How WhatsApp's Anti-Spam System Works
AndySendy academy

WhatsApp Anti-Spam: Account Weight, Unanswered Counter and Four Detection Layers

Why read this lesson before you start warming up

Over the next two weeks, you'll be doing things that look like superstition if you don't understand the system:

  • Waiting more than a minute between messages — and a different interval every time
  • Changing the text even though the meaning stays the same
  • Starting with 3–5 messages per day when you want to send a hundred right away
  • Increasing volume bit by bit, day after day
  • Not jumping straight into broadcasts, but weaving them into warm-up gradually

With an understanding of the logic, each of these points becomes obvious math. Without it, you'll inevitably cut a corner at the worst possible moment — and the number will be lost.

Scale of the system: a few numbers

Before we break down how the system works, get a sense of its scale.

WhatsApp blocks more than 8 million accounts per month for violations — and most owners only find out when they try to use the app again. That's about 270,000 bans per day. While you're reading this paragraph, the system has blocked another hundred numbers.

The most important point: 25–30% of all bans happen before a single user taps "Report". The algorithm detects the pattern on its own — from behavior.

This isn't scare tactics. It's context: the system operates at industrial scale, automatically, and there's practically no second chance.

The core idea: "Account weight"

WhatsApp doesn't divide numbers into "good" and "bad" once and for all. Every account is assigned an invisible weight in real time — an accumulated trust score.

  • Low weight → the system watches under a microscope. Any non-standard action means a ban.
  • High weight → the system trusts you. You can do more, faster, and there's a safety margin for mistakes.

A new number always starts at zero. Warm-up is the systematic building of this weight to a level where broadcasts become safe.

Tip: "weight" doesn't accumulate only through sent messages. Viewing statuses, replying to incoming messages, calls, session time — all of this adds weight.

What the system sees before your first message

Few people understand this — and many get burned by it.

The algorithm evaluates an account not from the moment of the first send, but from the moment of registration. Before you've written a single word, the system already knows three things.

Device

Meta collects hundreds of parameters: hardware IDs, screen resolution, fonts, plugins, Canvas rendering, and much more. A real phone with a unique IMEI is one trust profile. An emulator (BlueStacks, NoxPlayer, and other Android imitations on a PC) is another. Bots often use emulators, and Meta's systems know their fingerprints. An emulator with default settings is easy to detect. The result is a permanent ban with no appeal option.

IP address and its reputation

There are two important cases here.

First: home or office Wi-Fi where someone already spammed or received bans. That IP is already "dirty." WhatsApp checks your IP against Meta's internal databases and external spam databases — Spamhaus, Barracuda, URIBL. Datacenter IPs and known proxy ranges are often blocked automatically, without any prior violations.

Second: the IP address must be stable. Frequent logins and logouts from the account or IP changes look suspicious to Meta's security system.

Takeaway: mobile internet from the same SIM you're registering is the only safe option at the start.

Registration speed and cluster

Meta compares your SIM's country code with the IP, time zone, and device profile. If something doesn't match or looks too "clean" — the account gets flagged. Several numbers registered in a row from the same device or IP in a short time is a farm pattern. Each of those numbers gets elevated starting risk regardless of further behavior.

Four detection layers

Layer 1. Registration fingerprint

Described above: device, IP, registration cluster. Triggers before the first message.

Layer 2. Behavioral analysis — where most people get burned

This is the main layer. The system continuously sums a "risk score" across several signals at once. A ban triggers when the score crosses a threshold — even if no single signal looks critical on its own.

Signal What's tracked
Send speed Messages per minute / hour / day
Response Ratio Percentage of recipients who replied
Timing patterns Identical intervals = machine
Contact history Has this person written to you before? Is your number saved in their contacts?
Unanswered Counter Accumulated count of unanswered messages over 30 days

Unanswered Counter is the key mechanism of 2025–2026. It's a rolling 30-day window: how many of your messages didn't get a reply within 48 hours. The counter is cumulative and applies to all account types. It's what kills most numbers during improper warm-up.

Approximate safe thresholds (practical observations, not official Meta data):

Metric Safe Warning Danger
Messages / hour < 30 30–60 > 60
Response Ratio > 30% 15–30% < 15%
New contacts / day < 20 20–50 > 50
Identical messages / hour < 5 5–15 > 15

Important: these thresholds are for a warmed-up account in working mode. At the start of warm-up, we're talking about 3–5 messages per day. You still need to grow to reach these thresholds.

Layer 3. User reports

A report rate above 2% of contacts — and the account's quality rating drops to "Low." Several reports within 24 hours — a temporary send restriction. When warming up through a trusted pool, this layer is practically inactive — you only work with people who are guaranteed to reply. Reports are covered in a separate module on broadcasts.

Layer 4. Content analysis

WhatsApp doesn't read encrypted messages, but it analyzes content metadata: structural similarity of texts across different conversations, link reputation on global blacklists, forwarding patterns.

The algorithm identifies a template without reading the content — by length, structure, characteristics. "Hi [Name]! I have an offer" and "Good afternoon [Name]! I have an offer for you" — that's one template for the system.

Tip: that's exactly why Spintax must change not just one word, but phrase order, greeting, message length. A minimum of 4 nesting levels isn't overkill — it's a necessity.

How the system "thinks" at different stages of account life

First 7 days: maximum sensitivity

No history — no trust credit. Meta watches the first 72 hours of account activity like a hawk. Real users don't blast out 10 messages on day one — they browse, hesitate, get added to groups.

Main triggers at this stage:

  • Unanswered Counter — several messages in a row without a reply, and the system treats it as a broadcast
  • Outgoing/incoming ratio — a live person in the first week more often receives messages than writes themselves. Outgoing skewed more than 3:1 is a trigger
  • Timing — identical intervals between messages are a bot signature. Pauses must be longer than a minute and a different length each time

A ban at this stage: automatic, instant, with no right of appeal.

Days 7–21: behavioral and content filter

The account has left the extreme risk zone but falls under pattern analysis.

  • Content Similarity — message structure across conversations is compared
  • Ecosystem Usage — bots are built only for sending. The system checks: does the number view others' statuses, make calls, open settings. Absence of "everyday" activity is an automation marker
  • Spike Detection — a sharp volume jump without gradual growth. Safe growth: no more than ~20–30% of the previous day's volume

After 30 days: stable mode

The account has built weight. But the system doesn't turn off — daily rhythm, link reputation, accumulated Response Ratio continue to affect the safety margin.

How to transition from warm-up to broadcasts

The main mistake most people make is a sharp transition: two weeks of warm-up, then immediately launching a broadcast to hundreds of numbers. That's Spike Detection in its pure form, and a ban is practically guaranteed.

The right logic is gradually weaving broadcasts into warm-up:

  1. At the start — only incoming and mutual messages with trusted numbers. Volume: 3–5 per day.
  2. After a few days, the first cautious outgoing messages are added — 5–10 per day, warm contacts only.
  3. Volume grows gradually, day by day. No jumps.
  4. Incoming messages and replies from the trusted pool keep running in parallel — they hold Response Ratio at a safe level.
  5. Only when the account has built weight and Response Ratio is consistently high — broader broadcasting is connected.

The average Response Ratio for marketing messages is 30–50% according to Meta benchmarks. Dropping below 15% leads to account quality problems.

Warm-up builds the safety margin; broadcasting spends it. Running both in parallel replenishes the margin at the same time it's being spent — that's what makes the system sustainable.

When to return to warm-up mode

Warm-up isn't a one-time procedure. It's a tool you need to return to at any warning signal.

Metrics in the "warning" or "danger" zones are the system's signal that the risk score is rising. The right action is one: stop broadcasts and return to pure warm-up mode — incoming messages, mutual replies, low volume, high Response Ratio.

Trying to "ride it out" while continuing broadcasts means continuing to spend a safety margin you no longer have.

Why warm-up rules are not superstition

Now everything falls into place.

Pauses longer than a minute, different each time — because the algorithm detects rhythm. Identical intervals = machine. Irregular pauses = human.

Randomized texts — because Content Similarity works on structural similarity, not exact matches. You need to change not just one word, but phrase order, greeting, length.

3–5 messages per day at the start — because Unanswered Counter and Spike Detection are maximally sensitive in the first week.

Gradual growth — because Spike Detection catches jumps specifically. A smooth growth curve is invisible to the algorithm.

Incoming matters more than outgoing — because Response Ratio and the in/out ratio are primary trust signals.

"Everyday" activity — because Ecosystem Usage distinguishes a live account from a send-only bot.

Summary in one list

✅ Incoming from saved contacts ✅ Mutual replies — especially detailed ones ✅ Varied content: text, media, voice messages ✅ Pauses longer than a minute, a different length each time ✅ Everyday activity: statuses, views, settings ✅ Clean IP — mobile internet from your own SIM ✅ Smooth volume growth without jumps ✅ Return to warm-up at any warning signal

❌ Registration from an emulator ❌ Multiple registrations in a row from the same device or IP ❌ Dirty IP: Wi-Fi where someone spammed; VPN; proxy; datacenter ❌ Identical intervals between messages ❌ Outgoing without incoming ❌ Structurally similar texts without Spintax ❌ Sharp volume spikes ❌ Links with bad reputation in first messages to new contacts ❌ Device or IP change during an active period ❌ Sharp transition from warm-up to broadcast

What's next

In the next module — a step-by-step 14-day warm-up plan: specific volumes by day, content types, when and how to weave in the first broadcasts, and when to connect automation.