How to Protect Your Discord Server from Phishing Links
Phishing links โ fake websites designed to steal Discord tokens or login credentials โ are rampant on Discord. Here's how to stop them.
How Discord Phishing Works
Typical attack pattern:
- A member's account is compromised
- The attacker DMs all server members with a fake link ("free Nitro," "Steam trade offer")
- Victims click, enter credentials, and their accounts are also compromised
- The cycle repeats
AutoMod Link Filtering
Set up Discord AutoMod to block suspicious links:
- Server Settings โ AutoMod
- Create a rule: "Block specific keywords"
- Add known phishing domains (discord-nitro.com, steamcommunity.ru, etc.)
- Action: Delete message + timeout sender for 1 hour
Also block:
- Links from accounts less than 7 days old
- Links from members who haven't verified yet
Bot Protection
Wick โ Specialises in security and phishing detection:
- Automatically detects known phishing domains
- Quarantines suspicious accounts
- Alerts staff immediately
BeepBot / PhishermanAPI bots โ Block links against community-maintained phishing databases.
Member Education
Pin a message in your server explaining:
โ ๏ธ Discord Scam Warning
Discord will NEVER DM you about free Nitro.
Do NOT click links claiming:
- "Free Discord Nitro"
- "Steam account verification"
- "Your account will be banned"
Report suspicious DMs to moderators immediately.
Responding to a Phishing Incident
- Immediately ban the compromised account
- Post a server-wide warning
- Lock channels temporarily if the attack is ongoing
- Advise members to enable 2FA and change passwords
- Report the account to Discord Trust & Safety
A secure server builds trust with members โ mention your security practices on Discords.ai.
Related: Discord Server Security Checklist ยท Discord Scam Prevention Guide