Moderation
Threat-URL intel
Scammers do not need an invite — they need a fake nitro or steam URL that looks almost real. Threat-URL intel deletes those the moment they land.
- Built-in bad hosts
- Discord / Steam lookalikes
- Admin extra blocklist
- Strikes + cases
Why teams turn it on
Independent of the allowlist
Link filter answers “is this domain approved?”. Threat intel answers “is this domain dangerous?” — enable either or both.
Lookalike heuristics
Hosts that impersonate Discord or Steam without being official are treated as threats, not just an exact string match on yesterday’s scam list.
Staff visibility
Optional Case notes and strike counting feed the same escalation path as ads — jail after repeats if you want.
Escape hatch
Allowlist a host that was a false positive without turning the whole system off.
How it works
1. Extract links
Every human message is scanned for link hosts the same way the link filter does.
2. Classify
Built-in blocklist, your extras, then Discord/Steam lookalike rules (if enabled).
3. Remove and escalate
Message deleted, optional DM, Case, and strikes toward jail at your threshold.
Real situations
Fake nitro paste
A user posts discord-nitro.gift — deleted even if “.gift” domains are not on your mind.
Steam gift phishing
Lookalike steamcommunity hosts trip without you hand-maintaining every typo domain.
Partner false positive
A rare host that looks suspicious but is yours goes on the allowlist once.
FAQ
Does this replace the link filter?
No. Use both: whitelist for “only these domains”, threat intel for “never these scams”.
Is the built-in list complete?
No list is. Lookalikes catch many variants; extra_blocklist covers what you still see.