SylonSylon
All featuresJoin Gate

Join Gate

Screens every account at the door — how old it is, whether it has a picture, what it calls itself — and for bots, who added it.

Overview

Every other protection Sylon runs judges a member by something they did: a message, a status, an audit-log entry. By then the account is already inside, and against the two populations this exists for — throwaway accounts made an hour ago and bots somebody added without being asked to — "already inside" is the whole problem. The Join Gate judges the account itself: at the door, and again if the name changes afterwards.

How it works

1

Seven rules, each with its own switch

Account age, no avatar, advertising names, a username blocklist, a suspicion score, unauthorised bot additions and unverified bots. Every one of them is off until you turn it on, and starts as flag-only.
2

You choose what happens

Each rule acts on its own: write a log line, hand out a gate role, time out, kick or ban. A member who trips three rules is acted on once, at the harshest action any of them asked for.
3

The door is not the only check

A raid account's name is usually changed after it is inside. The two name rules run again whenever somebody changes their username, display name or nickname, so a clean handle at the door buys nothing.
4

Nobody is removed silently

The member is sent a direct message naming the rule they matched before the action lands, and the same case is written to your log channel with the account's age, its name and — for a bot — who added it.

Key capabilities

Minimum account age, from one day to a year
Accounts that have never set a profile picture
Names carrying a link or a Discord invite, including spaced-out evasion
A username blocklist using the word filter's own matching engine
A suspicion score that adds up several weak signals instead of trusting one
Bots added by anyone who is not allowed to add bots here
Bots Discord has not verified
A gate role instead of a punishment, when you want a look before deciding
Names re-checked after joining, not only at the door
Exempt roles and members, and its own log channel

Setup

1.Open the dashboard, go to the Join Gate tab and enable it, then pick a log channel — with every rule set to flag-only, that channel is the whole feature.
2.Turn on Account age and set a threshold. Seven days is a sensible start and is the single most effective rule here.
3.Leave every rule on "Flag only" for a few days and read the log. It tells you exactly who would have been removed.
4.Then choose real actions, rule by rule. If you want to look before deciding, pick a gate role and use "Give the gate role" instead of a kick.
5.For bots: switch on Unverified bots and Unauthorised bot additions, and check that Sylon holds View Audit Log.

How it works in detail

Why a score, and not a checklist

Every signal a "suspicious account" check can read is weak on its own. Plenty of real people join on a two-day-old account with no picture and a name full of digits — that is what joining Discord to talk to one friend looks like. So none of them decides anything alone: each is worth one or two points, and the account has to reach a threshold you set. The weights are fixed and listed in the dashboard, so the number you type is a number you can reason about.

The name rules do not judge in English

The pattern that decides whether a name "looks generated" is a statement about Latin spelling — no vowels, an implausible consonant run, a long numeric tail. Applied to a name written in Arabic, Thai, Hangul or Han it would flag most of the world's legitimate usernames, so it is never applied to them. The username blocklist has no such limit: it runs the message word filter's engine, which folds leetspeak, homoglyphs, inserted spaces and repeated letters in every script before matching.

Bots are judged as bots

A bot has no avatar habits and no display name worth reading, and a person is not added by anybody — so the human rules never look at bots and the bot rules never look at people. The two bot rules answer different questions: verification is a fact Discord publishes, and Sylon reads it exactly; who added the bot comes from the audit log, and whether they were allowed to is your own list, or — left empty — the Manage Server permission Discord itself requires to authorise one.

One action, one log line

A member can trip several rules at once, and each rule has its own configured action. Sylon does not apply them in turn: it takes the harshest one and applies it once, writes one log entry naming every rule that matched, and sends one direct message. Removing a bot and acting on the person who added it are the one deliberate exception — those are two different decisions, and the second one defaults to nothing.

Settings

Account ageAccounts created less than the chosen number of days ago. The single most effective filter against throwaway raid accounts.
No avatarAccounts that have never set a profile picture. Weak on its own — plenty of real people never bother — so it works best as a flag, or as part of the suspicion score.
Suspicious accountSeveral weak signals, added up. No single one of them is evidence — the point is that a genuine new member rarely carries more than two.
Advertising nameNames carrying a link or a Discord invite, including the spaced-out forms people use to dodge a check (d i s c o r d . g g).
Username filterMatch names against your own keyword list, using the same engine as the message word filter: leetspeak, homoglyphs, spacing and repetition are all folded before matching.
Unauthorised bot additionsA bot added by somebody who is not allowed to add bots here. Needs View Audit Log — without it Sylon cannot tell who added anything, so the rule stays quiet rather than guessing.
Unverified botsA bot Discord has not verified. Verification is a fact Discord publishes, so this rule is exact — but plenty of small, legitimate bots are unverified.
When it matchesWhat happens when this rule matches. A member who trips several rules is acted on once, at the harshest action any of them asked for.
Gate roleThe role handed out by the "Give the gate role" action. Sylon only assigns it; what it means is your own channel permissions. A member held behind it is also skipped by autorole and gets no welcome message.
DM the member the reasonSend the member a direct message naming the rule they matched, before they are timed out, kicked or banned.
Re-check names after joiningRun the name rules again when a member changes their username or display name after joining. Without this the gate is one-shot: a clean name at the door, an advert a minute later.
Log ChannelThe channel where the bot will send log messages for this feature.
Exempt RolesMembers holding any of these roles will be exempt from this protection.
Exempt MembersSpecific members this system completely ignores, in addition to the exempt roles.

Good to know

The gate needs a log channel. With a rule set to flag-only, that channel is the entire output of the feature.
Permissions depend on what you choose: Manage Roles for the gate role, Moderate Members for a timeout, Kick or Ban Members for the rest, and View Audit Log for the unauthorised-bot rule.
Members with Administrator or Manage Server are never screened, and neither is anyone in the exempt lists.
A member the gate removes or restricts does not get autorole and is not announced by the welcome message.
A username change is rechecked once every thirty seconds per member, so renaming repeatedly does not multiply the log entries.

Frequently asked questions

Will this kick real people?

Not unless you tell it to. Every rule starts as flag-only: it writes a line to your log channel and nothing else, so you can watch what it would have caught for a week before choosing an action. The suspicion score is tuned the same way — a real person who just made an account to join a friend's server scores three, and three is the default threshold, so anything stricter is a decision you make deliberately.

Why does the bot rule need View Audit Log?

Because "who added this bot" exists nowhere else. Without that permission Sylon cannot tell, and the rule stays quiet rather than guessing — a gate that removed every bot it could not account for would be a total failure dressed as protection.

What is the gate role, exactly?

A role Sylon hands out instead of punishing. What it means is your own channel permissions — a read-only view, a holding channel, whatever your server already uses. Sylon only assigns it, and a member holding it is also skipped by autorole and gets no welcome message, so they are not announced as a full arrival.

Is this the same as the invite tracker's account age setting?

No, and the similar name is unfortunate. That one decides whether a join earns its inviter a point; it never touches the member. This one decides whether the member gets in.

Related features