Scam comments with links show up within minutes of a Facebook ad going live, and the fix is to hide them automatically instead of deleting them by hand. Hiding keeps each comment visible to the person who posted it while making it vanish for everyone else, so the spammer keeps shouting into an empty room and your real audience never sees the bait.

This guide walks through the native settings that catch URLs and suspect words, how to auto-hide comments with links on Facebook ads, the exact rules to add so hides happen in seconds, and how to test the whole thing with a decoy before a big spend.

Person holding a smartphone showing a folder of social media apps

A live ad is a magnet. It reaches strangers, it collects engagement, and it borrows your brand's credibility. Scammers know that a comment sitting under your ad looks like it came from you, so they drop a link and count on a few people clicking before anyone notices.

The most common patterns are easy to spot once you know them:

  • A fake "support" or "official page" reply pointing to a lookalike URL.
  • A "you won" or "claim your gift" comment with a shortened link.
  • Crypto or investment bait promising returns, always with a link to click.
  • Copycat replies impersonating your brand and redirecting buyers to a clone site.

Meta removes an enormous volume of fake accounts and scam ads every year, and it takes down the majority of scam ads proactively before anyone reports them, according to Meta's own integrity reporting. Even so, comment sections move faster than any platform can police in real time, which is why the last line of defense is your own moderation setup.

The stakes are simple. Every link-dropping comment you leave up is a chance to send a paying visitor to a scammer, and a chance to make your ad look untrustworthy to the next person scrolling past.

What native settings catch URLs and suspicious keywords?

Facebook gives you two built-in tools at the Page level, and both carry over to comments on the ads that Page runs. Start here because they are free and they run automatically.

The profanity filter. In your Page settings you can set a profanity filter to Low, Medium, or Strong. It hides comments that contain flagged language. Scammers do not usually swear, so this one matters more for tone than for links, but leave it on Medium as a baseline.

The keyword blocklist. This is the real workhorse. You can add a large list of words, phrases, and emojis, and any comment containing an exact match gets hidden automatically. It exists in your content moderation settings and supports bulk upload, so you can paste a long list at once.

Here is the catch that most guides bury. Meta's newer Moderation Assist rules, the ones that let you trigger on links or account age, apply to organic Page posts and not to ad comments. On ads you are working with the profanity filter and the keyword blocklist. That gap is exactly why link spam survives on ads that looks handled on a normal post.

So the native layer is worth setting up, but on its own it is a sieve. It catches the exact words you thought to list and misses everything you did not.

The behavior you want is specific. When you hide a comment, it disappears from public view but stays visible to the person who wrote it and their friends, and that person is not told it was hidden. The spammer thinks their link is live. Nobody else ever sees it.

To make that happen for any comment containing a link, you combine two things.

Step one: stack your keyword blocklist with link fragments. Native settings match exact terms, so add the pieces a URL is built from:

  1. Add http and https to catch full links.
  2. Add www for links written without a scheme.
  3. Add common endings like .com, .net, .io, .xyz, and .link.
  4. Add link-shortener stems such as bit.ly and tinyurl.
  5. Add the words scammers pair with links, like "claim," "gift," "winner," and "whatsapp."

This alone hides a large share of obvious spam the moment it posts.

Step two: connect a tool that reads Facebook's own link detection. For true coverage across every ad, including dark posts, you connect an API-based moderation tool such as NapoleonCat, Agorapulse, or similar. These tools let you build a rule like "if a comment contains a link, hide it," and they hide it in near real time.

One important detail from NapoleonCat's own documentation is that this link detection leans on how Facebook classifies a link, which depends on the URL scheme. A comment with https:// gets flagged as a link. A bare acme.com written without the scheme may not, which is why your keyword blocklist of domain endings still matters as backup.

Together, the blocklist catches the plain-text domains and the tool catches the properly formatted links. Neither is complete on its own.

What rules should you add so hides happen in seconds, not hours?

Speed is the whole point. A comment hidden four hours after it posts has already done its damage. Build your rule set so the common cases fire instantly and you only review edge cases by hand.

Add these rules, in this order of value:

  • Contains a link, hide. Your primary rule. Anything Facebook reads as a URL gets hidden.
  • Contains a blocked keyword, hide. Your backup for bare domains and scam vocabulary.
  • New account with a link, hide. Where your tool supports account-age filters on ads, brand-new accounts posting links are almost always spam.
  • Repeated identical comment, hide. Bot rings paste the same text across many ads.
  • Escalate the rest. Route anything that is not an obvious hide to a human, so real customer questions still get answered.

A comparison helps you see where each layer pulls its weight.

CoverageNative profanity filterNative keyword blocklistAPI-connected tool
Runs on ad commentsYesYesYes
Catches full https:// linksRarelyOnly if listedYes
Catches bare domains like acme.comNoYes, if endings listedSometimes
Filters by account age on adsNoNoOften
Setup costFreeFreePaid subscription

The pattern is clear. Native tools handle the words you can predict. A connected tool handles the links you cannot list one by one. Run both.

Close-up of a smartphone showing social media app icons

How do you test your setup with a decoy comment?

Never trust a moderation rule you have not watched fire. The test takes five minutes and saves you from launching a big campaign with a broken filter.

Do this before you scale spend:

  1. Use a second personal account, not your admin or Page account. Ask a colleague or use your own secondary profile.
  2. Post a decoy comment on a live or preview ad that contains a trigger. Try one with https://example.com and a second one written as example.com with no scheme.
  3. Watch the timing. Note how many seconds pass before each comment is hidden. Your link rule should fire almost immediately.
  4. Verify visibility from both sides. Log out or use a different browser to confirm the comment is gone for the public, then check the posting account to confirm it still appears for the author.
  5. Check the bare domain. If example.com without a scheme stays visible, that is your signal to expand your keyword blocklist with more endings.

If both decoys vanish for the public and remain for the poster, your setup works. If only the https:// version disappears, your tool is catching schemes but your blocklist needs more domain endings to cover plain-text links.

Run this test again whenever you change tools or add a new ad account, because a filter that worked last quarter can quietly stop covering a new placement.

Where does consistent content fit into all this?

Clean comment sections protect the traffic your content already earns, and content is what keeps that traffic coming. Moderation is defense. Publishing is offense. You want both running so your ads and your organic pages reinforce each other instead of fighting scammers alone.

If comment cleanup is eating the hours you meant to spend writing, that trade is worth naming. The bottleneck for most brands was never the ability to write a good post, it was finding the time to keep publishing week after week while also running ads and moderating replies. Automating the repetitive parts, whether that is hiding link spam or keeping a blog fresh, frees you to spend attention where it actually moves the needle.

That same logic is why brands lean on tools like Bunzy to keep publishing on a schedule while they handle the campaigns, and why getting your content structured for AI answer engines has become part of the same playbook. If you want to go deeper on that side, our guide on how to get cited by ChatGPT covers the formatting that answer engines actually quote.

Set your native filters today, stack your blocklist with link fragments, connect a tool for real link detection, and run a decoy test before your next launch. That order takes an afternoon and it keeps every dollar of ad spend pointed at your real audience instead of a scammer's link.