-attacks-is-onerous/381809
**Category:** Feature
**Tags:** review-queue, spam
**Created:** [September 6, 2025, 3:58pm UTC](https://meta.discourse.org/t/flagging-mass-postings-from-spam-attacks-is-onerous/381809 "2025-09-06T15:58:22Z")
**Posts on this page:** 12
**Page:** 1

<div class="post-metadata">

### Author: ![emyoulation](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/emyoulation/32/165545_2.png) [@emyoulation](https://meta.discourse.org/u/emyoulation)
#### Post date: [September 6, 2025, 3:58pm UTC](https://meta.discourse.org/t/flagging-mass-postings-from-spam-attacks-is-onerous/381809/1 "2025-09-06T15:58:22Z")

</div>

The workflow for moderators Flagging a bunch of new postings from a SPAMbomb takes far too long.

We, like other Discourse forums, recently had dozens of “airways” and “quickbooks” postings swamp our site. We’ve searched this forum, implemented suggestions to mitigate new attacks. But this left the forum swamped and still sending crap to users in maillist mode who had various delays set.

To flush our queue of New content, it took nearly 2 minutes per posting. With 70 messages to clear, this meant over 2 hours of moderator time. The workflow was the main problem.

1. you had to view each posting even though the title made it clear that it was SPAM.

2. you had to scroll to the bottom of a VERY long message to get to the message Flagging controls.

3. the Flag button was hidden and an ellipsis button had to be clicked to show the Flag ![image](https://global.discourse-cdn.com/meta/original/4X/a/6/d/a6d0cfbd9a3bc808198eae8ae51add1fb841b369.png)

4. then the SPAM option had to be selected from a menu for each

5. then moderators had to make decisions about resolving the flag immediately (rather than just putting them in a queue so the Users wouldn’t still see all the crap)

6. choosing to delete user and block, a generic warning message will appear about that deleting the (possibly multiple) messages. But there is no info about the multiple messages. If those are all new, it is undoubtedly the correct step. But there is no title nor date for the multiple messages. (If the spammers find a way to spoof real users, this might cause REAL messages and users to be deleted.)

7. after the message is marked as deleted, the Red Deleted message content is left onscreen. Moderators have to select Latest view to refresh back to see the other new postings.

It would be very nice if there was a similar thread-reading feature with the “Admin” menu to “Select Posts…” for the New Postings queue. Allowing mass Flagging of Messages while viewing JUST their titles. This would allow moderators to deal with the queued messages with less time pressure.

 ![image](https://global.discourse-cdn.com/meta/original/4X/0/1/7/017b03140145d9db32018ac85f8f3ff71caabfae.png)

> [@Watched words to block recent spam attack](https://meta.discourse.org/t/watched-words-to-block-recent-spam-attack/380420):
>
> I’ve had at least two sites get hit with a wave of spam that looks like it’s designed to poison LLMs. The same attack has also been reported here at least once ([Anyone else currently undergoing mass spam attack?](https://meta.discourse.org/t/anyone-else-currently-undergoing-mass-spam-attack/378972)). The best solution is to set up [Discourse AI - Spam detection](https://meta.discourse.org/t/discourse-ai-spam-detection/343541), which I do recommend, but it’s a bit of a bother. Here’s a stopgap you can implement that will take just a few minutes. It assumes that you have a unix-like operating system (e.g., linux or mac). If you use Windows and can…

---

<div class="post-metadata">

### Author: ![Moin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/moin/32/554653_2.png) [@Moin](https://meta.discourse.org/u/Moin)
#### Post date: [September 6, 2025, 4:09pm UTC](https://meta.discourse.org/t/flagging-mass-postings-from-spam-attacks-is-onerous/381809/2 "2025-09-06T16:09:14Z")

</div>

> [@emyoulation](#):
>
> It would be very nice if there was a similar thread-reading feature with the “Admin” menu to “Select Posts…” for the New Postings queue. Allowing mass Flagging of Messages while viewing JUST their titles.

Is this a feature request for adding “flag” to the bulk actions on topic lists?

> [@emyoulation](#):
>
> the Flag button was hidden and an ellipsis button had to be clicked to show the Flag

That’s based on your configuration of the `post_menu_hidden_items` site setting.

---

<div class="post-metadata">

### Author: ![emyoulation](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/emyoulation/32/165545_2.png) [@emyoulation](https://meta.discourse.org/u/emyoulation)
#### Post date: [September 6, 2025, 4:26pm UTC](https://meta.discourse.org/t/flagging-mass-postings-from-spam-attacks-is-onerous/381809/3 "2025-09-06T16:26:29Z")

</div>

> [@Moin](#):
>
> Is this a feature request for adding “flag” to the bulk actions on topic lists?

That is one choice. It would probably have the greatest impact. But aren’t bulk actions an “Admin” level option rather than a “Moderator” level? And we had users wanting to Flag the obvious SPAM too. It was nearly as painful for them to do 20. (The initial limit for new users. We increased that as part of our response to this trend.)

But describing the full workflow was to see what opportunities I was missing. The `post_menu_hidden_items`is a good example.

---

<div class="post-metadata">

### Author: ![Moin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/moin/32/554653_2.png) [@Moin](https://meta.discourse.org/u/Moin)
#### Post date: [September 6, 2025, 4:32pm UTC](https://meta.discourse.org/t/flagging-mass-postings-from-spam-attacks-is-onerous/381809/4 "2025-09-06T16:32:22Z")

</div>

> [@emyoulation](#):
>
> But aren’t bulk actions an “Admin” level option rather than a “Moderator” level?

I think moderators can use them too.

> [@emyoulation](#):
>
> But describing the full workflow was to see what opportunities I was missing.

Do you know you can bulk delete users? [Deleting multiple users in bulk](https://meta.discourse.org/t/bulk-delete-multiple-users-as-a-staff-user/345785)

---

<div class="post-metadata">

### Author: ![emyoulation](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/emyoulation/32/165545_2.png) [@emyoulation](https://meta.discourse.org/u/emyoulation)
#### Post date: [September 6, 2025, 4:39pm UTC](https://meta.discourse.org/t/flagging-mass-postings-from-spam-attacks-is-onerous/381809/5 "2025-09-06T16:39:08Z")

</div>

> [@Moin](#):
>
> Do you know you can bulk delete users?

Yes, but doing that without the feedback loop of the message titles requires a lot of manual cross-referencing. (Since many users choose usernames with no meaning.)

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [September 6, 2025, 6:53pm UTC](https://meta.discourse.org/t/flagging-mass-postings-from-spam-attacks-is-onerous/381809/6 "2025-09-06T18:53:15Z")

</div>

This doesn’t count as a “Guide(s) to assist those who self-host their Discourse site” so I moved it to “support”, though apparently you solved your problem through onerous work before asking for support.

I think you do have a few decent #Contribute > Feature requests in here, so you could propose some of them there.

---

<div class="post-metadata">

### Author: ![emyoulation](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/emyoulation/32/165545_2.png) [@emyoulation](https://meta.discourse.org/u/emyoulation)
#### Post date: [September 6, 2025, 7:18pm UTC](https://meta.discourse.org/t/flagging-mass-postings-from-spam-attacks-is-onerous/381809/7 "2025-09-06T19:18:09Z")

</div>

> [@pfaffman](#):
>
> so I moved it to “support”

You’re correct. We resolved the immediate problem before taking the time to write up the workflow. So we do not need support either.

Perhaps it can be moved to Feature requests to avoid the rework?

---

<div class="post-metadata">

### Author: ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### Post date: [September 6, 2025, 7:26pm UTC](https://meta.discourse.org/t/flagging-mass-postings-from-spam-attacks-is-onerous/381809/8 "2025-09-06T19:26:19Z")

</div>

> [@emyoulation](#):
>
> Perhaps it can be moved to Feature requests to avoid the rework?

I think you should be able to move it, but I think for it to be a feature request you’d need to create one that just says what the request is, and maybe links back to this for a longer version.

This is pretty much what the feature request is, right?

> [@emyoulation](#):
>
> It would be very nice if there was a similar thread-reading feature with the “Admin” menu to “Select Posts…” for the New Postings queue. Allowing mass Flagging of Messages while viewing JUST their titles. This would allow moderators to deal with the queued messages with less time pressure.

with a title like “allow multi-select of topics and marking all as spam” (that seems a bit awkward but it’s close.)

Oh, and that’s almost exactly what was said elsewhere in this topic.

---

<div class="post-metadata">

### Author: ![tobiaseigen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tobiaseigen/32/539204_2.png) [@tobiaseigen](https://meta.discourse.org/u/tobiaseigen)
#### Post date: [September 17, 2025, 5:44pm UTC](https://meta.discourse.org/t/flagging-mass-postings-from-spam-attacks-is-onerous/381809/10 "2025-09-17T17:44:59Z")

</div>

I went ahead and moved this topic to #Contribute > Feature. I think there’s enough gold in here for the staff experience team to consider.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [September 18, 2025, 12:32am UTC](https://meta.discourse.org/t/flagging-mass-postings-from-spam-attacks-is-onerous/381809/11 "2025-09-18T00:32:28Z")

</div>

We have this now:

 ![image](https://global.discourse-cdn.com/meta/original/4X/0/4/5/0450b2e1cef8acc9834a0e554a3c34fff1f36bdb.png)

I wonder if we should add a simple

🗑 spam…

Option (for mods) which makes it trivial to handle spam topics.

* * *

The good news though is that this is a non issue once AI spam is enabled cause it stops the tap prior to stuff getting really bad.

---

<div class="post-metadata">

### Author: ![emyoulation](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/emyoulation/32/165545_2.png) [@emyoulation](https://meta.discourse.org/u/emyoulation)
#### Post date: [September 23, 2025, 3:50pm UTC](https://meta.discourse.org/t/flagging-mass-postings-from-spam-attacks-is-onerous/381809/12 "2025-09-23T15:50:23Z")

</div>

> [@sam](#):
>
> The good news though is that this is a non issue once AI spam is enabled cause it stops the tap prior to stuff getting really bad.

On the other hand, there is no doubt that the SPAMmer attacks will evolve to combat the AI spam feature. So this need will appear again in the future, a countering fix will be found within a few days and the “need” for will again be considered a “non issue”.

A stopgap feature will only be “an issue” during emergencies.

---

<div class="post-metadata">

### Author: ![emyoulation](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/emyoulation/32/165545_2.png) [@emyoulation](https://meta.discourse.org/u/emyoulation)
#### Post date: [January 26, 2026, 3:31pm UTC](https://meta.discourse.org/t/flagging-mass-postings-from-spam-attacks-is-onerous/381809/13 "2026-01-26T15:31:22Z")

</div>

> [@sam](#):
>
> I wonder if we should add a simple
> 
> 🗑 spam…

This would be a wonderful feature.
