HomeFeaturesThreat-URL intel

Moderation

Threat-URL intel

Scammers do not need an invite — they need a fake nitro or steam URL that looks almost real. Threat-URL intel deletes those the moment they land.

  • Built-in bad hosts
  • Discord / Steam lookalikes
  • Admin extra blocklist
  • Strikes + cases

Why teams turn it on

Independent of the allowlist

Link filter answers “is this domain approved?”. Threat intel answers “is this domain dangerous?” — enable either or both.

Lookalike heuristics

Hosts that impersonate Discord or Steam without being official are treated as threats, not just an exact string match on yesterday’s scam list.

Staff visibility

Optional Case notes and strike counting feed the same escalation path as ads — jail after repeats if you want.

Escape hatch

Allowlist a host that was a false positive without turning the whole system off.

How it works

  1. 1. Extract links

    Every human message is scanned for link hosts the same way the link filter does.

  2. 2. Classify

    Built-in blocklist, your extras, then Discord/Steam lookalike rules (if enabled).

  3. 3. Remove and escalate

    Message deleted, optional DM, Case, and strikes toward jail at your threshold.

Real situations

Fake nitro paste

A user posts discord-nitro.gift — deleted even if “.gift” domains are not on your mind.

Steam gift phishing

Lookalike steamcommunity hosts trip without you hand-maintaining every typo domain.

Partner false positive

A rare host that looks suspicious but is yours goes on the allowlist once.

FAQ

Does this replace the link filter?

No. Use both: whitelist for “only these domains”, threat intel for “never these scams”.

Is the built-in list complete?

No list is. Lookalikes catch many variants; extra_blocklist covers what you still see.