# Spam alert: sneaky spammers

**URL:** https://meta.discourse.org/t/spam-alert-sneaky-spammers/319044
**Category:** Community Building
**Tags:** spam
**Created:** [July 29, 2024, 2:52pm UTC](https://meta.discourse.org/t/spam-alert-sneaky-spammers/319044 "2024-07-29T14:52:18Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![hellekin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hellekin/32/51636_2.png) [@hellekin](https://meta.discourse.org/u/hellekin)
#### Post date: [July 29, 2024, 2:52pm UTC](https://meta.discourse.org/t/spam-alert-sneaky-spammers/319044/1 "2024-07-29T14:52:18Z")

</div>

Hear, hear!

Some spammers found a sneaky way to bypass Discourse security. But not for long. Here’s what community moderators need to watch for:

1. New users with proper profile, three legitimate but low quality posts (or AI-generated content) with autobiographer, first like, first emoji, first reply badges
2. Next post is longer, seemingly more elaborate, and contains at least two links: _one of them is legitimate_ and _one of them is SEO spam_.
3. The SEO spam link has a short anchor that is hidden next to the legitimate link.

In other words, be watchful about seemingly enthusiastic new users who post short first contributions, and watch out for obfuscated links.

One of the trigger warnings is the discrepancy between email username (at usually some large provider) and the actual username; profile picture looks legit (and was probably stolen from an actual account.)

---

<div class="post-metadata">

### Author: ![putty](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/putty/32/370902_2.png) [@putty](https://meta.discourse.org/u/putty)
#### Post date: [July 29, 2024, 3:20pm UTC](https://meta.discourse.org/t/spam-alert-sneaky-spammers/319044/3 "2024-07-29T15:20:12Z")

</div>

Have you tried using Akismet? It auto-flags almost all the spam on our site.

> [@Discourse Akismet](https://meta.discourse.org/t/discourse-akismet/109337):
>
> discourse2Summary Discourse Akismet allows you to fight spam with [Akismet](https://akismet.com/), an algorithm used by millions of sites to combat spam automatically.hammer_and_wrenchRepository Link [https://github.com/discourse/discourse-akismet](https://github.com/discourse/discourse-akismet)open_bookInstall Guide [How to install plugins in Discourse](https://meta.discourse.org/t/install-plugins-in-discourse/19157)Features What does it do? Akismet helps keep your site free of spam by automatically scanning all posts from new users. Scanned posts that Akismet flags as spam are immediately removed f…

---

<div class="post-metadata">

### Author: ![hellekin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hellekin/32/51636_2.png) [@hellekin](https://meta.discourse.org/u/hellekin)
#### Post date: [July 29, 2024, 4:47pm UTC](https://meta.discourse.org/t/spam-alert-sneaky-spammers/319044/4 "2024-07-29T16:47:04Z")

</div>

No, I didn’t. Discourse trust levels have been working very well so far, and I think it’s important not to rely on more code for most of the use-cases. Minimalism is an important feature for me, and for future life on our planet.

I would suggest harder regulation against spammers (and the advertising industry in general) but this is another topic.

---

<div class="post-metadata">

### Author: ![guidoleenders](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/guidoleenders/32/196268_2.png) [@guidoleenders](https://meta.discourse.org/u/guidoleenders)
#### Post date: [September 20, 2024, 7:11am UTC](https://meta.discourse.org/t/spam-alert-sneaky-spammers/319044/5 "2024-09-20T07:11:46Z")

</div>

We have Akismet activated. Akismet does not flag it. See background on [Are you experiencing AI based spam? - #13 by guidoleenders](https://meta.discourse.org/t/are-you-experiencing-ai-based-spam/292707/13). In our case, using hotmail etc. is not possible, but then they revert to using temporary domains. Messages are quite well-crafted and seem realistic and relevant probably for most readers not looking for spam.

In the cases we have seen there are indeed sometimes replies without links and sometimes a double link is contained on the first reply.
