What Scam Defense Detects
Scam Defense works through a layered signal pipeline. Deterministic checks run first; AI adjudication handles only what passes through.Canonicalized Links
Canonicalized Links
Links are normalized before comparison — Unicode lookalike characters, URL shorteners, misleading subdomains, and redirect chains are all resolved to their canonical form. A scam link disguised as
discord․gg (using a Unicode period) is caught the same way a plain discord.gg impersonation would be.Dangerous Attachments
Dangerous Attachments
Files are checked for dangerous types, doubled extensions (e.g.,
invoice.pdf.exe), and mismatches between the declared MIME type and actual file content. An image that is actually an executable is flagged regardless of what it’s named.QR Codes & Image Surfaces
QR Codes & Image Surfaces
QR codes embedded in images are decoded and their payloads are checked against the same link and domain intelligence used for text links. Image fetching applies strict size and timeout limits to prevent resource exhaustion.
Identity Signals
Identity Signals
Display names, usernames, and profile content are screened for staff, support, admin, and brand impersonation patterns. A new account claiming to be your server’s admin team is flagged before it can contact members.
Cross-Channel Campaign Detection
Cross-Channel Campaign Detection
When multiple accounts post the same — or structurally similar — content across different channels in a short time window, Scam Defense recognizes it as a coordinated campaign rather than isolated incidents. Each account is evaluated independently, but the campaign context raises the confidence of the overall finding.
AI Adjudication
AI Adjudication
Messages that pass all deterministic checks but still appear suspicious are passed to Thea’s AI for a final judgment. The AI evaluates context, phrasing patterns, and behavioral signals. This step runs only after all deterministic signals have been applied.
Threat Feeds
Thea’s domain and indicator feeds are versioned and validated before any update goes live. If a feed update is malformed or contains suspicious entries, it is quarantined automatically — it does not silently change what Scam Defense enforces. The Community scam list card under Settings → AutoMod is the server-facing control (ask before each update, update automatically, or do not use). The live view of signals and effective policy is Scam defense in the sidebar.The Evidence Model
Scam Defense combines independent signals rather than stacking correlated ones.- Deduplication: multiple signals originating from the same root cause (one bad link appearing in three messages) count once, not three times.
- Conservative action ceilings: each signal tier caps the maximum action Scam Defense will recommend. A single weak signal is never sufficient to trigger a punitive action.
- Recommendation, not mandate: Scam Defense produces a recommended response; your policy rules determine what action is actually taken.
Your Policy Controls the Response
Configure what Scam Defense does for each finding severity:
Set these under Settings → AutoMod → Actions by severity. Actions apply to regular members only (see Staff and bots below). Scam defense in the sidebar is the live view of signals and the effective policy — the controls themselves stay on AutoMod.
Staff, Bots & Webhooks
Accounts with staff roles, verified bots, and server webhooks run in observe-only mode. Their activity is recorded and can be investigated, but it never triggers automated punishment. This prevents Scam Defense from acting on your own tools and team.Graceful Degradation
If an external dependency — a threat feed API, the AI adjudication service, or a third-party enrichment source — is temporarily unavailable, Scam Defense continues operating with local protection. The degraded state is surfaced in the dashboard so you know which signals are temporarily inactive.Dashboard
Scam defense in the sidebar is a live, privacy-safe view of what Thea is finding. The effective scam policy card shows what is configured versus what is actually running (plan, provider, feed, and global controls).Overview
What your server is seeing, detection frequency, containment rate, and how often detections were contained before members were affected.
Findings
Every detection with its source tier, severity, policy verdict, and action taken. Filter by date, type, or outcome.
Detection Detail
Open any finding to inspect the event ID, source tier, severity level, policy verdict, action taken, confidence scores, Discord scope (channel, user, message), and full review history.
Review History
A log of every manual decision staff made — approvals, dismissals, and overrides — alongside the automated finding that prompted review.
Privacy
Scam Defense operates on server activity only — it does not access or monitor direct messages. Message bodies, raw URLs, QR code payloads, and screened display names are not retained after evaluation. Only the finding metadata (event ID, severity, action, timestamps) is stored for audit purposes.Enabling scam defense
1
Turn AutoMod on
Open Settings → AutoMod and enable AutoMod. Heuristics, blocked domains, and the community scam list are the scam-specific layers.
2
Set a log channel
Quarantine review and Allow / Ban decisions need a private staff channel.
3
Review findings first
Open Scam defense in the sidebar. Watch a few days of signals before you raise per-severity actions.
4
Tighten actions
Under Settings → AutoMod → Actions by severity, move from log-only to quarantine or delete once you trust the findings. Detection and audit visibility arrive first. Automated actions unlock after you have reviewed findings and calibrated policy, so a misconfigured rule cannot take mass action before you validate it.