Guide · July 28, 2026 · 6 min read
Securing a Discord server: the complete checklist
Ten points, ordered from the highest return to the most technical. Allow an hour to go through them all. It is the best-spent hour in a server's life: nearly every disaster we come across traces back to one of these ten points left aside.
Contents
1. The default role's permissions
The highest-return item of the lot, and the most neglected. The @everyone role holds,
by default, rights that the vast majority of members have no use for. Four to remove straight
away:
- Mention @everyone and @here — keep it for the team, without exception.
- Attach files — allow it only in the channels that need it.
- Embed links — same, and it closes phishing's way in.
- Create invite — keep it for verified members; this is how a private server stops being private.
Check as well that no secondary role quietly hands those rights back: on Discord, permissions add up.
2. Privileged accounts
Every administrator account is a key to the server. Keys get stolen.
- One or two administrators, not ten. The Administrator permission bypasses every other restriction.
- Precise permissions for moderators — kick, ban, manage messages. Nothing more. Nobody needs Administrator to moderate.
- Two-factor authentication required for moderation — the option is in Discord's settings, it is free, and it is the highest-return setting on the server.
- Quarterly review — strip rights from inactive members. A moderator account forgotten a year ago is an account nobody watches.
3. Installed bots
A compromised bot is the leading vector of destruction on a Discord server, ahead of the stolen administrator account.
- Take an inventory. How many bots? Which are still used? Remove the rest: each one is a door.
- Check their permissions. A music bot has no need to manage roles. Many ask for Administrator out of installation convenience: refuse.
- Place them low in the hierarchy, beneath your moderation roles.
- Be wary of little-known bots found on an obscure directory. The list of permissions requested is a good indicator.
4. Member arrival
Filtering at the door costs less than cleaning up inside.
- Discord verification level at Medium as a minimum.
- Minimum account age — seven days rules out most accounts created for an attack.
- Captcha on arrival, with roles granted after validation, never before.
- Direct messages blocked between server members: that is scammers' favourite channel.
Covered in detail in the guide on captchas and verifying new members.
5. Published content
Three families of threat arrive through the channels:
- Links — phishing, fake Nitro, fake support. See the guide on Discord scams.
- Files — token grabbers, infostealers. See the guide on malicious files.
- Images — fake giveaways and booby-trapped QR codes, which text filters do not see.
Add spam and toxicity, covered by automatic moderation. A server that filters only text lets through two thirds of what circulates today.
6. Mass arrivals
A raid is defined by its speed. What needs to be in place:
- Counting arrivals within a short window;
- Automatic raid mode that locks writing and blocks new arrivals without waiting for a human to wake up;
- Automatic return to normal, so a server is not left locked for a week by oversight;
- Immediate alert to the team, in a dedicated channel.
7. Destruction from the inside
The nuke is the costliest attack: it comes from the inside, from an account that already holds the rights. Permissions therefore protect against nothing — they were granted.
- Counting destructive actions per author in a rolling window: channel and role deletions, bans in series, webhook creation, permission escalation.
- Bots must be watched like humans. Most protections exempt them on principle: that is exactly the blind spot real attacks exploit.
- Graduated sanction, removing roles first — that cuts the permissions even when the kick fails because of the hierarchy.
- Automatic restoration of what has just been deleted.
8. Logging
Without logs, investigating after an incident is impossible: you know neither who, nor when, nor what. Discord's native audit log keeps only ninety days and stays hard to read.
- A private log channel, invisible to members.
- What you need to see there: deleted and edited messages, joins and leaves, role and permission changes, sanctions, bot actions.
- Including the team's actions. A log that exempts moderators is worthless on the day the problem comes from them — or from their stolen account.
9. The recovery plan
An unpleasant but necessary point: Discord offers no backup and no server restore. What is deleted is lost, and messages never come back.
- Write down the structure of the server somewhere outside Discord: channels, categories, roles, permissions.
- Use a bot that recreates automatically what has just been deleted: it is the only genuinely fast restoration.
- Plan a fallback channel — a second empty server, or a way of reaching members outside Discord. A destroyed server with no fallback loses its community for good.
- Write the emergency procedure and make it available to the team: who does what, in what order. Nobody improvises well at three in the morning.
10. The human team
The last point is the only one no tool replaces.
- Train the moderators on common scams: they are the first targets, because their accounts are worth more.
- An absolute rule: no team member ever asks for a password, a code or a screenshot in private. Say it publicly, regularly.
- Run a drill once: who locks down, who communicates, who bans. The first real crisis must not be the first attempt.
- Do not depend on one person. If the owner is unreachable and is the only one who can act, the server is stuck.
Summary
| # | Point | Effort | Impact |
|---|---|---|---|
| 1 | Default role permissions | 5 min | Very high |
| 2 | Privileged accounts + 2FA | 10 min | Very high |
| 3 | Bot inventory | 15 min | High |
| 4 | Verification on arrival | 15 min | Very high |
| 5 | Filtering links, files, images | 10 min | Very high |
| 6 | Anti-raid | 10 min | High |
| 7 | Anti-nuke | 10 min | Critical |
| 8 | Logging | 10 min | High |
| 9 | Recovery plan | 30 min | Critical |
| 10 | Team training | Ongoing | High |
Points 1, 2, 4 and 8 are done entirely inside Discord, with no third-party tool. Points 5, 6 and 7 require a bot: Discord provides nothing natively to analyse a file, read the text in an image or count an account's destructive actions.
OriusBot covers points 5 to 8 in its free version, with the analysis running on its own
infrastructure — no message, file or image from your server is passed to a third-party
service. The /diagnostic command checks in one go which points on this checklist are
actually active on your server.
Frequently asked questions
Where should I start?
With the default role's permissions. Removing the right to send links, attach files, mention everyone and create invites takes five minutes and removes most of the possible nuisance.
How many administrators?
As few as possible: every administrator account is a key that can be stolen. One or two, with two-factor authentication. Moderators do not need the Administrator permission.
Should I require 2FA for moderation?
Yes. The option exists in Discord and neutralises the theft of a privileged account's password. It is the highest-return setting on the server.
How do I know whether my server is protected?
By checking that an answer exists for the five vectors: mass arrivals, destruction from the inside, dangerous content, fake accounts, loss of traceability.
Can a destroyed server be restored?
Discord provides no backup. Messages are lost for good; only the structure and the roles can be recreated, by a bot that restores them or from a recent export.
Read next : Protecting your server from raids, Anti-nuke: protecting your server, Captcha and verification.

