Skip to content

BlogPlaybooks

How to Stop Spam Tickets and Ticket Scams in Discord

Four defences against Discord ticket spam, scams and impersonation: blacklist by role, anti-sniping protection, a form before the ticket opens, and one free policy.

Dani, Founder, AI Ticket Bot

6 min readUpdated

The four problems, which need different fixes

They get lumped together as "spam" and they are not the same:

Ticket spam
One person opening ticket after ticket, or a raid doing it at scale
Ticket sniping
Scammers watching for new tickets so they can DM the opener pretending to be staff
Advertising tickets
People opening a ticket to pitch you something
Impersonation
Someone with a copied name and avatar DMing your members "about their ticket"

Defence 1: blacklist, by user and by role

The obvious one, with a less obvious capability. On AI Ticket Bot the blacklist works by user or by role. Blocking a role blocks every member holding it.

Role blacklisting is the one that scales. If you have a "muted" or "restricted" role that moderation already applies, blacklisting that role means every moderation action automatically stops ticket abuse too, with no second step and nothing to remember.

Three details worth knowing. The blacklist scopes the ticket-opening privilege: a blacklisted member can still see a ticket channel they already have open until it closes, so it is not a server mute. Blocking an entire guild is an owner-level global action, not something a server admin does. And blocking somebody is its own staff permission, so a moderator can do it without holding Manage Server, which matters because the people who catch spam first are rarely the people you want administering the server.

The AI can also add someone to the blacklist itself, but the rules on that are deliberately narrow: two clear warnings and continued behaviour, and only for spam, repeated profanity at staff, prompt injection, scams or coordinated flooding. Never for disagreement, impatience, a single rude message, or a low-effort ticket.

Defence 2: anti-sniping protection

This one deserves explaining because the attack is not obvious.

When a ticket channel is created, that event is visible. A scam self-bot watching your server can correlate "channel created" with "which member just became able to see it" and work out who opened a support ticket. It then DMs that person, pretending to be staff, while they are actively waiting for help. That is the moment people are most likely to fall for it.

The defence is to break the correlation. AI Ticket Bot has an anti-DM setting: the ticket channel is created without the opener's view permission, then the opener is added a few seconds later, randomised. The event a scam bot is watching no longer identifies anybody.

What the anti-sniping toggle actually does

Where
Settings, Tickets tab. Server-wide switch
Plan
Free. No plan gate at all
Default
Off, because of the trade-off below
The trade-off
The opener waits those few seconds before seeing their own ticket
Scope
Channel-mode tickets. Thread mode is already member-scoped
The catch
It works best when your channel naming does not include the username. A channel called ticket-someuser defeats the whole thing

Defence 3: a form before the ticket opens

Requiring a short form does two things. It filters low-effort spam, because bots and drive-by advertisers do not fill in forms. And it improves the tickets you do get, because you have the information before the first reply.

Keep it to two or three fields. A long form deters legitimate members with a real problem, which is a worse outcome than the spam you stopped.

Modal forms at ticket open are a paid feature. If you have not paid, publishing your first panel starts 14 days of Premium with no payment method, which is enough to find out whether a form actually changes your spam rate before deciding.

Defence 4: make impersonation obvious

The most effective anti-scam measure costs nothing: publish that your staff never DM first, and then never DM first.

Where to put the policy

  • In your server rules
  • In the ticket panel description, where members read it right before opening one
  • In the ticket welcome message, which is the moment they are most at risk
  • Trained into your AI, so it says the same thing when anyone asks "is this staff member real"

Once members know the rule, an unsolicited DM is self-evidently a scam regardless of how convincing the profile looks. This works better than any technical control because it does not depend on catching the scammer. It removes their opening move.

What about rate limits?

Per-user throttles exist and help against the crude version of ticket spam. Set them loosely.

The reason: a member with a genuine urgent problem who accidentally closes their ticket and cannot open another is now a support problem you created. Closed tickets cannot be reopened, so a rate limit interacts badly with that. Rate limiting is a backstop, not a primary defence.

Defences ranked

DefenceEffortEffectTrade-off
Publish "staff never DM first"MinutesHigh against impersonationNone
Blacklist by roleMinutesHigh against repeat abuseNone
Anti-sniping protectionOne toggleHigh against DM scamsOpener waits seconds
Form before opening15 minutesModerate against low-effort spamDeters some real members
Per-user rate limitMinutesModerate against raidsPunishes legitimate members

What does not work

  • Blacklist the account and the role it holds

    The same person cannot simply come back in an hour

  • Delete the tickets and move on

    Without a blacklist entry the same account is back before you finish

  • Keep the panel easy to find, and defend it properly

    The people who need support are the ones who struggle to find things

  • Make the panel hard to find

    It stops legitimate members far more effectively than spammers, who are looking for it deliberately

  • Use a moderation bot for content filtering

    That is what it is for

  • Rely on your support AI to spot scams in general chat

    A support AI answers questions. It is not a moderation system

If spam is a real share of your volume

Then it is a volume problem as well as a safety problem, and it belongs in the wider plan. Our guide to reducing ticket volume treats spam as one of eight levers rather than the whole picture, which is usually the right frame.

Frequently asked questions

Four defences cover almost all of it: blacklist repeat offenders by user or by role, turn on anti-sniping protection so scammers cannot work out who opened a ticket, require a short form before the ticket opens, and publish that your staff never DM first. Rate limits help too, but they punish legitimate members if set aggressively.

Scammers watch for new ticket channels being created, work out which member just gained access, then DM that person pretending to be staff while they are actively waiting for help. It works because the timing makes the DM look legitimate. The defence is to break the correlation between the channel being created and the opener gaining access.

On AI Ticket Bot, yes: the blacklist works by user or by role, and blocking a role blocks every member holding it. That is the one that scales, because if moderation already applies a muted or restricted role, blacklisting that role stops ticket abuse automatically with nothing extra to remember.

It filters low-effort spam well, because bots and drive-by advertisers do not fill in forms, and it improves the tickets you do get because you have the information before the first reply. Keep it to two or three fields; a long form deters legitimate members with a real problem.

Publishing that your staff never DM first, and then never DMing first. It costs nothing, works better than any technical control, and does not depend on catching the scammer, because it removes their opening move. Put it in your rules, your panel description and your ticket welcome message.

Set them loosely, as a backstop rather than a primary defence. A member with a genuine urgent problem who accidentally closes their ticket and cannot open another is now a support problem you created. Closed tickets cannot be reopened, so a tight rate limit interacts badly with that.

It’s not just an AI, it’s your AI.

See it on your own server.

Add the bot free, teach it a few of your most common answers, and watch it clear the repeat tickets on its own.

Free plan, no card. Your first panel starts 14 days of Premium.