Default eligibility
Join protection is off by default. Server moderators can enable a browser CAPTCHA for accounts younger than 14 days. A separate dashboard option can require verification for everyone and is disabled by default. Accounts younger than seven days are highlighted in logs.
- A private verification link is sent first.
- A one-day timeout is applied when the challenge is created.
- The member has 30 minutes to complete the check.
- Three failed checks or expiry can lead to a kick.
Important delivery and rollback behaviour
If Stoatmod cannot deliver the private message, it does not apply the timeout or challenge. If setup fails after a timeout is applied, it attempts to roll the member back and records whether moderator action is still needed.
Commands
~join-protection statusReview the current state.
~join-protection enableEnable account-age verification.
~join-protection disableDisable new challenges.
~bypass USER_ID REASONRelease one pending member after moderator review and record why. Replace USER_ID and REASON before sending.
Use join protection responsibly
- Explain verification expectations in server rules.
- Keep a moderator recovery route for people who cannot receive a private message.
- Members must agree to the verification privacy notice before the browser CAPTCHA loads. Stoatmod performs no IP or alternate-account scan.
- Verify that timeouts are released after successful completion.