Compliance · 4 min read
WhatsApp Business Account Restricted: What Causes It
Two honest limits before anything else. Only Meta can restrict a business account, and only Meta can lift a restriction. No vendor has a back channel, an appeals contact, or a way to make it not happen. Anyone claiming otherwise is selling something they do not have.
And the specifics of Meta's enforcement — the exact thresholds, the exact signals, the exact appeal route — change, and are documented by Meta rather than by us. What follows is the shape of the thing, which changes far more slowly.
The mechanism people misunderstand
The instinct is that restrictions are about volume: send too much and you get caught. That is not quite it.
The load-bearing signal on this channel is what recipients do. A person who did not want your message has a block button in the same place as the reply button, and blocks are the currency of the whole system. A thousand messages people were expecting is a healthier pattern than fifty messages to people who were not.
Volume is not the offence. Volume applied to people who did not ask is.
That inverts the usual optimisation. The thing to protect is not your send rate; it is the proportion of your sends that somebody wanted.
What actually earns a restriction
- Messaging people who did not opt in. A number obtained from an order form, a business card, or a purchased list is a number, not permission. This is the single largest cause and it is entirely self-inflicted.
- A mismatch between what you said and what you sent. Somebody who agreed to delivery updates and receives a festival sale is being marketed to without consent, and they respond accordingly.
- Ignoring a stop request. If somebody asks to stop and a campaign continues, every subsequent message is a report waiting to happen.
- Volume that arrives faster than a human could produce it, which reads as automated regardless of how it was sent.
- Content that gets reported — misleading claims, anything that looks like a scam, anything a person would screenshot.
Notice that four of the five are decisions about who and what, not about tooling.
What a tool can honestly do
This is the part worth evaluating, and the questions are the same ones we would want asked of us on Instagram.
A tool can
A tool cannot
The left column is what "safe automation" actually means, and it is unglamorous: a system that sends less than it could, on purpose, and can tell you what it declined and why.

Two of those checks matter disproportionately for account health on any channel. Cooldown stops one person receiving two messages in quick succession, which is what makes an account feel like a machine to the person on the other end. Rate budget turns a spike into a queue rather than a burst.
If it has already happened
The honest sequence, and it is short:
- Stop everything. A kill switch that halts all automation immediately is the first thing to reach for, before diagnosis. Continuing to send into a restriction makes the pattern worse.
- Read what you sent. Not what you meant to send — the actual outbound messages, from the last week. Most causes are visible on inspection.
- Use Meta's own appeal route, whatever it currently is. There is no other route, and any vendor offering one is not describing a real thing.
- Fix the cause before asking to be reinstated, because a restriction lifted on an unchanged setup comes back.
The prevention that actually works
Almost all of it is decided before a single message is sent.
Only message people who asked. Say what you will send and then send only that. Make stopping easy and make it take effect everywhere immediately. Keep the proportion of wanted messages high, which usually means sending fewer of them to a smaller list rather than more to a bigger one.
What exists here today
PostEngage does not ship WhatsApp. On Instagram, where it does run, the equivalent question is whether automation gets an account restricted — and the answer is that it depends entirely on whether the tool acts as you. A tool on the official API replying to people who contacted you is doing the thing the API exists for; a tool signing into your account is a different product with a different risk, carried by you.
That argument is here in full, and the practical risk picture is here.



