Spam protection
Group spam protection that adds up rather than guesses.
A spammer rarely trips one rule cleanly. They post the same thing four times, with the same link, to three groups, twenty minutes after joining. Sedge scores each of those signals and acts on the total.
Worked example
How a score of 135 is reached.
Five rules fired. None of them would have removed anybody on its own — the third and fourth are what pushed the total past the removal band.
The weights below are the platform defaults, unchanged. The message, the member and the link are sample values.
| Rule | Running total | Contribution |
|---|---|---|
Repeated content duplicate.repeated The same message had already been posted twice in the last hour.
| 30 | +30 |
Repeated links link.repeated The same link appeared in each copy.
| 60 | +30 |
Group invite spam link.invite_spam An invite link to another WhatsApp group, posted by a member who is not an admin.
| 95 | +35 |
Message flooding flood.burst Six messages inside the five-second window.
| 115 | +20 |
Previous warning history.prior_warning Warned nine days ago; the weight has decayed from 30.
| 135 | +20 |
| Total | threshold 100 | 135 |
The score reached 135 against a threshold of 100. The group is in monitor mode, so the member was removed only on paper — nothing changed in WhatsApp.
Thresholds
You decide what a score does.
Bands are yours. Move the removal band to 140 and Sedge becomes cautious; move it to 70 and it becomes strict. Both are one number.
- 0+No action
- 40+Logged
- 60+Warned
- 80+Sent to review
- 100+Removed
Strikes
A member who keeps tripping rules climbs a ladder rather than being judged fresh each time. Strikes expire after 90 days by default, and can be revoked by hand.
- strike 1Warning
- strike 2Enhanced monitoring
- strike 3Remove and send to review
New member probation
For the first 24 hours after joining, every rule weight is multiplied by 1.5 and a message cap of 20 applies in the first hour. Links and media can be blocked outright during probation if you want them to be.
The default rule set
Message flooding
Floodingflood.burst
Many messages sent in a short burst.
+20Repeated content
Repeated contentduplicate.repeated
The same or near-identical message posted more than once.
+30Repeated links
Linkslink.repeated
The same URL posted repeatedly, or an unusual number of links at once.
+30Group invite spam
Linkslink.invite_spam
Invite links to other WhatsApp groups, posted by a non-admin.
+35Blocked domain
Linkslink.blocked_domain
A link to a domain on the organization blocklist.
+50Mass mentions
Mentionsmention.mass
Tagging a large number of members at once.
+20Media flooding
Media floodingmedia.flood
Rapid runs of images, stickers, voice notes or video.
+20Promotional language
Words and phrasesphrase.promotional
Wording characteristic of advertising and recruitment spam.
+20Automated posting pattern
Posting patternbot.timing
Machine-like regularity, or the same content across many groups. Posting often is not enough on its own.
+20New member probation
New membersmember.probation
Stricter handling during a new member’s first hours in the group.
0Previous warning
Historyhistory.prior_warning
The member has been warned before.
+30Known offender
Historyhistory.known_offender
The member has been removed for spam before.
+40Trusted member
Historytrust.whitelisted
A whitelisted member. Negative weight, so trust actively offsets signals.
−100
Every rule can be re-weighted, switched off, or given a severity override that skips the score entirely — for a known malware domain, for instance.
Signals
What each kind of rule measures.
Naming the mechanism matters more than naming the threat. If you can predict what a rule will do, you can tune it.
- History
- What the member has done before.
- Flooding
- Message volume inside a rolling window.
- Repeated content
- The same message posted more than once.
- Links
- URLs, invite links and blocked domains.
- Mentions
- How many members a message tags.
- Words and phrases
- Wording you asked Sedge to watch for.
- New members
- Stricter handling in a member’s first hours.
- Posting pattern
- Machine-like regularity across messages.
- Media flooding
- Runs of images, stickers or voice notes.
Limits we will state plainly
What weighted scoring is not.
Any rule engine gets things wrong. The design assumes that rather than denying it.
- It does not understand the message. It counts, compares and matches. A sincere message that looks exactly like a scam will score like one, which is why nothing is removed without a review case.
- Posting a lot is not enough on its own. The posting-pattern rule needs machine-like regularity over at least six messages, or the same content in three groups, before it contributes anything.
- Trust is a rule too. A whitelisted member carries a weight of −100, so they have to trip almost everything at once before a score reaches a band that matters.
Tune it against your own traffic, not ours.
Change a weight and see the effect on a real recent message before you save it.