스팸 방지 팁

:bookmark: 이 문서는 Discourse 포럼에서 스팸을 방지하는 방법에 대한 포괄적인 가이드를 제공하며, 스팸 없는 커뮤니티 환경을 유지하는 데 도움이 되는 다양한 설정 및 도구에 대한 정보를 포함합니다.

:person_raising_hand: 필요한 사용자 권한: 관리자

대부분의 포럼에서는 스팸이 드뭅니다. 그러나 사이트에서 스팸 문제로 어려움을 겪고 있다면, Discourse에는 스팸을 자동으로 방지하는 데 도움이 되는 수많은 도구가 제공됩니다.

다음 가이드는 커뮤니티에 긍정적인 환영 환경을 유지하면서 스팸을 방지하는 데 도움이 되는 몇 가지 권장 사항을 제공합니다.

Discourse AI를 활용한 스팸 감지

AI 스팸 감지는 자동화된 스팸 감지를 위한 최고의 Discourse 기능 중 하나입니다. 다른 도구와 달리, 이는 사전에 구성된 규칙에 기반하여 사용자와 게시물을 자동으로 차단할 수 있습니다. AI 스팸 감지는 Discourse 호스팅의 모든 사용자에게 제공되며, LLM이 구성된 셀프 호스팅 사이트에서도 사용할 수 있습니다.

AI 스팸 감지의 이점은 다음과 같습니다:

  • 자동화: 명백한 스팸을 차단하는 데 수동 개입이 필요하지 않습니다.
  • 커스터마이징: 커뮤니티의 고유한 요구 사항에 맞게 조정할 수 있습니다.
  • 확장성: 커뮤니티가 집중적인 스팸 공격을 받아도 잘 작동합니다.
  • 광범위한 호환성: GPT-4, Claude 3.5, Gemini Flash와 같은 무료(Discourse 호스팅에서) 또는 비용 효율적인 LLM도 스팸 감지를 효과적으로 처리할 수 있습니다.

AI 스팸 감지 설정

:megaphone: 이제 Starter 및 Standard 고객의 경우 기본적으로 활성화되어 있습니다.

관리자 설정 → 플러그인 → AI → 스팸 처리에서 단순히 활성화하십시오 (상세 정보).

기본적으로 Discourse가 우리 사이트를 위해 조정된 프롬프트를 사용하지만, 사이트 특성에 맞는 사용자 지정 지침을 추가할 수 있습니다.

조정된 프롬프트 예시

:information_source: Discourse AI 를 사용하면 창의적인 AI 봇을 사용하여 사이트의 필요에 맞는 조정된 프롬프트를 생성할 수도 있습니다.

기본 신뢰 수준

사이트의 신규 사용자의 기본 신뢰 수준은 .../admin/site_settings/category/trust 페이지에서 조정할 수 있지만, 기본 신뢰 수준을 0으로 유지하는 것을 권장합니다.

이 설정의 값을 수정했다면, 신뢰 수준이 Discourse의 스팸 관련 설정과 상호작용하는 방식 때문에 이 설정을 변경하면 사이트에 심각한 스팸 위험을 초래할 수 있으므로 0: 신규 사용자로 되돌리는 것을 강하게 권장합니다.

스팸 관련 사이트 설정

:warning: 스팸으로 특별한 어려움을 겪고 있지 않다면, 다음 설정을 기본값으로 유지하는 것을 권장합니다.

Discourse에는 사이트의 .../admin/config/spam 페이지에서 접근할 수 있는 여러 스팸 관련 사이트 설정이 있습니다.

이 설정들은 스팸 감지 민감도를 높이거나 낮추고, 스팸 게시와 관련된 결과의 엄격성을 조정하는 데 사용할 수 있습니다.

다음은 사이트에서 스팸이 처리되는 방식에 눈에 띄는 영향을 미치는, 더 자주 조정되는 스팸 관련 설정 중 일부입니다.

모든 설정의 기본값은 아래에 표시되어 있습니다.

게시물 숨김

게시물 숨김 민감도게시물 숨김 후 쿨다운 분 설정은 표시된 게시물이 Discourse에 의해 자동으로 숨겨질 가능성과 사용자가 표시되고 숨겨진 게시물을 편집할 수 있기까지 기다려야 하는 시간을 제어합니다.

신규 사용자 무음 처리

Discourse에는 신규 사용자 무음 처리 사용자 수 사이트 설정이 있으며, 이는 특정 수의 고유 사용자에 의해 스팸으로 표시된 경우 신규 사용자를 자동으로 무음 처리합니다.

기본값은 3으로 설정되어 있으므로, 동일한 사용자(들)로부터 계속되는 스팸 문제로 어려움을 겪고 있다면 이 값을 낮추는 것을 고려할 수 있습니다.

링크 제한

Discourse는 신규 사용자 스팸 호스트 임계값 설정을 사용하여 외부 도메인으로의 링크를 포함할 수 있는 신규 사용자의 게시물 수를 제한합니다. 사이트의 신규 사용자가 동일한 도메인으로의 링크를 자주 스팸으로 남기는 경우, 이 설정의 값을 낮추는 것을 고려할 수 있습니다.

IP 주소 제한

Discourse는 주어진 IP 주소에서 사용자가 만들 수 있는 신규 계정 수를 제한합니다. 사이트의 문제 있는 사용자가 사이트를 스팸으로 남기기 위해 계정을 반복적으로 생성하는 것을 발견했다면, 기본값에서 이 값을 낮추는 것을 고려할 수 있습니다.

또한, 사용자가 여러 계정을 생성한 후 동일한 주제에 댓글을 남기는 것을 방지하기 위해 활성화할 수 있는 소캅펫 표시 체크박스가 있습니다:

추가로, 문제 있는 사용자의 IP 주소를 관리 페이지의 마지막 IP 주소등록 IP 주소 필드에서 수동으로 조회하고, 동일한 IP 주소와 연관된 다른 계정을 삭제할 수 있습니다.

또는 “로그 → 차단된 IP” 페이지(.../admin/logs/screened_ip_addresses)에서 스팸머가 사용하는 IP 주소를 차단하는 것을 고려하십시오:

표시 요구 사항 조정

기본적으로, 주제는 Discourse가 해당 주제에 대한 게시를 자동으로 중단하기 전에 5명의 고유 사용자에게 표시되어야 합니다.

주제 닫기 표시자 수 사이트 설정을 조정하여 주제에 대한 게시를 중단하는 데 필요한 표시자 수를 높이거나 낮출 수 있으며, 주제 자동 닫기 민감도 설정을 조정하여 해당 주제가 대신 자동으로 닫힐 가능성을 변경할 수 있습니다.

감시 단어

감시 단어는 스팸머가 반복적으로 사용할 수 있는 단어, 구문 또는 URL 링크를 포함하는 게시물을 차단하거나 제한하는 데 도움이 되는 또 다른 훌륭한 기능입니다.

스팸머가 게시물에서 동일한 유형의 텍스트를 자주 사용하는 것을 발견했다면, 사이트에 “차단” 또는 “무음” 단어를 추가하는 것을 고려하십시오.

감시 단어의 더 고급 사용을 위해, 감시 단어와 함께 정규식 사용도 고려할 수 있습니다.

신뢰 수준 요구 사항 강화

스팸이 주로 TL0 사용자로부터 온다는 것을 발견했다면, TL1에 도달하는 것을 더 어렵게 만들기 위해 일부 신뢰 수준 설정을 조정하는 것도 좋습니다:

hCaptcha 플러그인

Discourse Captcha 플러그인은 로컬 가입 양식에 hCaptcha를 통합하여 보안과 봇 보호를 강화하는 것을 목표로 합니다.

:sparkles: 모든 Discourse 호스팅 사이트에서 이 플러그인은 자동으로 포함됩니다.

추가 단계

사용자가 왜 사이트를 스팸으로 남기는지 이해하는 것이 중요합니다. 그들은 지루해서, 악의적이거나, 자신을 홍보하려는 것일까요?

어려운 사용자를 다루는 제안과 다양한 다른 조정 주제는 Discourse 조정 가이드에서 찾을 수 있으며, 사이트 조정에 대한 추가 아이디어를 얻기 위해 이 가이드를 읽어보는 것이 좋습니다.

위 내용 외에도, 단기적으로 조정 팀을 강화하여 전체적인 커버리지를 갖추는 것은 스팸과의 싸움에서 또 다른 좋은 접근 방식입니다. 핵심은 문제 있는 사용자를 지치게 하여 그들이 지루해지고 떠나게 만드는 것입니다.

이 가이드를 거친 후에도 계속 스팸 문제로 어려움을 겪고 있다면, 게시물 승인 수, 허용된 그룹 제외 승인, 또는 허용된 그룹 제외 신규 주제 승인 설정을 사용하여 신규 사용자의 모든 게시물 또는 일부 게시물을 검토 대기열에 넣는 것을 고려할 수 있습니다:

허용된 그룹 제외 승인 설정은 지정된 그룹에 속하지 않는 사용자가 만든 게시물의 승인을 요구합니다. 관리자 및 모더레이터가 만든 게시물은 항상 승인됩니다.

허용된 그룹 제외 신규 주제 승인 설정은 지정된 그룹에 속하지 않는 사용자가 만든 신규 주제의 승인을 요구합니다. 관리자 및 모더레이터가 만든 주제는 항상 승인됩니다.

그러나 게시물이 승인되지 않으면 신규 사용자가 사이트에 상호작용을 시작하기가 어려워질 수 있으므로, 이를 처리할 충분한 모더레이터가 있는지 확인하는 것이 중요합니다.

18개의 좋아요

I cant speak for all forums but I forum I used to be on as TL3 there was at least one spam post still up when I logged on for the first time for the day in my watched categories. And the one I’m currently a mod on we get an average of 2 or so spam posts a day. So I think it is some what common on a lot of forums based on that

5개의 좋아요

One very useful regular expression is \d{3}-\d{4}|[\w+\-.]+@[a-z\d\-]+(\.[a-z\d\-]+)*\.[a-z]+ which blocks email addresses and phone numbers. Don’t forget to enable settings - posting - “watched words regular expressions”.

7개의 좋아요

Hey :wave:

I’ve been making great use of these tips on my forum so…thank you! :heart:

Is there a setting that can be enabled that sends only new users signing up from say a gmail.com domain, to the review queue?

Currently, I have all new users sent to the queue for review but I’ve found the majority of the spam users are ones that are created using a gmail email. Sending only those to the review queue would reduce to load and the review time, for me at least :sweat_smile:

1개의 좋아요

@SaraDev Do you know if this is possible? I’ll love to know too as it would be very helpful to block not just IPs but specific domains!

1개의 좋아요

There is no core Discourse feature to send posts only from users on a specific domain (e.g., gmail.com) to the review queue.

The closest related feature is the auto approve email domains site setting, which allows certain email domains to bypass the manual user approval process by automatically approving users from those domains.

There are also settings for blocked email domains and allowed email domains that provide a way to restrict or control who can register on your site based on their email domains:

However, these settings would all require the must approve users setting to be enabled, and only impact users initially registering on a site, and not the interaction between creating posts and the review queue.

As a workaround, you could use Groups to accomplish a similar functionality though. For example, you could create a custom group and automatically add users who register with a specific email address to the group, and then add this group to the approve unless allowed groups and approve new topics unless allowed groups setting.

With this type of setup, you could effectively bypass the review queue for users with a specific domain, while still sending other posts to the review queue if desired.

2개의 좋아요

Hi, I was wondering whether it is possible to force a captcha on topic and/or post creation?

I don’t know, but what it helps if a bot can bypass captcha when login? Then it can do same when publishing,

True, but there seems to be captcha support for registration, so I was wondering whether the same exists for topic/post creation.

We’ve seen a number of clients hit by large spam attacks lately, and what they all had in common is that they opened up one or more categories to everyone - create, bypassing all trust level restrictions.

For seasoned Discourse admins it’s obvious that this is a bad idea, but for less experienced people it’s not. So it might be a good idea to state the (for us) obvious and add this to the start post of the topic.

7개의 좋아요

Lately, we’ve been dealing with spammers who use automatic registration and then try creating new topics with AI-generated content that looks like genuine requests for advice, but includes Amazon affiliate links. They usually mask those links with various URL shortener engines. They are able to respond to replies and even can chat in PM in a funny way. Has anyone experienced this? I wonder if, since these attempts seem to be fully automated, there would be plenty of other targeted Discourse forums. Do you have any advice on a strategy for cutting them loose?

1개의 좋아요

Hi @Overgrow,

A few ideas you could try here to prevent this:

  • Use Discourse AI - AI triage to Set up spam detection in your community to detect this type of content
  • Add URL shorteners and Amazon affiliate link patterns to your blocked watched words list
  • Lower the newuser spam host threshold and increase requirements for TL1
  • Reduce max new accounts per registration IP and enable flag sockpuppets
  • Use the Discourse hCaptcha plugin to help prevent automated spam/AI registrations on your site.
  • Consider placing all new user content in the review queue until the attack subsides by adjusting:
    • approve post count
    • approve unless trust level
    • approve new topics unless trust level

The approach here will be similar to preventing spam in general, with more of a focus specifically on the shortened URLs, and AI generated content.

For your case here, you could try using an AI prompt for specifically detecting AI content like the following:

You are a spam detection system. Analyze the following content and context.

Notes:
- Replies must remain relevant to the discussion thread.
- Mark as SPAM if the content is irrelevant, promotional, or automated.
- Consider new user posts with links as potential SPAM unless explicitly relevant to the topic.

Watch for content that appears authentic but has unnatural patterns. 
Look for text with peculiar phrasing, excessive formality mixed with 
casual language, or generic advice that doesn't quite fit the context. 
Flag content containing hidden affiliate links, especially when the post 
seems designed to naturally lead to product recommendations.

Pay special attention to these red flags:
1. Content that poses as genuine advice requests but contains promotional elements
2. Posts that introduce a problem and then suggest specific products as solutions
3. The presence of URL shorteners (bit.ly, tinyurl, t.co, goo.gl, etc.) which may disguise affiliate links
4. Amazon product links or references, especially with affiliate parameters (tag=, ref=, affiliate=)
5. Content that seems to ask for recommendations but subtly steers toward specific products
6. Artificial quality text - overly formal language mixed with casual expressions or awkward structure
7. New accounts posting content with any of the above patterns

Respond only with "SPAM" or "NOT SPAM".
3개의 좋아요

Having a lot of trouble with bot accounts lately. Ive had to disable new user registrations for the second time. Yesterday had to delete 50 odd bot accounts with roughly 30 spam posts. Have already enabled hcaptcha with a difficult puzzle but hasn’t stopped them. Was on 3.5.0 but just updated to 3.6.0 just after the attack. We already don’t allow links at trust level 0 and require 30 posts before allowing links, but these posts are just walls of text about travel agents and other random nonsense. Had also had AI accounts and posts that refer to actual forum content but don’t quite make sense. Those are somewhat entertaining for our user base, but anyway, I didn’t want to enable AI on the forum but i feel i have exhausted all other options. However, i get this message:

But I don’t see anywhere to add said configuration?

Above all, while the AI might help with the spam, I don’t think that enabling this will help with the bot accounts being created in the first place or am I wrong?

1개의 좋아요

If approve post count is set to 1. Then is modifying these still needed?

I honestly don’t know the answer to that question.

Yes, if approve_post_count is set to 1, you should still review those other settings.

How these settings interact:

approve_post_count (set to 1):

  • Affects users with trust level 0 and 1
  • Requires their first post to be approved
  • After 1 approved post, they can post freely (assuming they’re still TL0 or TL1)

approve_unless_allowed_groups (formerly approve_unless_trust_level):

  • Affects everyone not in the specified groups
  • Requires all posts (not just the first one) to be approved

approve_new_topics_unless_allowed_groups (formerly approve_new_topics_unless_trust_level):

  • Affects everyone not in the specified groups
  • Requires approval only for new topics (not replies)

The key difference:

  • approve_post_count is temporary - once users hit the count threshold, they can post freely
  • The “unless allowed groups” settings are ongoing - they apply to ALL posts/topics from users not in the specified groups, regardless of how many posts they’ve made

You could also combine settings for better control over posting on your site, for example:

  • Use approve_post_count: 1 to review initial posts from new users (TL0/TL1)
  • Use approve_unless_allowed_groups settings for ongoing moderation of everyone except specific groups (e.g., TL2+ members)

This creates an approach where new users are moderated initially, and you could also control who gets ongoing freedom to post without approval.