All posts
SafetyMeta PolicyReference

Instagram Automation Rules 2026: Allowed vs Banned

A clear reference for Instagram's 2026 automation rules: exactly what's allowed, what's banned, and where the line sits, straight from Meta's official messaging policy.

The heyy.to team5 min read

Most posts about Instagram automation rules bury the actual rules under a thousand words of throat-clearing. This one does not. Here is the allowed-vs-banned list, straight, with the reasoning underneath it. Bookmark it if you run automations.

Allowed

These are things Meta's official Messaging API supports directly. Doing them is not a loophole. It is the intended use.

  • Auto-replying to a comment. When someone comments on your post or reel, you can send them one private reply, within 7 days of the comment. One reply per comment.
  • Auto-replying to a DM. When someone messages your account, you can respond with standard messages for 24 hours. This covers keyword replies and story-reply flows.
  • Auto-replying to a story reply. A story reply is a message to you, so it opens the same 24-hour window.
  • Sending links, lead forms, and offers inside those windows. Normal message content is fine.
  • Using an approved tool on the official API. Automation itself is allowed. Meta built the API for it.
  • Running this across multiple accounts, each connected properly through the official login.

Banned

These get you an action block or worse, regardless of which tool you use.

  • Cold-DMing strangers. Messaging people who never engaged you first. There is no window for a stranger, so there is nothing compliant to send.
  • Auto-DMing new followers. A follow is not a message. Auto-messaging every new follower is cold outreach, and it is a line we refuse to cross.
  • Using a tool that logs in with your password. Third-party apps accessing your account via your login credentials violate Meta's Terms of Use and can lead to a permanent ban.
  • Blasting identical messages at high volume. Mass DMs with no pacing look like a spam cannon.
  • Unthrottled sends during a viral spike. Thousands of DMs in minutes is the classic ban trigger, even when every recipient commented.
  • Misusing the human-agent tag to extend automated messaging past 24 hours. That tag is for real humans, not bots.

The line, in one sentence

You are allowed to respond to people who engaged you, inside Meta's windows, at a human pace, through the official API. Everything banned is some version of breaking one of those four conditions: cold outreach, outside the window, too fast, or off the official API.

If you keep that sentence in your head, you can classify almost any automation feature yourself. "Auto-DM new followers?" Cold outreach. Banned. "Reply to a comment with a link?" Response, inside the window, allowed. It is not complicated once you see the shape.

Quick-reference table

If you want the whole thing at a glance:

ActionAllowed?Why
Reply once to a comment within 7 daysYesMeta's private-reply mechanic
Reply to a DM within 24 hoursYesStandard messaging window
Auto-reply to a story replyYesA story reply is a message to you
Send a link or offer inside the windowYesNormal message content
Cold-DM a strangerNoNo window opens for a stranger
Auto-DM new followersNoA follow is not a message
A tool that uses your passwordNoViolates Meta's Terms of Use
Thousands of DMs in minutesNoLooks like a spam cannon
Human-agent tag on automated sendsNoThe tag is for real humans only

Where tools differ

Two tools can both be technically on the official API and still land you in very different places, because a tool can offer banned behavior on top of an allowed foundation. A tool that lets you cold-DM followers is handing you a banned action with a friendly button. The API underneath being official does not save you.

This is why we designed heyy.to so the rules are built into the product, not left to you to enforce:

  • Official API, so the password-login rule is impossible to break.
  • Triggers only, so cold DMs and auto-DM-to-new-followers are not even options.
  • A per-account rate cap, so the volume and viral-spike rules hold automatically.
  • One reply per matched comment, so your public replies stay clean.
  • A kill switch, so you can stop everything if a warning appears.

The rules do not change based on how careful you feel on a given day. Building them into the tool is how you make "allowed" the only thing you can actually do.

Common questions

Did Instagram's automation rules change in 2026? The core rules have been stable: respond to engagement, inside the windows, at a human pace, on the official API. What changes over time is enforcement getting sharper, which is why the accounts doing risky things keep getting caught in bigger batches. The rules did not move. Detection did.

Do I need a professional account to automate compliantly? Yes. The official Messaging API works with Instagram professional accounts (Business or Creator) connected to a Facebook Page. If a tool automates a personal account, it is almost certainly a credential-based bot.

Is a keyword auto-reply allowed? Yes, as long as it fires in response to a comment or a DM the person sent. That is a reply, not cold outreach. The keyword is just how you decide which reply to send.

Keep this handy

Instagram's automation rules in 2026 are not a mystery. Respond to engagement, inside the windows, at a human pace, on the official API. Everything else is a variation on those four. Use this list to sanity-check any tool or feature before you turn it on.

The creators who stay out of trouble are not the ones who memorized a policy document. They are the ones who picked a tool that cannot break these rules for them. That is the difference between hoping you stay compliant and being compliant by default.

For the full explanation behind each rule, read our Instagram automation safety guide.

See how heyy.to builds the rules in →

© 2026 heyy.to. All rights reserved.hello@heyghe.com