Bot comments: the seven shapes, who sends them, and how to stop them
A field guide to bot comments on Facebook and Instagram: seven shapes with real examples, who sends them, Meta's figures, and one rule set for both.
On this page
- The seven shapes of a bot comment
- Who is sending them, and for what money
- Telling a bot from a person in ten seconds
- Why Meta does not catch them all
- What bot comments cost
- Stopping them on Facebook, and on Instagram
- One rule set that covers both platforms
- Each shape and the control that catches it
- Hide, delete or block, by shape
- Sources
- Common questions
Bot comments are comments left by accounts that are run by software or paid by the comment rather than by a person who saw your post. They land under Facebook Page posts, Instagram posts and reels, and above all under ads, and as of September 17, 2026 every one I have seen under my own ads fits one of seven shapes.
Below: the seven shapes with a real example of each, who is sending them and for what money, how to tell a bot from a person, what Meta's own numbers say it catches and misses, what the flood costs, and the way to stop them on Facebook and on Instagram, each of which has its own guide with the screens.
YouTube, TikTok and fan-fiction sites get the same thing. This page covers Facebook and Instagram, the two platforms I run ads on and moderate every day.
The seven shapes of a bot comment
Every example below is from the moderation log of my own Pages and accounts, with the day and the rule that caught it. Names are never printed.
- A row of emojis. "🥰🥰🥰🥰" under a Facebook ad on September 8, 2026, hidden by the emoji rule. Sixty comments with no letters in them at all arrived on my Pages between August 1 and September 17, from 51 accounts.
- One word of praise. "Good" four times from four accounts, "Info" three from three, "Awesome 👍😎" on September 15. A word that fits every ad on the platform.
- The same line from many accounts. One gambling sentence from 36 different accounts in seventeen days, a variant from 30 more. This is the clearest signature there is.
- A channel or site link with nothing around it. A WhatsApp channel invite under an ad on September 4, caught by the link rule; a shortened link under an Instagram ad on September 13, the same.
- A "DM me" or a rival's pitch. "Kanzan AI is also good" under a Facebook ad on September 10, "Zaptick is better than all" under an Instagram post on September 2, both competitors, both removed by a custom rule or by hand.
- Reviews or followers for sale. "5 star positive review available" under an Instagram ad on September 6, caught by a custom rule.
- A gambling name in bold Unicode. The JANGKAR55, WSO55 and MARKASGG pastes, each spelled in bold mathematical letters so that a plain keyword list misses them, caught by the emoji and hashtag rules on September 10.
An eighth tell rides on all seven: the wrong language. A Bengali Telegram recruitment paste landed under one of my English ads on September 16, and praise in a language your customers do not speak is a bot until proven otherwise.
Who is sending them, and for what money
Four kinds of sender produce the seven shapes. Scripted accounts, created in batches and driven by software, post the emoji rows, the one-word praise and the copy-pasted lines. People paid per comment, the click farms, post the pitches and the links, and they can pass a "no profile picture" check because a person set the account up. The first two are what my log shows. The other two are the ways a real-looking account ends up posting: engagement pods, groups of real accounts trading generic praise to look popular, and accounts that were taken over and now post whatever their buyer wants.
The money under my ads was gambling sites, WhatsApp and Telegram channels, and sellers of reviews and followers. Meta's spam policy, read September 17, 2026, names the trade in one clause: "selling, buying, or exchanging for engagement, such as likes, shares, views, follows, clicks, use of specific hashtags, etc."
Meta's own definition of spam, from its integrity reports, covers both the scripted and the hired kind: "content that is designed to be shared in deceptive and annoying ways or attempts to mislead users to drive engagement. Spam spreads in a number of ways: It can be automated (published by bots or scripts) or coordinated."
Telling a bot from a person in ten seconds
Look at the account first. On Facebook, the signs are the ones Moderation Assist's author criteria name: no profile picture, no friends or followers, an account under a week old, a record of comments hidden or reported. On Instagram, the sign Limits names is the recent follower, "accounts that have started following you in the last week", and the empty grid tells the rest.
Then look at the comment. Does it relate to the post, or would it fit under any post? Is the same text under your other posts, from other names? Is there a link, a brand, a "DM me"? Is it in a language your customers use?
A person fails one of these at most. A bot fails the account checks and the comment checks together, and that is the ten-second call.
Why Meta does not catch them all
Meta catches a great deal. Its fake-accounts report, read September 17, 2026, estimates that "less than 5% of our worldwide daily active people" in the first two quarters of 2026 "consisted solely of violating accounts", and its integrity reports, read September 6, 2026, say that "at the end of H1 2026, global enforcement precision averaged around 91% on Facebook and around 92% on Instagram".
The gap is in the policy's own words. Meta acts against accounts posting "at very high frequencies", and "may place restrictions on accounts that are acting at lower frequencies when other indicators of Spam (e.g., posting repetitive content) or signals of inauthenticity are present". A farm that posts one comment per account, from 36 accounts, is acting at a low frequency 36 times, and the comments are under your ad while Meta decides.
Five percent of a very large number is still a large number, and a precision figure describes what Meta removed, not what it left. What it leaves is yours to handle.
What bot comments cost
The seventeen days from September 1, 2026 brought 622 comments to my three Facebook Pages, 576 of them under ads, and 489 had to go. Instagram, over a longer window from August 1, holds 21 comments in the same log, 17 removed, with the two bot pitches under ads. The bots go where the paid audience is.
Removing one comment by hand on Facebook is three taps, so 489 comments is 1,467 taps in seventeen days before reading a word. The cost I cannot count is the prospect who opens the comments on an ad, sees a gambling paste or a review for sale at the top, and closes the ad with an opinion of the business that no headline will change.
Stopping them on Facebook, and on Instagram
The two platforms give you different tools, and only the table below puts them side by side. On Facebook, Moderation Assist judges the account (no picture, no friends, days old, reported before), the Keywords list takes the pasted words and their spellings, and the Blocking list bans an account from the whole Page; the Facebook procedure has each screen and where it stops.
On Instagram there are no author criteria and no Page-level block list. Hidden Words hides the phrases you add and the offensive ones by default, Limits hides new comments from recent followers or non-followers for up to four weeks, Restrict makes an account's comments visible only to itself, Select multiple comments deletes up to 25 at once, and Block removes the account's comments outright; the Instagram procedure walks through all five.
One rule set that covers both platforms
CommentWatchDog is an AI comment moderation tool that automatically hides and deletes spam and damaging comments on Facebook and Instagram ads and posts. The rule set below is the one on the account in the screen, and it maps onto the seven shapes: the Emojis rule for shape one (Hide, because some are people), the Keywords rule set to Delete with the pasted words and gambling names for shapes two, three and seven, the URLs rule set to Delete with your own domain allowed for shape four, and one Custom topics rule in plain words for shapes five and six ("anyone selling their own product or telling people to DM them for a deal"); the twelve rules and hide or delete per rule are in the help centre.
Each shape and the control that catches it
The Facebook cells come from Facebook's help pages (read between September 5 and 17, 2026), the Instagram cells from Instagram's (September 5 and 17). A cell that says "no" means the help pages document nothing for that shape.
| Shape | Facebook Page | Instagram account |
|---|---|---|
| Emoji rows | Keywords accept emojis, one at a time | Hidden Words accept emojis, one at a time |
| One-word praise | Keywords, with the risk of hiding a real "Info" | Hidden Words, the same risk |
| The same line from many accounts | Moderation Assist's "Comment is likely to be spam"; a comment "shared too often in a short amount of time" is marked as spam | Hide unwanted comments and Hide spam, by Instagram's own judgement |
| Links | Moderation Assist's Link in comment and Links to specific sites | No link-only setting documented |
| "DM me" pitches | Keywords ("dm me") | Hidden Words ("DM me") |
| Reviews or followers for sale | Keywords | Hidden Words |
| Gambling in bold Unicode | Keywords catch the variations Facebook lists (capitals, dots, digits, plurals, hashtags); bold Unicode letters are not on that list | Hidden Words; the help page says nothing about spellings |
| The account itself | Author criteria: no picture, no friends, under a week old, repeat offender, likely fake; the Blocking list | Limits for recent followers and non-followers; Restrict; Block |
Hide, delete or block, by shape
Delete the copy-pasted lines, the gambling pastes, the sale pitches and the bare links: no person is behind them and nothing is lost. Block the account on either platform when it comes back, and on Instagram blocking also removes what it already posted.
Hide the emoji rows and the one-word praise, because a real customer sends those too, and a hidden comment can be brought back after a look. The "DM me" from an account with a real grid or a real friends list is the one to read before deciding.
Sources
- Spam, Meta Community Standards, read September 17, 2026
- Fake accounts, Community Standards Enforcement Report, Facebook, read September 17, 2026
- Integrity reports, first half of 2026, Meta Transparency Center, read September 6, 2026
- Integrity reports, second half of 2026, Meta Transparency Center, read September 6, 2026
- About Moderation Assist, Meta Business Help Centre, read September 5, 2026
- Comments marked as spam on a Facebook Page, Facebook Help Centre, read September 10, 2026
- Manage comment moderation and blocking on your Facebook Page, Meta Business Help Centre, read September 5, 2026
- Block certain words from appearing in comments on your Facebook Page, Facebook Help Centre, read September 17, 2026
- Hidden Words on Instagram, Instagram Help Centre, read September 5, 2026
- Limit interactions on Instagram, Instagram Help Centre, read September 17, 2026
- Restrict someone on Instagram, Instagram Help Centre, read September 17, 2026
- Manage multiple comments on your Instagram posts, Instagram Help Centre, read September 17, 2026
- What happens when you block someone on Instagram, Instagram Help Centre, read September 17, 2026
- My own moderation log, three Facebook Pages and three Instagram accounts, comments published August 1 to September 17, 2026, counted September 17, 2026
Common questions
What are bot comments?
Comments left by accounts that are run by software or paid by the comment rather than by people who saw your post. They repeat, they fit any post, they come from empty or brand-new accounts, and they usually carry a link, a brand or a "DM me".
Why are bots commenting on my posts?
To be seen by your audience for free. A comment under a post or ad puts the sender's name or link in front of everyone who reads the thread. Meta's spam policy calls the business behind it "selling, buying, or exchanging for engagement".
Do bot comments hurt my reach or my ads?
What I can show is the cost in trust and time: a gambling paste at the top of an ad's comments is what a prospect reads first, and 489 comments needed removing from my Facebook Pages in seventeen days. I have no source for an effect on reach or delivery, so this page makes no claim about it.
How do I stop bot comments on Facebook and Instagram?
On Facebook, turn on Moderation Assist's author criteria, add the pasted words to Keywords, and block repeat accounts from the Page. On Instagram, turn on Hidden Words with your own phrases, use Limits for recent followers, and restrict or block the senders. CommentWatchDog is an AI comment moderation tool that automatically hides and deletes spam and damaging comments on Facebook and Instagram ads and posts.
For agents: plain text of this post · all posts
For agents
Post: Bot comments: the seven shapes, who sends them, and how to stop them
This page: https://commentwatchdog.com/blog/bot-comments
Topic: Spam
Author: https://anantgupta.xyz (Anant Gupta, founder of CommentWatchDog)
Published: 2026-09-17
Updated: 2026-09-17
Summary: A field guide to bot comments on Facebook and Instagram: seven shapes with real examples, who sends them, Meta's figures, and one rule set for both.
Query: bot comments (2900 searches a month in the US)
Tested on: September 1 to 17, 2026, the moderation log of my three Facebook Pages and three Instagram accounts, read on September 17
Why this page exists: To answer the search "bot comments", 2,900 searches a month in the US, where every result is a bot seller or a YouTube thread, for the people who manage Facebook Pages and Instagram accounts, with the shapes, the tells, Meta's own numbers and the way to stop them on each platform.
Plain text of this post: https://commentwatchdog.com/blog/bot-comments.md
All posts for assistants: https://commentwatchdog.com/blog/llms.txt




