Svenska

All help

Raids and mass spam

Every feature these pages present as available is listed as shipped in docs/claims.yaml with its tests, and the build checks it. The sources behind each section are in the documents themselves, for anyone who wants to check us.

A raid is a wave of new accounts that join at once to flood, spam or scare a group. This page says what protects your group today, what only you can switch on in Telegram, and what to do after an attack. The shields that will stop a raid by themselves are built but not switched on; they are under "Coming" at the end, so you know what is on its way and do not plan around it yet.

What protects your group today

  • You can ban, mute and restrict from a reply, a user ID or a @username the bot has seen in the group, with a reason.
  • If you run several groups, one ban can cover all of them. The other groups see that the ban came from elsewhere, never from where.
  • If the bot loses an administrator right it needs, you hear about it in private, at once.
  • A ban for a serious violation of Telegram's terms leaves one line, with no text and no media, and is never lifted by a rule. Only a person can lift it.

No automatic shield acts on your group today. Until the shields are switched on, your defence is your own bans, Telegram's settings below, and the people who moderate.

Telegram's own settings

These are Telegram's settings for your group, not the bot's. The bot cannot switch them on or off; only an administrator with the right can, in the group's settings in the Telegram app. We have not checked where each one sits in the app, so look for the nearest name in your group's settings, or ask the person who set the group up.

SettingWhat it does
Join requestsSomeone who joins without an invite link must be approved by an administrator first, so a wave of joins does not get in by itself. It does not stop a raid that comes in through a leaked invite link; a link can be made to require approval too
Slow modeA member can send one message per interval you choose
Member permissionsWhat every member may do by default, such as sending messages or link previews. Link previews are a permission of their own
Aggressive anti-spamTelegram's own spam protection in a stricter mode. Administrators of larger groups can turn it on; Telegram said over 200 members in 2022
Hidden membersThe member list is hidden
Boosts that skip restrictionsMembers who boost the group as many times as you set are not held by slow mode or member permissions
Invite linksThe bot can revoke only links it made itself. Links made by other administrators stay open, and so does a public group's name

The bot cannot read these settings for you, so it cannot remind you if slow mode is off or join requests are not on. Check them yourself. The bot also never changes the group's default permissions on its own: a change like that has no end date, and if the bot stopped, the group would stay locked. To close the group, change the permissions yourself in Telegram.

What the bot watches

The bot needs two rights: delete messages, and restrict or ban members. It checks that it still has them on every change to its own rights and once a day. If one is lost, you get a private message that says which: "WardForth can no longer delete messages in this group", or "WardForth can no longer restrict or ban members in this group". The bot cannot take a right back; an administrator with that right gives it. The message reaches you only if you have opened a private chat with the bot, so do that now if you have not.

After an attack

Do these in order, and stop at the step that solves it.

  1. Check Telegram's settings. If the attack is still going, turn on join requests and slow mode. Only you or another administrator can do that; the bot cannot do it for you.
  2. Ban the accounts. Reply to one of their messages with /ban, or name the account by user ID or by a @username the bot has seen in the group (an unseen one is refused), and choose a reason. Several groups? One ban can cover all of them. Three things to know:
    • In a supergroup, a ban deletes all of that person's messages in the group. That helps against spam, but the messages cannot be brought back, so ban the right accounts.
    • WardForth keeps no copy of the group's messages. It cannot restore a message or the group's history.
    • The shortest ban or mute is one minute. A ban with no stated time lasts the group's period, and a longer time than the period is refused. A mute or a restriction needs a time, from one minute to just under a year.
  3. If the bot lost a right, give it back. The private message says which one. Ask an administrator with that right to give it to the bot again. Until then, bans and deletions do not work, and the bot says so when someone tries. If the bot was removed from the group, bans of up to a year end by themselves in Telegram; longer bans stay until an administrator lifts them.
  4. Look at what happened. The bot keeps a history of bans, mutes and restrictions. Reading it in the bot, with /log, /history and /bans, is built but not yet listed as available, so this page does not promise it.
  5. Protect your own account. WardForth has no login of its own in the beta. Your Telegram account is the key to your group's bot, and whoever takes it over can act as you. Turn on Two-Step Verification and a passkey on your Telegram account.

If the bot did something nobody asked for, or your account is no longer yours, that is a security matter and not a moderation one, and the operator of WardForth must hear of it at once. The channel for reaching the operator is not decided yet, so this page names none.

Coming

Not available yet. A feature moves up when it ships and its tests exist.

Everything below is built and tested, and none of it is switched on in the running bot. Do not plan around it yet. It moves out of this part when it is switched on.

How the shields will work

  • Shadow mode first. Every new rule starts in shadow mode: it records what it would have done and sends nothing to the group. You turn it on when you have seen the results. A rule has three modes: shadow, on and off.
  • Message text is judged in memory and never stored. A shield's own log keeps only the rule, the outcome, the time and the group. When a live shield mutes or bans someone, the ordinary entry for that member is written too, with the reason, as for a ban you make yourself. Warning points are stored per member until they expire. Both follow the group's period. No message text is in any of them.
  • A shield uses one of the five ordinary reasons. It can never use the reason for a serious violation of Telegram's terms. Only a person can.
  • A shield never changes the group's default permissions. Its actions are delete, mute, ban, remove and lift.

The shields

ShieldWhat it will do
Join gateA new member must pass a check before they can post: one button, a sum, or a question you write with two to four answers. The member is held until then
Raid shieldA wave of joins closes the gate for a while. Each new joiner is held, and the gate reopens by itself. You get a private message with an "Open now" button
Flood filterToo many messages from one member, or from the whole group, in a short time: the messages are deleted or the member is muted
Link filterAllowed and blocked domains, invite links, hidden links, and stricter rules for new members
Word filterYour own words, patterns and expressions. A hit is logged as the rule, never as the text
Warning pointsPoints that rise with each warning and expire. Each step on the ladder is a mute or a ban

None of the shields reads pictures, video or other media. The filters look at text, links and the shape of a message, and nothing else.

Three presets, from most closed to most open

A preset is a named set of choices. No preset contains a number: no source gives a default for a count or a length, so the numbers are yours, and the next table gives the range the bot accepts.

Whatever you choose, start every shield in shadow mode and move it to "on" one at a time, after you have seen what it would have done. A row without "action" is the shield's mode: shadow, on or off. A row with "action" is what the filter does when it acts: delete or mute.

"New members may post no link at all" does nothing until a new-member period is set. It applies only to members who joined less than that period ago, and a period of 0 turns it off.

SettingClosedBalancedOpen
Join gateononshadow
Challenge kindquestionsumbutton
If the member does not answer in timeremoveremovestay restricted
Raid shieldononon
Flood filterononshadow
Flood filter, actionmutedeletedelete
Link filter: block invite linksyesyesyes
Link filter: block hidden linksyesyesno
Link filter: new members may post no link at all (needs a new-member period above 0)yesnono
Link filter, actiondeletedeletedelete
Word filteron, with your wordson, with your wordsoff
Warning pointson, ladder ends in a banon, ladder with mutes onlyoff

Three things to know about the presets:

  • The order of the challenge kinds is our reading, not a measured fact: a question you wrote yourself cannot be answered by a script that knows nothing about your group, and a single button is the easiest to pass.
  • "Remove" is not a ban. The member can come back and try again. And removal on timeout cannot be carried out yet: a member who misses the time stays restricted until the hold ends by itself. Do not count on "remove" until this page says it works.
  • A ban step on the warning ladder deletes all of that member's messages in a supergroup. Look at that before you choose a ban as a step.

The numbers you choose

SettingWhat it meansAccepted
Joins before the gate closesMore than this many joins within the window closes the gate3 to 10000
Window for the joinsThe time in which the joins are counted10 to 3600 seconds
How long the gate stays closedAfter this it reopens by itself60 to 86400 seconds
Time to answer the gateHow long a new member has30 to 3600 seconds
Restriction if the member stays restrictedHow long30 seconds to 366 days
Messages per memberAbove this, the flood filter acts2 to 1000
Messages for the whole groupOptional. Leave empty to count members only2 to 100000, or empty
Flood windowThe time in which messages are counted1 to 3600 seconds
Mute length (flood, links, words)How long a mute lasts30 seconds to 366 days
New-member period for linksA member who joined less than this long ago is new. 0 turns it off0 to 2592000 seconds
Allowed and blocked domainsLower-case host namesup to 200 of each
WordsA word, a pattern or a regular expression, 1 to 200 charactersup to 200
Warning ladderSteps with points that rise, each a mute or a ban1 to 10 steps, points 1 to 100
Warning points expire afterDays1 to 365

Telegram makes a restriction or a ban shorter than 30 seconds or longer than 366 days permanent, which is why nothing outside that range is accepted. The ranges say what the bot accepts, not what is right for your group. A group that wants numbers from its own rhythm will get recommendations from Group DNA once it ships.

What the shields cannot promise in a raid

  • Telegram publishes no limit for restricting, banning or deleting, only for sending messages. A raid of hundreds of joins means hundreds of calls at a rate nobody has published. Joiners who are not yet held when Telegram slows the bot down can post.
  • A restart forgets an open closure and its held members. Their holds end by themselves, and the owner is not told that the gate reopened.
  • Join requests that arrive while the gate is closed are left pending, and you are told how many wait. Whether Telegram expires or caps pending requests is not known.
  • A held member that is a bot account walks free when the hold ends, if WardForth was down.
  • A member can post a clean message and then edit a link into it. The bot now receives edited messages from Telegram, but they are not handed to the filters yet, so an edit is not checked.

The message you will get

This is an illustration, not real data. It shows the shape of the private message the raid shield will send you when it closes the gate:

Gate closed. N joins in M minutes. It reopens at HH:MM, or now if you say so.

N, M and HH:MM are filled in from your own group's joins. The "Open now" button works only for the owner of that group, and the change is written to the audit log.

Reading what the shields did

The panel's Trail screen and the shield summaries, such as "would have stopped N", are planned. They are not shipped, and this page does not promise them.