How do you block phishing links on Discord?
6
Configuration steps
5
Final tests
4
Errors solved
~7 min
Reading time
The answer
The short answer
Phishing links on Discord are blocked at three levels: a filter that removes the message before anyone clicks, an allowlist of trusted domains so the filter does not delete your partners' links, and a report queue through which members feed the threat database themselves. In Venon Security that is LinkShield's job, on the Panel → Security → Content protection screen. Members report suspicious addresses with the /report-link command or from the message context menu Report a suspicious link, and once the report threshold is crossed the domain is blocked automatically.
The content is checked against the bot's configuration — last verified: 2026-08-06.
Context
What the problem is
Phishing on Discord impersonates Nitro, a giveaway or a login page, and most often arrives from an account the victim knows. The compromised account sends the next round of messages, so one click turns into an avalanche. Deleting by hand is always late — the link has to disappear before anyone clicks it.
Without an extra bot
What you can do with Discord alone
- 01
Take the Embed Links permission away from @everyone on the channels where links are not needed.
- 02
In Discord's native AutoMod, enable the rule blocking suspicious links and invites.
- 03
Agree on a principle: nobody from the support team ever writes first in DMs or asks anyone to log in.
- 04
Pin a short set of instructions in the announcements channel on what to do after clicking a suspicious link (change the password, log out of all sessions, enable 2FA).
Venon Security
What Venon Security adds
LinkShield removes messages with suspicious domains and can apply a timeout or a ban once the violation limit is crossed.
Reports from members through /report-link and the context menu feed the threat database, and once the threshold is reached the domain is blocked automatically.
Trusted domains (the allowlist) protect partner links and official sources from being removed by accident.
Configuration
Configuration step by step
0 of 6 steps
Turn LinkShield on
Panel → Security → Content protection → Links and invites/venonsec-panelLinkShield is the layer specialising in addresses: it looks at the domain, the rate at which links are pasted and the reports, not at the message content.
- LinkShield active: on.
- Block Discord invites: on, unless you run partner exchanges in public channels.
- Log channel (ID): the staff channel where information about blocked addresses goes.
Set the link posting limits
Panel → Security → Content protection → Links and invitesA phishing campaign almost always looks like a series of messages with a link in a short time. A limit in a time window catches that pattern, even when the domain is brand new.
- Link spam limit: on.
- Max. links in the window and Window (seconds): 3 links per 20 seconds, for example.
- Timeout (minutes): a short break for an account that crossed the limit.
- Max. invite violations and Ban past the violation limit: enable deliberately, because that action cannot be undone for the member.
Add the trusted domains
Panel → Security → Content protection → Trusted domainsThe allowlist exists so the filter does not delete the links you care about — documentation, your shop, a partner's channel. Keep it short and review it every few months.
- Add only domains you genuinely trust and that you control or whose owner you know.
- Do not add link shorteners — any page at all can hide behind one shortened address.
- For every partner domain, agree who on the staff is responsible for reviewing it periodically.
Enable reports from members
Panel → Security → Content protection → Log channel and reports/report-linkThe community notices new campaigns faster than any list does. Reports turn that attention into automatic protection.
- Reports from members: on.
- Auto-block threshold (reports): the number of independent reports after which a domain is blocked automatically.
- The /report-link <url> [category] command accepts the categories: Scam, Phishing, Malware, Other.
- The same can be done without typing the address: the message context menu → Apps → Report a suspicious link.
Tell the community how to report
The reporting mechanism only works when people know about it. One pinned message raises the number of reports more than any threshold change.
- Say it plainly: do not click, report it through the message context menu.
- Explain that the report is anonymous to the rest of the server and goes only to the staff.
- Add instructions for the case where somebody did click: change the password, log out of all devices, enable 2FA.
Review the threat database
Panel → Security → Content protection → Threat databaseThe threat database shows the reports and the domains blocked automatically. A regular review catches both new campaigns and false reports.
- You can add an address by hand through the New domain and Threat category fields.
- Remove entries reported by mistake, so legitimate sites are not blocked.
- Schedule a review once a week — more often after a wave of phishing.
The steps you tick are saved in your browser — you can come back and finish later.
Verification
How to check the configuration worked
- 1
Paste an address you added to the threat database earlier into a test channel — the message should disappear, and an entry should appear in the LinkShield log channel.
- 2
Paste a link to a domain from the allowlist — it has to stay untouched.
- 3
Report any address with /report-link and check that it appeared in the Threat database section.
- 4
Paste three different links within a dozen seconds with the limit set — the link spam limit should fire.
- 5
Check that an invite to another Discord server is blocked, if you enabled Block Discord invites.
Diagnostics
When something does not work
The filter deletes partner and documentation links.
- Cause
- The domain did not make it onto the trusted list, or AutoMod is blocking all links.
- Fix
- Add the domain in the Trusted domains section and check that the Block links switch in AutoMod is not set too broadly.
Suspicious links still get through.
- Cause
- The campaign uses a fresh domain that is not in any database yet.
- Fix
- Enable the Link spam limit — it catches the behaviour pattern regardless of the domain — and lower the Auto-block threshold (reports), so the community closes new addresses faster.
Members do not report links.
- Cause
- Nobody knows the option exists, or reports are switched off.
- Fix
- Enable Reports from members and pin short instructions about the Report a suspicious link context menu in the announcements channel.
Somebody reports legitimate sites to get them blocked.
- Cause
- The auto-block threshold is too low for the number of active members.
- Fix
- Raise the Auto-block threshold (reports) and review the Threat database, removing wrong entries. Reports are visible to the staff, so abuse can be traced.
Honestly
What this configuration does not solve
No database knows a domain registered five minutes ago. The first messages of a new campaign can get through — which is why the rate limit and the reports matter.
Venon does not see private messages between members, and a large share of phishing on Discord goes exactly through DMs.
The bot will not recover a compromised account or undo the effects of entering a password on a fake page — that is a job for Discord's support and a password change.
The filter does not recognise the content of a page, only the address. A legitimate domain with a phishing subpage planted on it can get through.
Link shorteners and redirects limit how effective a domain filter can be — consider blocking them in public channels.
Commands
The commands used in this guide
/report-link
Report a suspicious link or domain to help protect the server
Permission: Public
/clear
Bulk-delete messages in this channel.
Permission: Manage Messages
/warn
Issue a warning to a user.
Permission: Moderate Members
/venonsec-panel
VenonSec: security and AutoMod control panel
Permission: Manage Guild
Read on
Related guides
How do you set up AutoMod on Discord?
How to set up AutoMod on Discord: anti-spam, anti-caps and mention-limit thresholds, word blacklists and actions per detector. With a test and the usual mistakes.
Read the guideHow do you protect a Discord server from a raid?
How to protect a Discord server from a raid: entry verification, AntiRaid thresholds, content protection and logs. Concrete settings, a test and the usual mistakes.
Read the guideHow do you clear spam on Discord?
How to clear spam on Discord: the /clear command, muting the author, the log entry and the AutoMod settings that stop it coming back.
Read the guide
FAQ
FAQ – common questions
Are domain allowlists safe?+
Yes, as long as they are short and reviewed regularly. The risk appears when adding link shorteners or services hosting arbitrary user content — one entry on the list then opens access to everything sitting under that domain.
Should you block all links on the server?+
Rarely worth it. A total block breaks normal conversation and teaches people to send addresses in DMs, where there is no protection at all. A combination works better: a domain filter, a rate limit and reports from members.
How do you report a suspicious link without copying the address?+
Right-click the message, choose Apps, then Report a suspicious link. The report goes into the threat database without the address being pasted into the chat, so nobody clicks it by accident.
What should you do when somebody has already clicked a phishing link?+
Change the password immediately, log out of all sessions in Discord's settings and enable 2FA. If the account started sending messages, give it a timeout until control is recovered and report the domain through /report-link.
Set this up in your own Venon Security panel
Every screen mentioned in the guide is in the web panel. You save the configuration by hand and see its state before anything takes effect on the server.
