Skip to content

Spam protection

Group spam protection that adds up rather than guesses.

A spammer rarely trips one rule cleanly. They post the same thing four times, with the same link, to three groups, twenty minutes after joining. Sedge scores each of those signals and acts on the total.

Worked example

How a score of 135 is reached.

Five rules fired. None of them would have removed anybody on its own — the third and fourth are what pushed the total past the removal band.

The weights below are the platform defaults, unchanged. The message, the member and the link are sample values.

Score135over threshold 100
Sample valuesSimulatedRemoved
Every rule that contributed to a score of 135, against a threshold of 100.
RuleRunning totalContribution

Repeated content

duplicate.repeated

The same message had already been posted twice in the last hour.

occurrences
3
window
3,600 s
similarity
97%
across groups
yes

30

+30

Repeated links

link.repeated

The same link appeared in each copy.

domain
promo-signals.example
links
1
occurrences
3

60

+30

Group invite spam

link.invite_spam

An invite link to another WhatsApp group, posted by a member who is not an admin.

invite links
1
invite code
K3f…9pQ

95

+35

Message flooding

flood.burst

Six messages inside the five-second window.

messages
6
window
5 s
limit
5

115

+20

Previous warning

history.prior_warning

Warned nine days ago; the weight has decayed from 30.

prior warnings
1
days since
9
rule weight
30
decayed by
33%

135

+20
Total
threshold 100
135

The score reached 135 against a threshold of 100. The group is in monitor mode, so the member was removed only on paper — nothing changed in WhatsApp.

Thresholds

You decide what a score does.

Bands are yours. Move the removal band to 140 and Sedge becomes cautious; move it to 70 and it becomes strict. Both are one number.

  1. 0+No action
  2. 40+Logged
  3. 60+Warned
  4. 80+Sent to review
  5. 100+Removed

Strikes

A member who keeps tripping rules climbs a ladder rather than being judged fresh each time. Strikes expire after 90 days by default, and can be revoked by hand.

  1. strike 1Warning
  2. strike 2Enhanced monitoring
  3. strike 3Remove and send to review

New member probation

For the first 24 hours after joining, every rule weight is multiplied by 1.5 and a message cap of 20 applies in the first hour. Links and media can be blocked outright during probation if you want them to be.

The default rule set

  • Message flooding

    Flooding

    flood.burst

    Many messages sent in a short burst.

    +20
  • Repeated content

    Repeated content

    duplicate.repeated

    The same or near-identical message posted more than once.

    +30
  • Repeated links

    Links

    link.repeated

    The same URL posted repeatedly, or an unusual number of links at once.

    +30
  • Group invite spam

    Links

    link.invite_spam

    Invite links to other WhatsApp groups, posted by a non-admin.

    +35
  • Blocked domain

    Links

    link.blocked_domain

    A link to a domain on the organization blocklist.

    +50
  • Mass mentions

    Mentions

    mention.mass

    Tagging a large number of members at once.

    +20
  • Media flooding

    Media flooding

    media.flood

    Rapid runs of images, stickers, voice notes or video.

    +20
  • Promotional language

    Words and phrases

    phrase.promotional

    Wording characteristic of advertising and recruitment spam.

    +20
  • Automated posting pattern

    Posting pattern

    bot.timing

    Machine-like regularity, or the same content across many groups. Posting often is not enough on its own.

    +20
  • New member probation

    New members

    member.probation

    Stricter handling during a new member’s first hours in the group.

    0
  • Previous warning

    History

    history.prior_warning

    The member has been warned before.

    +30
  • Known offender

    History

    history.known_offender

    The member has been removed for spam before.

    +40
  • Trusted member

    History

    trust.whitelisted

    A whitelisted member. Negative weight, so trust actively offsets signals.

    −100

Every rule can be re-weighted, switched off, or given a severity override that skips the score entirely — for a known malware domain, for instance.

Signals

What each kind of rule measures.

Naming the mechanism matters more than naming the threat. If you can predict what a rule will do, you can tune it.

History
What the member has done before.
Flooding
Message volume inside a rolling window.
Repeated content
The same message posted more than once.
Links
URLs, invite links and blocked domains.
Mentions
How many members a message tags.
Words and phrases
Wording you asked Sedge to watch for.
New members
Stricter handling in a member’s first hours.
Posting pattern
Machine-like regularity across messages.
Media flooding
Runs of images, stickers or voice notes.

Limits we will state plainly

What weighted scoring is not.

Any rule engine gets things wrong. The design assumes that rather than denying it.

  • It does not understand the message. It counts, compares and matches. A sincere message that looks exactly like a scam will score like one, which is why nothing is removed without a review case.
  • Posting a lot is not enough on its own. The posting-pattern rule needs machine-like regularity over at least six messages, or the same content in three groups, before it contributes anything.
  • Trust is a rule too. A whitelisted member carries a weight of −100, so they have to trip almost everything at once before a score reaches a band that matters.

Tune it against your own traffic, not ours.

Change a weight and see the effect on a real recent message before you save it.