Skip to main content

How to use the DM protection?

Flag risky direct messages before they do damage - set your triggers, work the alert queue, and resolve each alert.

Written by Ron Storfer

Introduction

DM protection watches the direct messages arriving at your connected accounts and flags the dangerous ones - phishing lures, scam offers, spam blasts, and abuse - so a risky message is caught before anyone on your team acts on it.

The most important thing to understand: DM protection flags, it does not act. Spikerz will not delete a message, block a sender, or reply on your behalf. It raises an alert, and you decide what to do - handling the message in the platform's own inbox, then marking the alert resolved in Spikerz. Nothing happens to your conversations without you.

The feature is organized into two tabs:

  • Settings - which categories Spikerz scans your messages for

  • Alerts - the queue of flagged messages waiting for your review

Before You Start

Make sure that:

  • Your account is on a supported platform. DM protection is available on Facebook and Instagram only - the other networks do not expose direct messages to Spikerz. See Where DM Protection Works below.

  • The account is connected and its token is valid. Spikerz can only scan what it can see - a disconnected asset raises no alerts at all. See Token Inventory (Asset Management).

  • The messaging permissions were granted when the account was connected. See the Spikerz Platform Permissions Guide.

Step 1: Choose What Gets Flagged

Open the Settings tab. Under Predefined triggers you will find the four categories Spikerz can scan your direct messages for. Each one has its own dropdown with two states: Active scan or Off.

The Settings tab of DM protection, showing the predefined trigger categories set to Active scan

What Each Category Catches

Category

What it catches

Spam

Bulk and repetitive messages - promo blasts, "follow for follow", mass outreach with no real intent behind it

Scam

Attempts to trick you or your team out of money, access, or product - fake partnership and sponsorship offers, prize claims, crypto pitches, urgent payment requests

Offensive language

Abusive, hateful, or harassing messages directed at you, your brand, or the people who run your accounts

Phishing

Messages engineered to steal credentials or account access - fake copyright and verification notices, look-alike support accounts, credential-harvesting links

Note: a category set to Off is not scanned, so messages of that kind arrive with no alert at all. Because DM protection only ever flags, leaving a category on Active scan costs you nothing but an alert to review - there is no risk of a legitimate message being deleted or a real customer being blocked.

Recommendation: keep all four categories on Active scan. Phishing is the one to never switch off - it is the category that leads to a stolen account.

Step 2: Review What Has Been Flagged

Open the Alerts tab. This is your working queue of flagged messages.

The Alerts tab of DM protection, showing the status filters and a flagged message card

The Status Filters

The row of counters across the top splits the queue by state:

  • All DMs - everything Spikerz has scanned for this account

  • Alerts - the messages that tripped one of your categories

  • Needs review - alerts nobody has dealt with yet. This is the number that matters day to day.

  • Resolved - alerts you have closed out

Use Search to find a specific sender or phrase, Filter to narrow the queue, and Display to change how the list is laid out.

What Is on an Alert

Each card carries everything you need to make a judgment call without leaving Spikerz:

  • The sender and when it arrived - in the example above, a message from meta_support_center, a look-alike support handle.

  • The message itself, so you can judge it in full rather than from a label.

  • The category badge on the right - Phishing in the example - showing why the message was flagged. It is a dropdown, so you can reclassify a message Spikerz labelled wrongly.

  • Manage DMs in inbox - opens the conversation on the platform itself, which is where any action on the message happens.

  • Translate - renders a foreign-language message in your own, useful when the queue spans markets.

  • Feedback - tells Spikerz the call was wrong, so detection improves over time.

You can also Add tag, Add assignee, and Add sentiment to an alert. Assignees are what turn the queue into a shared workflow instead of one person's job - assign the alert to whoever owns that account or that market.

Step 3: Act on the Message, Then Resolve the Alert

This is the part that is easy to miss. Spikerz flags the message; closing it out is yours to do, in two separate places.

  1. Read the alert and decide whether it needs action. Plenty of flagged messages are simply spam you can ignore.

  2. Handle the message on the platform. Select Manage DMs in inbox to open the conversation on Facebook or Instagram, and do whatever the message calls for there - delete it, block the sender, report the account, or leave it alone. Spikerz cannot do any of this for you: there is no auto-delete, auto-block, or auto-reply in DM protection.

  3. Resolve the alert in Spikerz. Use the check icon at the bottom-left of the card. The alert leaves Needs review and moves into Resolved.

Working through a backlog: use the checkbox on each card, or Select all at the top of the list, to resolve several alerts in one pass. This is the fast way to clear a pile of low-risk spam without opening each one.

Why Resolving Matters

Needs review is a queue, not a log. Because Spikerz never acts on a message by itself, an unresolved alert means nobody has decided anything yet. Let the count run away and the one phishing attempt that mattered ends up buried under a hundred spam messages nobody bothered to close.

Treat Needs review the way you would treat an inbox: work it down to zero, and the number becomes a signal you can trust.

Where DM Protection Works

Direct message scanning depends on the platform exposing messages through its API. Today that means Facebook and Instagram.

Detection

FB

IG

TikTok

YouTube

LinkedIn

X

DM Phishing & Scam

N/A

DM Hate & Spam

N/A

For the full feature matrix across every Spikerz protection, see the Spikerz Platform Security Features & Availability Guide.

Good to Know

  • Flagging only. DM protection raises alerts. It does not delete messages, block or report senders, or send replies - every action on an actual conversation happens on Facebook or Instagram.

  • Detection follows the connection. If an asset's token is revoked or expires, message scanning stops until it is reconnected, and messages that arrived during the gap are not retroactively flagged.

  • Switching a category off does not clear your queue. Alerts already raised stay in Needs review until someone resolves them.

  • A flag is not a verdict. The category badge is Spikerz's read on the message - your judgment on the actual text is what counts, which is why you can reclassify it.

Troubleshooting

No alerts are appearing

  1. Check the platform. DM protection covers Facebook and Instagram only - there is nothing to scan on the other networks.

  2. Check the Settings tab. A category set to Off raises no alerts. If all four are off, the queue stays empty no matter what arrives.

  3. Check the account is connected and that messaging permissions were granted - see Token Inventory (Asset Management).

  4. Contact Spikerz support if all three look correct and you are still seeing nothing.

Messages are being flagged that should not be

Reclassify the message using the category badge on the card, and use Feedback to tell Spikerz the call was wrong. If one category is consistently noisy for your account, you can set it to Off - but remember that switching off Phishing or Scam removes your warning on the two categories that cause real damage.

The "Needs review" count is not going down

Alerts stay in Needs review until someone resolves them - it does not clear on its own, and reading an alert is not the same as resolving it. Use the check icon on each card, or Select all to resolve a batch at once.

You cannot delete or block from inside Spikerz

That is by design. DM protection is a detection layer - it never touches your conversations. Select Manage DMs in inbox on the alert to open the conversation on the platform, take the action there, then come back and resolve the alert.

Did this answer your question?