Introduction
DM protection watches the direct messages arriving at your connected accounts and flags the dangerous ones - phishing lures, scam offers, spam blasts, and abuse - so a risky message is caught before anyone on your team acts on it.
The most important thing to understand: DM protection flags, it does not act. Spikerz will not delete a message, block a sender, or reply on your behalf. It raises an alert, and you decide what to do - handling the message in the platform's own inbox, then marking the alert resolved in Spikerz. Nothing happens to your conversations without you.
The feature is organized into two tabs:
Settings - which categories Spikerz scans your messages for
Alerts - the queue of flagged messages waiting for your review
Before You Start
Make sure that:
Your account is on a supported platform. DM protection is available on Facebook and Instagram only - the other networks do not expose direct messages to Spikerz. See Where DM Protection Works below.
The account is connected and its token is valid. Spikerz can only scan what it can see - a disconnected asset raises no alerts at all. See Token Inventory (Asset Management).
The messaging permissions were granted when the account was connected. See the Spikerz Platform Permissions Guide.
Step 1: Choose What Gets Flagged
Open the Settings tab. Under Predefined triggers you will find the four categories Spikerz can scan your direct messages for. Each one has its own dropdown with two states: Active scan or Off.
What Each Category Catches
Category | What it catches |
Spam | Bulk and repetitive messages - promo blasts, "follow for follow", mass outreach with no real intent behind it |
Scam | Attempts to trick you or your team out of money, access, or product - fake partnership and sponsorship offers, prize claims, crypto pitches, urgent payment requests |
Offensive language | Abusive, hateful, or harassing messages directed at you, your brand, or the people who run your accounts |
Phishing | Messages engineered to steal credentials or account access - fake copyright and verification notices, look-alike support accounts, credential-harvesting links |
Note: a category set to Off is not scanned, so messages of that kind arrive with no alert at all. Because DM protection only ever flags, leaving a category on Active scan costs you nothing but an alert to review - there is no risk of a legitimate message being deleted or a real customer being blocked.
Recommendation: keep all four categories on Active scan. Phishing is the one to never switch off - it is the category that leads to a stolen account.
Step 2: Review What Has Been Flagged
Open the Alerts tab. This is your working queue of flagged messages.
The Status Filters
The row of counters across the top splits the queue by state:
All DMs - everything Spikerz has scanned for this account
Alerts - the messages that tripped one of your categories
Needs review - alerts nobody has dealt with yet. This is the number that matters day to day.
Resolved - alerts you have closed out
Use Search to find a specific sender or phrase, Filter to narrow the queue, and Display to change how the list is laid out.
What Is on an Alert
Each card carries everything you need to make a judgment call without leaving Spikerz:
The sender and when it arrived - in the example above, a message from meta_support_center, a look-alike support handle.
The message itself, so you can judge it in full rather than from a label.
The category badge on the right - Phishing in the example - showing why the message was flagged. It is a dropdown, so you can reclassify a message Spikerz labelled wrongly.
Manage DMs in inbox - opens the conversation on the platform itself, which is where any action on the message happens.
Translate - renders a foreign-language message in your own, useful when the queue spans markets.
Feedback - tells Spikerz the call was wrong, so detection improves over time.
You can also Add tag, Add assignee, and Add sentiment to an alert. Assignees are what turn the queue into a shared workflow instead of one person's job - assign the alert to whoever owns that account or that market.
Step 3: Act on the Message, Then Resolve the Alert
This is the part that is easy to miss. Spikerz flags the message; closing it out is yours to do, in two separate places.
Read the alert and decide whether it needs action. Plenty of flagged messages are simply spam you can ignore.
Handle the message on the platform. Select Manage DMs in inbox to open the conversation on Facebook or Instagram, and do whatever the message calls for there - delete it, block the sender, report the account, or leave it alone. Spikerz cannot do any of this for you: there is no auto-delete, auto-block, or auto-reply in DM protection.
Resolve the alert in Spikerz. Use the check icon at the bottom-left of the card. The alert leaves Needs review and moves into Resolved.
Working through a backlog: use the checkbox on each card, or Select all at the top of the list, to resolve several alerts in one pass. This is the fast way to clear a pile of low-risk spam without opening each one.
Why Resolving Matters
Needs review is a queue, not a log. Because Spikerz never acts on a message by itself, an unresolved alert means nobody has decided anything yet. Let the count run away and the one phishing attempt that mattered ends up buried under a hundred spam messages nobody bothered to close.
Treat Needs review the way you would treat an inbox: work it down to zero, and the number becomes a signal you can trust.
Where DM Protection Works
Direct message scanning depends on the platform exposing messages through its API. Today that means Facebook and Instagram.
Detection | FB | IG | TikTok | YouTube | X | |
DM Phishing & Scam | ✔ | ✔ | ✖ | N/A | ✖ | ✖ |
DM Hate & Spam | ✔ | ✔ | ✖ | N/A | ✖ | ✖ |
For the full feature matrix across every Spikerz protection, see the Spikerz Platform Security Features & Availability Guide.
Good to Know
Flagging only. DM protection raises alerts. It does not delete messages, block or report senders, or send replies - every action on an actual conversation happens on Facebook or Instagram.
Detection follows the connection. If an asset's token is revoked or expires, message scanning stops until it is reconnected, and messages that arrived during the gap are not retroactively flagged.
Switching a category off does not clear your queue. Alerts already raised stay in Needs review until someone resolves them.
A flag is not a verdict. The category badge is Spikerz's read on the message - your judgment on the actual text is what counts, which is why you can reclassify it.
Troubleshooting
No alerts are appearing
Check the platform. DM protection covers Facebook and Instagram only - there is nothing to scan on the other networks.
Check the Settings tab. A category set to Off raises no alerts. If all four are off, the queue stays empty no matter what arrives.
Check the account is connected and that messaging permissions were granted - see Token Inventory (Asset Management).
Contact Spikerz support if all three look correct and you are still seeing nothing.
Messages are being flagged that should not be
Reclassify the message using the category badge on the card, and use Feedback to tell Spikerz the call was wrong. If one category is consistently noisy for your account, you can set it to Off - but remember that switching off Phishing or Scam removes your warning on the two categories that cause real damage.
The "Needs review" count is not going down
Alerts stay in Needs review until someone resolves them - it does not clear on its own, and reading an alert is not the same as resolving it. Use the check icon on each card, or Select all to resolve a batch at once.
You cannot delete or block from inside Spikerz
That is by design. DM protection is a detection layer - it never touches your conversations. Select Manage DMs in inbox on the alert to open the conversation on the platform, take the action there, then come back and resolve the alert.

