Compliance · 5 min read

WhatsApp Spam Policy 2026: Complaints, Blocks and Bans

The PostEngage teamEngineering and support ·

You can read Meta's messaging policy end to end and still get reported, because the policy describes rules and the report comes from a person having a reaction.

This post is written from the other side of the thread. Not what the rulebook forbids, but what a real person is doing in the seconds before they press block — because that reaction is the signal the platform actually watches, and the reaction has its own logic.

The context nobody accounts for

An Instagram DM lands in an app people opened to be entertained. A WhatsApp message lands between their mother and their child's school group, on the same screen they use to coordinate a hospital visit.

That is the whole difference. The tolerance for an unwanted message is far lower here, and the response is not a scroll past. It is a block, from somebody who was in the middle of their day.

The same message, word for word, is a mild annoyance on one channel and an intrusion on the other. The words did not change. The room did.

The five moments

Almost every complaint comes from one of these. Notice how few of them are about the message being badly written.

  1. "Who is this?" The recipient does not recognise the sender. This is the biggest one by a distance, and it comes from messaging a number you obtained rather than one that was given to you for this purpose. A number from an order form, a business card, a lead ad or a purchased list is a number, not permission.
  2. "I did not sign up for this." They recognise you, and the message is not what they agreed to. Somebody who consented to delivery updates and got a festival sale is being marketed to without consent, and the recognition makes it worse rather than better — it feels like a bait and switch by a business they trusted.
  3. "Again?" Recognised, expected, and too frequent. The individual message is fine. The third one this week is not. Frequency to one person turns a tolerant recipient into an irritated one faster than total volume ever does.
  4. "I already told you to stop." The most expensive of the five. A stop request that was ignored, or that only paused one campaign, converts somebody mildly annoyed into somebody who reports you and tells other people.
  5. "This does not smell right." Urgency, a prize, a payment link, a claim that overreaches, a display name that does not match the business. People in India are attuned to this because they are targeted constantly, and a legitimate business writing in the register of a scam gets treated like one.

Four of the five are decided before a single word of the message is written.

Why volume is the wrong thing to optimise

The instinct after a scare is to send less. That is usually the right action for the wrong reason, and the wrong reason will lead you back into trouble.

A thousand messages to people who were expecting them is a healthier pattern than fifty to people who were not. The offence is not volume. It is volume applied to people who did not ask.

Which means the metric to protect is not your send rate. It is the proportion of your sends that somebody actually wanted — and that proportion is set by how you built the list, not by how carefully you throttle it afterwards.

The ten checks every reply passes through, in order: kill switch, connection, takeover, window, dedupe, cooldown, quiet hours, rate budget, credits, content safety.
Two of these carry most of the weight for complaint prevention on any channel. Cooldown stops one person hearing from you twice in quick succession. Rate budget turns a spike into a queue.

What software can genuinely prevent

An honest split, and it is the same one we would want applied to us.

A tool can

Refuse to send outside a permitted window. Enforce a cooldown per person. Halt everything on a keyword that reads as a stop request. Pace rather than burst. Keep a never-send list you can edit. Record every refusal with its reason.

A tool cannot

Know whether somebody genuinely consented. Make an unrecognised sender recognisable. Prevent a block. Undo a report. Judge whether your offer is relevant to the person receiving it.

The right column is where the complaints come from. That is the uncomfortable part of this whole topic: the controls a tool sells you operate on the smaller half of the problem.

The stop request deserves its own paragraph

If somebody asks you to stop — in any wording, in any language, including "band karo", "mat bhejo" or a single angry word — the stopping has to be immediate, total and permanent. Not paused for this campaign. Not until the next list upload overwrites it.

Practically, that means the suppression has to live somewhere higher than the campaign: a list every send checks against, that a bulk import cannot quietly reset. Ask any vendor to show you exactly where that lives. It is a five-minute question that predicts a great deal about the product.

Where we actually stand

PostEngage does not ship WhatsApp. The behaviour described above is how the channel works, not a feature set you can turn on with us.

On Instagram, where we do run, the structural protection is that there is no outbound at all — the product replies to people who contacted us first, inside Meta's windows, and every refusal is recorded with a named reason.

If you want what happens after the complaints accumulate, the restrictions post is blunt about it. If you want the health signal underneath, the quality rating post explains it. And if you want the map of the policy documents themselves, that is here.

One email when we publish.

No drip sequence, no “quick question” follow-up. Unsubscribe is one click and we honour it immediately.