Compliance · 7 min read
Instagram DM Automation in 2026: The Complete Picture
This is the overview post. It does not walk you through building anything — the setup guide does that — and it does not argue for a product. It describes the shape of the thing, including the parts that are inconvenient, so you can evaluate anything in this category properly.
There are two kinds of tool, and only one is safe
Everything else follows from this distinction.
Official API
Credential-based
What the official API permits
Three things, and the list is short on purpose.

Reply to a comment, publicly, and open a private conversation with the person who wrote it — for seven days from that comment. The window runs per comment, so an old post that resurfaces still works.
Reply to a direct message, for twenty-four hours from their last message. Only another message from them restarts it. Nothing you send extends it.
Read the events on your own content. Comments and messages that came to you. Not other people's posts, not your follower list's activity, not anything you would have to go and fetch.
Those two clocks, and the ceilings that sit on top of them, are the whole operating envelope. Every tool in this category works inside this table or is not on the official API — with one honest caveat under it about how well any of these numbers are actually sourced:
| Limit | Published | What we run | Why |
|---|---|---|---|
| Private reply to a comment | 7 days | 7 days | per comment, so an old post that resurfaces still works |
| Reply inside a DM thread | 24 hours | 24 hours | restarted only by them writing again |
| DMs per account per hour | ~200 | 180 | deliberately under |
| Comment replies per hour | ~750 | 700 | deliberately under |
| API calls per second | 2 | 2 | Meta's ceiling |
There is a third window most articles never mention. Meta's Human Agent permission extends the 24-hour DM window to seven days — but only for a human replying by hand through an inbox, never for an automation. It is a separate permission, granted per app after review. Ours is submitted and not yet granted, which is why nothing here relies on it. Any tool advertising seven-day DM replies either holds that permission or is describing something else; it is a fair question to ask them.
What no compliant tool can do
Worth being complete, because most of the disappointment in this category comes from expecting one of these.
- Message someone who has not messaged you. No cold outreach, at any price.
- Send a follow-up sequence. A day-three message requires them to have written on day two or three.
- Broadcast to your followers. Same reason.
- Recover an abandoned cart. Instagram does not know your website exists, and the person never messaged you.
- Follow, unfollow, or like at scale. That requires acting as you.
- Read images. A photo-only DM contains nothing to match on.
- See who viewed a story, or message them.
If a product offers these, it is doing the credential thing, or describing an ads product bought in Meta's own tools.
What actually gets accounts restricted
Not automation as a category. The specific behaviours are:
- Acting as the user. Automated following, liking, and DMs sent through a logged-in session.
- Volume that does not look human. Hundreds of identical messages in minutes, which is why a compliant tool paces sends rather than blasting them.
- Content people report. Spam, scams, or repeated unwanted messages, which is a content problem rather than a tooling one.
A tool on the official API, sending replies to people who wrote to you, inside published limits, is doing the thing the API exists for.
What a good one refuses to send
This is the part worth evaluating, because sending is easy and refusing is where products differ.

The three that matter most in practice: takeover, which stands the automation down the moment you reply by hand; dedupe, because Instagram redelivers events and one comment should not produce three replies; and a rate budget, so a post that travels overnight does not become a send storm.
When you evaluate any tool in this category, ask what it does when it is unsure, and whether it can tell you afterwards why something did not go out.
The cost shape to check
Two meters exist in this category and they grow at very different speeds.
A contact meter grows with reach — everyone who ever commented is someone you now hold and pay for. A reply meter grows with conversations, which is a much smaller number, because most people who ask one question go away satisfied.
Here, templated replies are free and unlimited and a credit is spent only when the model writes something new. The free tier is 100 credits with no card, and packs start at ₹499. Whether that shape suits you depends on how much of your inbox repeats — which is a thing you can measure in ten minutes by reading fifty messages and tallying the distinct questions.
The number worth putting against either meter is not the subscription. It is what the unanswered half of your inbox is worth:
Before you compare any pricing page
You answer 18 of 60 a week and miss 42. At 12% those 42 are worth
₹7,560a week, unanswered
42 missed × 12% × ₹1,500. The 18 you do answer are already worth ₹3,240, which is the number worth protecting first.
What this looks like when it is running
Numbers from this product's own database rather than a case study, because every vendor in this category quotes a customer and none of them quote themselves.
Across 2026 so far: 5,104 replies sent, a median of 5.8 seconds from the event arriving to the reply going out, and 2.4% held — refused by the gate above and shown to the account owner with the reason instead of being sent.
That last figure is the one to interrogate when you evaluate anything here. A tool reporting a 0% hold rate is not being careful; it is not checking. Ours is public on the homepage and moves with real traffic.
What to do with all of this
Checklist
If you are evaluating: check for a password field, ask what gets refused, and work out which meter you are being charged on.
If you are building: start with one automation and the paced first week. If you want the safety argument in full, it has its own post.
Questions people ask
Can Instagram DM automation get my account banned?
Not if the tool uses the official API. What gets accounts restricted is acting as you — automated following, liking, and DMs sent through a logged-in session — plus volume that does not look human and content people report. A tool replying to people who wrote to you, inside the published windows, is doing what the API exists for.
Can I send a DM to someone who has never messaged me?
No. No tool on the official API can, at any price. You may reply to a comment for 7 days from that comment, and to a DM for 24 hours from their last message. There is no cold outreach, no broadcast to followers, and no abandoned-cart recovery, because in each case the person never messaged you.
Do I need a Facebook Page?
Yes. A professional Instagram account linked to a Facebook Page is Meta's own requirement for the Instagram Messaging API, not a vendor's. Any product advertising that no Page is needed is not using that API.
How many automated DMs can I send in an hour?
The figure everybody quotes is about 200 per account per hour, and about 750 for public comment replies. Be careful with both: they circulate widely but they are industry convention rather than numbers we can point to on a Meta page, and we mark them as unverified in our own documentation. The one that is genuinely documented by Meta is 2 API calls per second. Sensible tools run beneath whatever the ceiling is, because exceeding it produces an app-level quality signal that affects every account on that app rather than just yours.
What is the Human Agent permission?
A Meta permission that extends the 24-hour DM window to seven days for a human replying by hand through an inbox — never for an automation. It is granted per app after review. Ours is submitted and not granted, so nothing in this product depends on it.
Can automation read a photo someone sends me?
A photo-only DM carries no text to match on, so keyword triggers see nothing. Treat any claim of image understanding here with the same scepticism as a claim of cold DMs.
What should a good tool do when it is unsure?
Hold the reply and tell you why, rather than sending something approximate. Ask any vendor what their hold rate is. A reported 0% means nothing is being checked.


