How to Stop Spam Tickets and Ticket Scams in Discord
Four defences against Discord ticket spam, scams and impersonation: blacklist by role, anti-sniping protection, a form before the ticket opens, and one free policy.
Dani, Founder, AI Ticket Bot
6 min readUpdated
The four problems, which need different fixes
They get lumped together as "spam" and they are not the same:
- Ticket spam
- One person opening ticket after ticket, or a raid doing it at scale
- Ticket sniping
- Scammers watching for new tickets so they can DM the opener pretending to be staff
- Advertising tickets
- People opening a ticket to pitch you something
- Impersonation
- Someone with a copied name and avatar DMing your members "about their ticket"
Defence 1: blacklist, by user and by role
The obvious one, with a less obvious capability. On AI Ticket Bot the blacklist works by user or by role. Blocking a role blocks every member holding it.
Role blacklisting is the one that scales. If you have a "muted" or "restricted" role that moderation already applies, blacklisting that role means every moderation action automatically stops ticket abuse too, with no second step and nothing to remember.
Three details worth knowing. The blacklist scopes the ticket-opening privilege: a blacklisted member can still see a ticket channel they already have open until it closes, so it is not a server mute. Blocking an entire guild is an owner-level global action, not something a server admin does. And blocking somebody is its own staff permission, so a moderator can do it without holding Manage Server, which matters because the people who catch spam first are rarely the people you want administering the server.
The AI can also add someone to the blacklist itself, but the rules on that are deliberately narrow: two clear warnings and continued behaviour, and only for spam, repeated profanity at staff, prompt injection, scams or coordinated flooding. Never for disagreement, impatience, a single rude message, or a low-effort ticket.
Defence 2: anti-sniping protection
This one deserves explaining because the attack is not obvious.
When a ticket channel is created, that event is visible. A scam self-bot watching your server can correlate "channel created" with "which member just became able to see it" and work out who opened a support ticket. It then DMs that person, pretending to be staff, while they are actively waiting for help. That is the moment people are most likely to fall for it.
The defence is to break the correlation. AI Ticket Bot has an anti-DM setting: the ticket channel is created without the opener's view permission, then the opener is added a few seconds later, randomised. The event a scam bot is watching no longer identifies anybody.
What the anti-sniping toggle actually does
- Where
- Settings, Tickets tab. Server-wide switch
- Plan
- Free. No plan gate at all
- Default
- Off, because of the trade-off below
- The trade-off
- The opener waits those few seconds before seeing their own ticket
- Scope
- Channel-mode tickets. Thread mode is already member-scoped
- The catch
- It works best when your channel naming does not include the username. A channel called
ticket-someuserdefeats the whole thing
Defence 3: a form before the ticket opens
Requiring a short form does two things. It filters low-effort spam, because bots and drive-by advertisers do not fill in forms. And it improves the tickets you do get, because you have the information before the first reply.
Keep it to two or three fields. A long form deters legitimate members with a real problem, which is a worse outcome than the spam you stopped.
Modal forms at ticket open are a paid feature. If you have not paid, publishing your first panel starts 14 days of Premium with no payment method, which is enough to find out whether a form actually changes your spam rate before deciding.
Defence 4: make impersonation obvious
The most effective anti-scam measure costs nothing: publish that your staff never DM first, and then never DM first.
Where to put the policy
- In your server rules
- In the ticket panel description, where members read it right before opening one
- In the ticket welcome message, which is the moment they are most at risk
- Trained into your AI, so it says the same thing when anyone asks "is this staff member real"
Once members know the rule, an unsolicited DM is self-evidently a scam regardless of how convincing the profile looks. This works better than any technical control because it does not depend on catching the scammer. It removes their opening move.
What about rate limits?
Per-user throttles exist and help against the crude version of ticket spam. Set them loosely.
The reason: a member with a genuine urgent problem who accidentally closes their ticket and cannot open another is now a support problem you created. Closed tickets cannot be reopened, so a rate limit interacts badly with that. Rate limiting is a backstop, not a primary defence.
Defences ranked
| Defence | Effort | Effect | Trade-off |
|---|---|---|---|
| Publish "staff never DM first" | Minutes | High against impersonation | None |
| Blacklist by role | Minutes | High against repeat abuse | None |
| Anti-sniping protection | One toggle | High against DM scams | Opener waits seconds |
| Form before opening | 15 minutes | Moderate against low-effort spam | Deters some real members |
| Per-user rate limit | Minutes | Moderate against raids | Punishes legitimate members |
What does not work
Blacklist the account and the role it holds
The same person cannot simply come back in an hour
Delete the tickets and move on
Without a blacklist entry the same account is back before you finish
Keep the panel easy to find, and defend it properly
The people who need support are the ones who struggle to find things
Make the panel hard to find
It stops legitimate members far more effectively than spammers, who are looking for it deliberately
Use a moderation bot for content filtering
That is what it is for
Rely on your support AI to spot scams in general chat
A support AI answers questions. It is not a moderation system
If spam is a real share of your volume
Then it is a volume problem as well as a safety problem, and it belongs in the wider plan. Our guide to reducing ticket volume treats spam as one of eight levers rather than the whole picture, which is usually the right frame.
Keep reading
Frequently asked questions
Four defences cover almost all of it: blacklist repeat offenders by user or by role, turn on anti-sniping protection so scammers cannot work out who opened a ticket, require a short form before the ticket opens, and publish that your staff never DM first. Rate limits help too, but they punish legitimate members if set aggressively.
Scammers watch for new ticket channels being created, work out which member just gained access, then DM that person pretending to be staff while they are actively waiting for help. It works because the timing makes the DM look legitimate. The defence is to break the correlation between the channel being created and the opener gaining access.
On AI Ticket Bot, yes: the blacklist works by user or by role, and blocking a role blocks every member holding it. That is the one that scales, because if moderation already applies a muted or restricted role, blacklisting that role stops ticket abuse automatically with nothing extra to remember.
It filters low-effort spam well, because bots and drive-by advertisers do not fill in forms, and it improves the tickets you do get because you have the information before the first reply. Keep it to two or three fields; a long form deters legitimate members with a real problem.
Publishing that your staff never DM first, and then never DMing first. It costs nothing, works better than any technical control, and does not depend on catching the scammer, because it removes their opening move. Put it in your rules, your panel description and your ticket welcome message.
Set them loosely, as a backstop rather than a primary defence. A member with a genuine urgent problem who accidentally closes their ticket and cannot open another is now a support problem you created. Closed tickets cannot be reopened, so a tight rate limit interacts badly with that.
It’s not just an AI, it’s your AI.
See it on your own server.
Add the bot free, teach it a few of your most common answers, and watch it clear the repeat tickets on its own.
Free plan, no card. Your first panel starts 14 days of Premium.
Keep reading.
All articlesMinecraft Discord Ticket Bot: Store, Bans and Join Problems
A ticket bot lives in Discord and cannot see your Minecraft server. Which half of the queue an AI can close alone, and what every ticket must ask for first.
9 min read
Discord Support for Roblox Communities: The Tickets You Cannot Fix
A large share of a Roblox server's tickets are about Roblox, not about your game. Sort them by who can act, not by topic, and let the AI carry the redirects.
9 min read
Discord Support for Crypto Communities: When Support Is the Attack Surface
In a crypto Discord the support channel is what scammers impersonate, and a wrong answer costs money nobody can return. Run support through tickets.
9 min read