Stoatmod / New-account protection guide

How to strengthen a Stoat server against abusive joins

Join protection is one layer of incident readiness. Combine it with sensible default roles, spam controls, a private log channel and a documented moderator recovery path.

All guides

The details, in one place.

Use join verification, account-age checks, spam controls, role design and moderator recovery to reduce abusive new-account activity.

  • Reviewed 31 August 2026
  • 3 sections
  • Guides

Prepare the server

  • Give new members a limited default role.
  • Keep high-impact permissions away from automatic roles.
  • Create a private incident channel.
  • Document who can bypass or remove a challenge.
  • Test private-message delivery with a controlled account.

Configure join protection

  1. 01

    Check current state

    The default targets accounts younger than 14 days.

    ~join-protection status
  2. 02

    Enable when needed

    Start new-account challenges.

    ~join-protection enable
  3. 03

    Review verification-for-everyone

    The dashboard option is separate and normally off.

  4. 04

    Test completion and expiry

    Confirm timeout release, failed-attempt handling and the 30-minute expiry path.

During an incident

  • Keep moderators focused on real server state rather than a stream of success messages.
  • Use spam and mass-mention controls alongside join checks.
  • Bypass only a reviewed user ID.
  • Record incomplete timeout rollback for manual recovery.
  • Join CAPTCHA is optional and off by default; members review and agree to its privacy notice.

Ready to configure a server?

Install Stoatmod, then verify the first outcome.

Open the official bot profile →