How to hide spam comments on Instagram, by hand and automatically
Instagram has two built-in ways to hide a spam comment, and both are free. To hide one comment, swipe it in the comment thread and tap Hide. To hide them before you ever see them, open your profile settings, find Hidden Words, switch on the offensive comment filter and add your own words to the manual list. Anything containing one of those words stops appearing under your post, and Instagram does not tell the person who wrote it. That covers a great deal. It stops covering the spam that carries no word on your list, which is most of it.
Set up Instagram's own filters first
Do this before you look at any tool, including ours. It takes five minutes, it costs nothing, and it removes the easy half of the problem. There are more controls here than most people realise.
- Hidden Words, in your profile settings. The first switch hides comments Instagram judges offensive, using its own list rather than yours. The second is a manual list: type your own words, phrases and emoji, separated by commas, and comments containing them are hidden.
- Hide one comment by hand. Swipe the comment, tap Hide. It also offers Report and Restrict from the same place.
- Turn comments off for a single post, from the three dots on the post. Useful for an announcement you do not want a thread under.
- Limit who can comment at all, to people you follow or people who follow you. This is the blunt instrument, and it also silences customers.
- Restrict an account. Their comments become visible only to them, and you are not notified. It is quieter than blocking, which they can see.
- Block, for a handle that is coming back. A blocked account cannot see your profile or comment again.
Two are worth more than the rest. The manual word list is the one you will keep adding to, because you know your own spam: the reseller who names their shop, the phrase the giveaway bots use. And Restrict is the right answer for a person rather than a pattern.
What a word list cannot catch
A manual filter matches words you thought of in advance. Spam is written by people whose job is to not use those words. Six shapes of comment get through a word list every day, and none of them needs a word you would ever have listed.
- A link. Someone drops their own shop, a shortener or a chat group invite under the post you paid to promote. The domain changes daily, so there is no word to add.
- A phone number or an email. A reseller leaves a number under your product post so the buyer contacts them instead of you. Any country code, written with spaces, dots or dashes.
- Emoji. Forty emoji bury the two real questions under your reel, and not one of them is a word.
- Hashtag stuffing. #f4f #followback #likeforlike, posted to farm your audience.
- Tagging your buyers. A spam account replies to the people commenting on your post, tagging them one by one to drag them into a different inbox.
- A handle posing as you. An account with your name and a copied profile picture, telling a customer their order failed and asking for a card number and an OTP to fix it. It uses your brand's own words, so your own filter is the last thing that would catch it.
There is a second problem, and it is the one people notice later. A filter works at the moment a comment is posted. It does nothing about the four hundred comments already sitting under a reel from March.
Instagram's Hidden Words filter matches words you list in advance. The spam that costs you money carries no such word: a shortener link, a phone number, an emoji flood, or a fake support account asking your customer for an OTP. That is the gap an automatic moderation tool fills.
How an automatic moderation rule decides
Comment Guard reads every comment on a connected Instagram account and decides in a fixed order, stopping at the first thing that answers. The order matters more than the rules do, because it is what keeps a customer's comment safe.
- Handles you blocked. Nothing they write is read any further.
- Your never-touch list. Words, phrases and handles you named, plus your leads, plus anybody you have messaged before, plus verified accounts if you want them protected.
- The pattern rules. Links, contact details, emoji, hashtags, mentions, floods, and any words or patterns you added. These cost nothing and run instantly.
- The AI rules, in one call rather than one per rule, and only if nothing above has decided.
- Nothing matched, so the comment stays up.
The test screen in the dashboard runs the identical function, with nothing acted on. You can paste a real comment, see which step decided and why, and change a rule before it touches a post. That is the screen to spend your first ten minutes on.
| Rule | What it looks for | Default | Needs AI |
|---|---|---|---|
| Spam links | Any link out to another shop, shortener or chat group | Hide | No |
| Phone numbers & emails | Contact details in any country's format | Hide | No |
| Emoji flood | More than 20 emoji in one comment | Hide | No |
| 18+ emoji | The explicit set, plus food emoji used suggestively | Hide | No |
| Hashtag stuffing | More than 4 hashtags, ignoring your own campaign tags | Hide | No |
| Tagging your buyers | More than 2 handles tagged in one comment | Hide | No |
| Copy paste floods | The same line from 4 or more handles within five minutes | Off until you switch it on | No |
| Abuse & profanity | Insults and obscenity in whatever language they arrive in | Hide | Yes |
| Negativity | Calling the product a scam or a waste of money | Waits for you | Yes |
| Fake accounts | A handle posing as you or your support team to phish customers | Delete | Yes |
Hide, delete, wait, or let through
Each rule carries one of four actions, and picking them deliberately is most of the work. The defaults lean towards hiding, because hiding is reversible and the person who wrote the comment is not told.
| Action | What happens on the post | Reversible |
|---|---|---|
| Hide | The comment stops showing under the post | Yes, one tap puts it back |
| Delete | The comment is removed from Instagram | No, and no tool can change that |
| Waits for you | Nothing. It is queued under Waiting on you in the feed | Nothing happened, so nothing to undo |
| Let through | Nothing, and the commenter can be tagged as a lead | Not applicable |
The people it never touches
Getting this wrong is the mistake that costs real money, so it is checked before anything that could remove a comment. Five groups are protected, and four of them are switches you control.
- Handles on your never-touch list. Your own team, your regulars, the friend who comments in emoji.
- Comments containing a word on your allow list. Useful for a phrase your customers use that also trips a rule.
- Your leads. Anybody already captured as a lead is left alone.
- Anybody you have messaged before. Worth knowing exactly what that means: it is a DM that was sent, not a purchase, because payments are not part of the product.
- Verified accounts, if you switch that on. It is the cheapest protection against moderating a brand that wants to work with you.
Your own comments are skipped too, which matters more than it sounds. If you run comment-to-DM with a public reply, those replies come from your account, and to a phishing rule they read exactly like somebody impersonating your brand. There is a domain allow list as well, for your own site, your booking page and the marketplace you sell on, so a customer linking your product page is not treated as a reseller.
Watch only, for the first two days
There is a setting worth using before you trust any of this, and the dashboard offers it as a two-day window. In watch only, every comment is read and judged, the verdict is written down, and nothing on Instagram is touched. The feed shows what would have been hidden and what would have been deleted, with the reason on each row.
Read that list, then switch on the rules you agree with and leave the rest off. It is a much better use of two days than turning ten rules on and discovering on Friday that your emoji limit was too tight.
Writing your own rules
Three kinds, beyond the built-in ones. A word rule takes a list of words and phrases. A pattern rule takes a regular expression, for something shaped rather than spelled. And a prompt rule is a sentence describing what you want gone, judged by the model with the rest of the AI rules.
The word rules are the ones most people need, and they stretch further than Instagram's list does. Matching across scripts is on by default, so a word typed in Hindi also matches the same word typed in English letters, and the other way round. Fuzzy matching is on too, which catches the deliberate misspellings: doubled letters, a zero for an o, full stops between every character. Matching inside words is off by default, so a rule for “plum” does not hide a plumber.
The ceilings, read from the code on 28 September 2026: 60 rules per Instagram account, 500 words or phrases in one word rule, 200 characters in a pattern, 600 in a prompt, and 300 entries in each allow list. Some patterns are refused when you save them, with the reason in plain words, because a pattern that repeats a group which already repeats can run for ever and there is no way to interrupt one once it has started.
The confidence line, and what waits under it
The AI rules do not answer yes or no. Each returns how sure it is, from 0 to 100, and you set the line it has to clear before anything happens. Above the line, the rule's action is carried out. In the thirty points below it, the comment is queued under Waiting on you instead, with the score on the row. Further down, nothing happens at all.
Every AI rule is scored before anything is decided, and the strongest call wins rather than whichever rule sat first in the list. That ordering was a real bug once: a 55 per cent abuse match was reached before a 99 per cent impersonation match, so a comment phishing for card details was only queued for review and stayed live. A spammer had to add an insult to survive.
Clearing the spam that is already there
Moderation from now on does nothing about the backlog, so the cleanup sweep is a separate job with a different shape. You pick one post, it reads up to 500 comments from it and says what the current rules would do with each. Nothing is touched at this stage. You tick what should go, and only then does anything reach Instagram.
Two details worth knowing before you run it. Your leads are never swept up in a bulk clean, whatever the rules say. And the model looks at the first 150 comments on a load rather than all 500, so a very busy post reports how many it did not judge instead of quietly pretending it checked everything.
What it costs, and what happens when it runs out
The pattern rules cost nothing and run on every plan, the free one included: links, contact details, emoji, hashtags, mentions, floods and every word or pattern you wrote. The four AI rules spend one credit per check, and credits come with a plan.
| Plan | Price per month | AI credits per month | Comments checked |
|---|---|---|---|
| Free | ₹0$0 | None | Pattern rules only |
| Starter | ₹99$3.50 | None | Pattern rules only |
| Pro | ₹249$9 | 200 | About 830 |
| Business | ₹499$17 | 1,000 | About 4,100 |
| Growth | ₹899$25 | 2,000 | About 8,300 |
| Agency | ₹1,599$40 | 5,000 | About 20,800 |
Two ceilings sit on top of that. One post cannot spend the whole month in an afternoon, because there is an hourly cap of 2,000 AI checks per Instagram account. And identical comments are one check, not fifty, so the fiftieth “fake product” under the same reel is answered from the first one's verdict.
When the allowance goes, nothing switches off. The pattern rules keep running on every comment and the dashboard says which ceiling you hit. A moderation tool that went dark at its limit would be worse than one that does less.
What no tool can do
- Undelete. Instagram does not return a deleted comment, so a delete rule is a decision you cannot take back.
- Work on a personal account. Reading and hiding comments needs an Instagram Business or Creator account and a connection made on Meta's own authorisation screen.
- Moderate somebody else's post, or a live broadcast in any useful way. Live comments scroll past faster than anything can act on them.
- Stop a determined person from coming back. Hiding is not blocking. For a handle that returns under a new name each week, use Instagram's block list, which Guard reads: a blocked handle is deleted without any other rule being consulted.
- Read your DMs. Comment moderation is comments, and inbox spam is a different feature.
A sensible order to do this in
- Switch on Instagram's own Hidden Words filter and add the ten words you already know. Free, five minutes.
- Restrict or block the two or three handles that keep coming back.
- If the spam that is left has no word to catch it, connect the account and leave Guard in watch only for two days.
- Read what it says it would have hidden, and set the emoji and hashtag numbers against your own comment section rather than accepting the defaults.
- Switch on the rules you agree with, hiding rather than deleting, and put your regulars on the never-touch list.
- Sweep your three best-performing posts, since that is where old spam is still being read.
If you want the detail on the rules rather than the setup, /ai-features/comment-guard describes each one and what it costs to run.
Questions people ask about this
- How do I hide spam comments on Instagram?
- For one comment, swipe it in the comment thread and tap Hide. To hide them automatically, open your profile settings, find Hidden Words, switch on the offensive comment filter and add your own words and phrases to the manual list. Comments containing one of those words stop showing under your post, and Instagram does not notify the person who wrote it. For spam that carries no word you could have listed, such as a shortener link or a phone number, you need a moderation tool that matches patterns rather than words.
- Does Instagram tell someone their comment was hidden?
- No. Hiding is deliberately quiet, which is why it is the sensible default for automated moderation and why deleting is not. The comment simply stops appearing under the post for other people. Restricting an account works the same way: their comments become visible only to them and you are not notified of new ones.
- Can I hide Instagram comments automatically without an app?
- Partly. Instagram's own Hidden Words filter is automatic, free and needs nothing installed, and it will handle any spam that contains a word or emoji you listed in advance. What it cannot do is recognise a shape rather than a word: a link to a domain that changes every day, a phone number written with dots, forty emoji, or a handle impersonating your support team. Those need a tool reading the comments through Meta's API.
- What is the difference between hiding, deleting and restricting a comment?
- Hiding removes the comment from public view and can be undone with one tap. Deleting removes it from Instagram permanently, and no tool can bring it back, which is why it should be reserved for rules you have already watched work. Restricting applies to a person rather than a comment: everything they write becomes visible only to them, and they are not told. Blocking stops the account reaching you at all, and they can see that they are blocked.
- Will hiding comments hurt my reach?
- Hiding a spam comment removes engagement Instagram never valued in the first place, since a link-dropping bot is not an audience. The bigger effect runs the other way: a comment section full of resellers and phishing accounts costs you the buyers who read it before deciding. What is worth avoiding is a filter so tight that it hides real questions, which is why watch-only mode exists and why emoji and hashtag limits should be set against your own comment section rather than left at a default.
- How do I stop fake accounts pretending to be my brand in my comments?
- This is the one case where deleting rather than hiding is the right default, because a comment telling your customer their order failed and asking for a card number and an OTP does its damage while it is still visible. It also cannot be caught by a word list, since it uses your brand's own vocabulary. In HookSend it is an AI rule that reads the comment against what your account actually sells, and it deletes rather than hides by default. Add the handle to Instagram's block list as well, so the next comment from it never needs judging.
- Can I clean up spam comments on old Instagram posts?
- Yes, but it is a separate job from ongoing moderation, which only sees comments as they arrive. HookSend's cleanup sweep reads up to 500 comments from one post you choose, shows what the current rules would do with each of them, and changes nothing until you tick what should go. Leads are never included in a bulk clean, and the AI looks at the first 150 comments rather than all 500, so a very busy post tells you how many it did not judge.
- Do automatic comment rules need a paid plan?
- The pattern rules run on every plan, including the free one: links, phone numbers and emails, emoji floods, hashtag stuffing, mention spam, copy-paste floods, and any words or patterns you write yourself. The four AI rules, which read abuse, negativity and impersonation, spend one AI credit per check and start on the Pro plan at 200 credits a month, roughly 830 comments. When credits run out the AI rules go quiet and everything else carries on.
- What happens if the AI gets it wrong?
- A hidden comment can be put back from the feed with one tap, and doing so marks it as a wrong call so you can see how often it happens. Set your rules to hide rather than delete while you are still learning what they catch, since a deleted comment is gone for good. The test screen also runs the identical decision code with nothing acted on, so you can paste a real comment and see exactly which rule decided and how sure it was before you trust it on a live post.