Bernard Honeypot¶
Overview¶
A honeypot channel is a channel that no real member of your server should ever post in. Bernard posts a warning at the top of it, and anyone who posts there anyway has their message deleted and is automatically kicked, timed out, or banned.
Spam bots and compromised accounts usually work the same way: they post the same scam link or advert in every channel they can see, as fast as they can. AutoMod's text filters catch phrases Bernard already knows about, but a honeypot catches these accounts whatever they say, because a real member reading the warning would never post there. Placed near the top of your channel list, the honeypot is often the first channel a spam bot reaches, so it is removed before it gets to your real channels.
The honeypot is free for every server.
How It Works¶
The Warning¶
When the honeypot is turned on, Bernard posts a red warning embed in the honeypot channel, titled ⚠️ Do not post in this channel. It says:
- "This channel is a trap for spam bots and compromised accounts."
- "Anyone who posts here will be" followed by the punishment you chose, such as kicked, timed out for 1 day, banned for 7 days, or permanently banned.
- "Moderators are exempt."
Below that, a Victims so far field shows a live count of everyone the honeypot has caught, and the footer reads "Protected by Bernard". When you change the punishment, Bernard edits the warning to match.
The counter goes up each time the honeypot successfully punishes someone. Bernard updates it at most once every 15 seconds or so, so during a raid it may take a moment to catch up. The count belongs to your server, not the channel, so it carries over if you move the honeypot to a different channel.
No Warning, No Punishment¶
The honeypot only punishes members while Bernard's warning is visible in the channel. This keeps the honeypot fair: nobody is punished without being told first.
- If someone deletes the warning, the honeypot stops punishing immediately, and Bernard posts a new warning within about 15 seconds. The honeypot starts punishing again once the new warning is up.
- If Bernard can't post the warning (for example, because it is missing a permission in that channel), the honeypot stays unarmed until the problem is fixed. Bernard tells you why in OmniLogs, in
/configuration honeypot status, and on the dashboard. See Unarmed Reasons for each reason and how to fix it.
While the honeypot is unarmed, the channel behaves like any other channel: posts are not deleted, and nobody is punished.
What Counts as a Post¶
Any message posted in the honeypot channel counts, including messages posted in threads under the honeypot channel. What the message says does not matter.
Who Is Exempt¶
The following members can post in the honeypot channel without being punished:
- Bots.
- The server owner.
- Members with the Administrator permission.
- Members with any moderation-related administrative capability (for example,
KICK_MEMBERSorCONFIG_CHANGES). - Users and roles on your server's AutoMod immunity list.
Note
Moderators' own messages in the honeypot channel are left alone. While the honeypot is armed, Bernard does not delete them and neither the honeypot nor AutoMod acts on them, so your team can post in the channel (for example, to pin an explanation) without setting it off.
Bursts of Messages¶
A spam bot often posts several messages in a row. Bernard punishes each member at most once per minute: the first message triggers the punishment, and any further messages from the same member within that minute are simply deleted.
AutoMod in the Honeypot Channel¶
The honeypot runs before AutoMod and Dynamic Slow Mode. When the honeypot acts on a message, AutoMod does not also act on it, so a member is never punished twice for the same post.
AutoMod never posts its in-channel notification in the honeypot channel or its threads, whether the honeypot is turned on or off, so the honeypot warning is never buried under AutoMod notices. If AutoMod does act on a message there (for example, while the honeypot is unarmed), it still deletes the message, punishes the author as usual, and logs the violation to OmniLogs.
Punishments¶
You choose one punishment for everyone the honeypot catches:
| Punishment | Details |
|---|---|
| Kick (default) | Removes the member from the server. They can rejoin with an invite. |
| Timeout | Stops the member from chatting or joining voice for between 1 minute and 28 days (Discord's limit for timeouts). |
| Temporary ban | Bans the member for between 1 minute and 365 days. The ban is lifted automatically when it ends. |
| Permanent ban | Bans the member until a moderator unbans them. |
Bans can also delete up to 7 days of the member's recent messages across the server, which is useful for cleaning up whatever a spam bot posted before it reached the honeypot.
Honeypot punishments work like Bernard's other punishments:
- The member receives a direct message explaining what happened and why, if their privacy settings allow it. The message links to an explanation of the honeypot written for them.
- The punishment is recorded on the member's Rapsheet, with Bernard as the moderator and the reason "Posted in the honeypot channel #channel-name".
- Timeouts and temporary bans end automatically.
Bernard can't punish a member whose highest role is at or above Bernard's own highest role. The message is still deleted, and the failed punishment is reported to OmniLogs so a moderator can follow up. See Failed Punishments.
Setting Up a Honeypot¶
Before you start, read the Best Practices below and create a new, dedicated channel for the honeypot.
Warning
Never turn a channel your members use into a honeypot. Everyone who posts there after setup, apart from the exempt members, will be punished. Always use a new, dedicated channel.
From Discord¶
Run the /configuration honeypot setup command, choosing the channel and the punishment:
/configuration honeypot setup channel:#do-not-post punishment:Kick
For a timeout or temporary ban, also set how long it lasts. For bans, you can optionally choose how many days of messages to delete:
/configuration honeypot setup channel:#do-not-post punishment:Temporary ban duration:7d delete_message_days:1
To run the command, you need the CONFIG_CHANGES administrative capability and the capability for the punishment you choose, so nobody can use the honeypot to hand out a punishment they couldn't issue themselves:
| Punishment | Capability needed (in addition to CONFIG_CHANGES) |
|---|---|
| Kick | KICK_MEMBERS |
| Timeout | TEMP_SILENCE_MEMBERS or PERMA_SILENCE_MEMBERS |
| Temporary ban | TEMP_BAN_MEMBERS |
| Permanent ban | PERMA_BAN_MEMBERS |
The server owner and administrators can always run the command.
Bernard checks that it has every permission it needs before turning the honeypot on. If the channel had messages from non-exempt members in the past week, Bernard asks you to confirm before going ahead, in case you picked a channel people use by mistake.
Once the honeypot is on, Bernard posts the warning and replies with a link to it. You can change the punishment later with /configuration honeypot punishment, and turn the honeypot off with /configuration honeypot disable. Turning it off removes the warning but keeps your settings, so running setup again turns it back on.
From the Dashboard¶
Server owners and administrators can also set up the honeypot from the Bernard dashboard:
- Open your server in the dashboard and go to Server settings.
- In the Honeypot section, turn on Honeypot channel.
- Choose the channel. Only text channels are listed.
- Choose the Punishment. For a timeout or temporary ban, set its length. For bans, choose whether to delete the member's recent message history.
- Apply your changes. The dashboard asks you to confirm before it arms the honeypot ("Arm the honeypot?"), and again whenever you move it to a different channel.
The section shows the punishment as it will appear in the warning (for example, "Anyone who posts in the channel will be timed out for 1 day"). Timeout and ban lengths are entered in minutes, hours, or days. For bans, Delete message history offers "Don't delete" or the previous 1 to 7 days.
The honeypot channel must be dedicated to the honeypot. Bernard refuses a channel it already uses for something else, such as your OmniLogs forum or event channels, the arena channel, or a rapsheet notes channel.
Checking the Honeypot's Status¶
Run /configuration honeypot status to see whether the honeypot is on, which channel and punishment it uses, how many members it has caught, whether it is armed (with a link to the warning), and any permissions Bernard is missing.
On the dashboard, a status card under the Honeypot settings shows:
- Status: one of "Armed: warning posted in #channel" (with a View in Discord link to the warning), "Not armed" with the reason, "Waiting for Bernard to post the warning", or "Off".
- Victims: how many members the honeypot has caught.
- Failed punishments: how many punishments failed, shown only when there are any.
- Recent victims: the latest members caught, each with the punishment, the time (in UTC), whether it succeeded or why it failed, and the rapsheet entry.
Unarmed Reasons¶
If the honeypot is turned on but not armed, the status command and the dashboard say why. Once you fix the problem, Bernard retries automatically within the hour. To retry straight away, run /configuration honeypot status.
| Reason | What it means | How to fix it |
|---|---|---|
| Missing permissions (for example, "I'm missing these permissions: Send Messages") | Bernard can't see or post in the honeypot channel. | Give Bernard's role the listed permissions in that channel: View Channel, Send Messages, Embed Links and Read Message History. |
| The channel no longer exists | The honeypot channel was deleted. Bernard turns the honeypot off when this happens and logs it to OmniLogs. | Create a new channel and run setup again, or choose a new channel on the dashboard. |
| It isn't a text channel | The chosen channel can't hold the warning. | Choose a regular text channel. |
| Discord denied permission to post or edit the warning | Discord refused Bernard's request even though its permissions looked right, often because of a channel permission override. | Check the honeypot channel's permission overrides for Bernard's role. |
| The warning hasn't been posted yet (on the dashboard: "Waiting for Bernard to post the warning") | The honeypot was just turned on or moved, or the warning was just deleted, and Bernard hasn't posted the new warning yet. | Wait a moment and check again. |
To actually punish members, Bernard also needs Manage Messages in the honeypot channel to delete posts, plus Kick Members, Timeout Members, or Ban Members in the server depending on the punishment. The status command lists any that are missing under Bot Permissions. Bernard's current invite link includes all of these, but servers that added Bernard with an older invite may be missing Timeout Members. To fix that, invite Bernard again or grant the permission to its role, as described in Invite Link. See also Honeypot Permissions.
Best Practices¶
- Use a dedicated channel with a name that warns people off, such as
#do-not-postor#bot-trap. Members who read the name and the warning will stay out. - Place it near the top of your channel list. Spam bots tend to start at the top, so a honeypot there catches them before they reach your real channels.
- Let
@everyonesend messages in the channel. A honeypot that spam bots can't post in can't catch them. - Keep Bernard's role above your ordinary members' roles. Bernard can't punish anyone whose highest role is at or above its own.
- Start with a kick or a timeout. These are gentle on a curious member who posts by mistake. Once you are confident the honeypot only catches spam bots, you can switch to a temporary or permanent ban.
OmniLogs¶
Every honeypot punishment is logged to OmniLogs under the AutoMod event, in the same thread as AutoMod violations. A successful punishment is titled Honeypot Triggered, and a failed one is titled Honeypot Triggered - Punishment Failed. Each entry contains the following fields:
| Field | Shown | Contents |
|---|---|---|
| Message Author, Text Channel | Always | Who posted, and the channel or thread they posted in. |
| Notification URL | Always | A link to the honeypot channel (the message itself has been deleted). |
| Punishment | Success | The punishment applied, such as "Timed out for 1 day". |
| Victim | Success | The member's number on the victim counter, such as "#42". |
| Attempted Punishment | Failure | The punishment Bernard tried to apply, such as "Would have been kicked". |
| Reason, Suggested Fix | Failure | What went wrong and how to fix it. See Failed Punishments. |
| Punishment DM | Always | Whether the direct message reached the member. |
| Corresponding Rapsheet Entry | When one was written | The ID of the member's rapsheet entry. |
| Message Deleted | Always | Whether Bernard deleted the post. |
| Member Age, Account Age | Always | How long the member had been in the server, and how old their account is. |
| Attachments | Always | How many files were attached to the post. |
| Message Contents | Always | What the post said. |
When the honeypot is unarmed because Bernard can't post the warning, or is turned off because its channel was deleted, Bernard posts a Honeypot Unarmed or Honeypot Disabled message under the Notifications event.
Failed Punishments¶
If Bernard deletes the message but can't punish the member, the log entry is titled Honeypot Triggered - Punishment Failed and its Reason and Suggested Fix fields say what went wrong and how to fix it. Failed punishments don't count towards the victim counter.
| Reason | How to fix it |
|---|---|
| Bernard's role is not above this member's highest role. | Move Bernard's role above this member's highest role in Server Settings > Roles, then punish them by hand. |
| Bernard is missing the Kick Members, Timeout Members or Ban Members permission. | Give Bernard's role the permission named in the log entry, then punish this member by hand. |
| Discord rejected the punishment. | Punish this member by hand. If this keeps happening, check Discord's status page. |
Privacy¶
For each member the honeypot catches, Bernard stores their Discord user ID, the IDs of the channel and message, the punishment and whether it succeeded, how long they had been in the server, and the age of their account. This powers the victim counter and the dashboard's status card. Bernard does not store what the message said: the message content appears only in your server's OmniLogs entry, just like an AutoMod violation. See the Privacy Policy.
See Also¶
- AutoMod - Bernard's automatic moderation suite, which the honeypot runs alongside.
- Punishment Commands - How Bernard's punishments, direct messages and role hierarchy work.
- OmniLogs - Where honeypot hits and failed punishments are logged.
- Rapsheets - Where each honeypot punishment is recorded.
- Server Permissions - The Discord permissions Bernard needs to run a honeypot.
- Command Reference: Honeypot Commands - Exact syntax, parameters, and requirements for every honeypot command.