MadHoney doesn't try to recognize spam. It wires up your server so only a bot would ever trigger the trap. Humans click Verify, read a captcha, and get in. Bots post in the decoy channel and get banned. MadHoney deletes their recent messages before anyone wakes up.
A spam bot never posts just once. It blasts every channel it can reach and tries to ping @everyone on the way through. Every message lights up that channel with an unread marker, and here's the part that stings: ban the bot and delete the spam, and those unread dots usually stay. You come back to a whole server flagged with "new messages" for spam nobody should have seen. MadHoney's job is to stop that before it starts - to catch the bot in one place, before it can touch the rest of your server.
Every channel is hidden behind a verified role. A new account sees exactly two things: your rules channel… and one decoy.
Humans click Verify, read an image captcha, and type the code. The whole server unlocks in about ten seconds. No DMs, no third-party site.
The decoy is named like a real channel (#general-2) and it's the only place an unverified account can post. Spam bots post everywhere they can, so they post there first. MadHoney bans the account immediately and deletes its messages from the last 7 days. Verified humans never even see the channel.
A spam bot doesn't pick targets. It dumps its message in every channel it can see and pings @everyone if it can. Gate everything behind the verified role and the only door left open is the honeypot.
Name the decoy like a normal channel (general-2, chat-2) and an indiscriminate bot walks straight in. It looks like just another place to spam.
The honeypot's only content is an image. A human reads "don't post here" and backs off; a bot can't parse a picture, so it posts anyway and trips the trap.
The verified role hides the honeypot from everyone who has passed the captcha, so your members never even see the channel. An account that posts there before verifying can still trip it, which is why a burst of catches is kicked rather than banned until a moderator looks.
MadHoney generates the hazard banner that sits pinned in the honeypot: your headline, body text, colors, fonts, even your community's logo. Design it with /madhoney banner or in the dashboard. The one you're looking at is rendered live by the bot.
No config files, no slash-command archaeology. Sign in with Discord, pick your server, and every decision MadHoney makes is something you can see and change.
/madhoney setup helps you select the required roles and channels. Then /madhoney deploy gives existing members access, posts the panels, and gates your channels. A dry run shows every proposed change before you apply it.
Every ban is reported to a staff channel: who, when, and what they posted. One-click Unban button if a curious human tripped the wire.
Every honeypot catch, across every server, goes to the universal ban list. If you opt in, MadHoney bans known spammers when they join your server. You can also ban all listed accounts with Ban from List. You can opt out at any time; your own catches stay yours. Undo removes a user from the list everywhere.
The honeypot never looks at what a message says, only that it was posted in the trap. Compromised-account detection is the one exception: it compares a member's own recent messages to spot a hijacked account, in memory only, never written to disk. No profiling, no analytics. Staff and owners are always exempt.
Log in with Discord and manage any server where you have Manage Server: config, verify message, banner designer, deploy actions, and the ban log.
Read it, fork it, self-host it. One Node process, three files of state. github.com/nomadsgalaxy/MadHoney · OCL v1.1 + SWAtt.
A stolen account is already verified and already trusted, so no door check stops it. When one blasts the same message across your channels within seconds, MadHoney spots the pattern and acts - report it, kick, quarantine so they must re-verify, or ban. Your choice, per server.
If the honeypot fires more than 5 times in 3 minutes, MadHoney starts raid mode. During raid mode, MadHoney kicks detected accounts instead of banning them. It does not add them to the universal ban list until a moderator confirms the incidents. The health check also identifies each enabled feature that does not have its required permission.
/madhoney setup. Select the Verified role, rules channel, decoy channel, and optional staff log channel./madhoney deploy. Give existing members access. Post the panels. Run the gate dry run. Review the proposed changes. Apply the changes.MadHoney is free to add and free to run. No paywalls, no premium tier, nothing locked behind an upgrade. Running the bot and dashboard does cost real money for servers and hosting, though. If MadHoney keeps your community clean, chipping in helps cover those costs and keeps it free for everyone.
I wanted to tinker with a dynamic cost estimator to help me figure out how much my projects cost me. I thought this would be a neat data point to track and show, for full transparency. If you wish to help offset this cost, feel free to donate via Ko-fi. MadHoney will always be free.
| Bare-metal electricity (MadHoney’s share, at residential rates) | $5.92/mo |
| Cloud failover standby (kicks in if the bare-metal server goes down) | $0.20/mo |
| Cloudflare edge — Workers & D1 database (free at this scale; cost grows with the database) | $0.00/mo |
| Domain & web infrastructure | $0.50/mo |
| Total | $6.62/mo |