Sweep InboxMeta Tech Provider
← All articles

Hiding Comments With Links on Ads: Step by Step

Zied
Zied
7 min read
Hiding Comments With Links on Ads: Step by Step

To hide comments with links on ads, open the comment on your Facebook or Instagram ad, tap the menu, and choose Hide comment. That removes it for everyone except the person who posted it. The harder part is catching every link comment fast enough, because scammers post disguised URLs faster than you can moderate by hand, and each one redirects the clicks you paid for.

This guide walks through why link spam is worth your attention, why the platform's built-in tools let so much of it through, and how to build rules that catch shortened and disguised links before a customer ever clicks them.

Why link spam in ad comments costs you real money

When you run a paid ad, you are buying attention. A link comment steals it. A scammer drops "Refunds delayed? Get yours here: bit.ly/xxxx" under your promoted post, and some fraction of the audience you paid to reach clicks that instead of your product. You covered the cost of the impression, and someone else collected the click.

The scale of junk on these platforms is not small. In 2024, Meta removed more than 100 million fake Pages engaged in scripted abuse and took down over 23 million profiles that were impersonating large creators. Fake accounts are the engine behind most link spam, and they keep coming back under new names.

The money side is just as blunt. TrafficGuard estimates that 22% of global digital ad spend is lost to ad fraud, framing it as roughly one dollar lost for every three spent. Not all of that is comment spam, but link comments are a direct, visible slice of the problem: a hijacked comment section quietly siphons the traffic you are paying for.

There is a brand cost too. A comment section full of fake support links and phishing offers makes your ad look untrustworthy, and a shopper who spots one scam link tends to distrust the whole thing. The damage lands right where your conversion happens.

Why Meta's native tools miss disguised and shortened links

Facebook and Instagram give you a profanity filter and a keyword blocklist. Both help, and both are easy to slip past.

The core problem is that keyword blocking matches words, not intent. A blocklist can catch a literal domain, but spammers rarely paste a clean domain anymore. They reach for tricks that keyword lists were never built to handle:

  • URL shorteners. A link like t.ly/abc or bit.ly/xyz hides the real destination. The visible text tells you nothing, and your blocklist has no domain to match. Shortener services are widely abused precisely because they break the connection between what a user sees and where they land.
  • Character spacing and swaps. Writing "b i t. l y" or swapping letters for lookalike characters defeats an exact-match filter while staying perfectly readable to a human.
  • No link at all. "DM me for the discount code" or "link in bio" moves the scam off the comment, so there is no URL to block in the first place.
  • New domains every day. Even if you block one shortener, there are dozens more, and spammers rotate through them faster than you can add entries.

Native filters also run on a delay and require you to be watching. On a busy ad, a link comment can sit at the top of the thread for hours before anyone hides it, which is more than enough time to collect clicks.

How to hide comments with links on ads: the manual way

For a one-off, the manual process is quick:

  1. Open the comment on your ad or post.
  2. Select the three-dot menu on the comment.
  3. Choose Hide comment.

Hiding is usually the right move over deleting. A hidden comment stays visible only to the person who wrote it and their friends, so the spammer does not realize it was removed and is less likely to repost or retaliate. Deleting removes the comment entirely but is more obvious to the poster. Reserve deletion for the worst offenders and hide the rest.

This works fine when you get one link comment a week. It falls apart the moment a bot network targets a scaling ad and drops the same shortened link twenty times an hour across several Pages.

Building keyword and pattern rules to catch link spam

To catch link spam at scale, you need rules that match patterns, not just exact words. Think in layers.

Start with a URL pattern rule

The single most useful rule flags any comment that contains a URL structure at all. Instead of listing individual domains, you match the shape of a link: anything with http, www., or a something.com pattern. Most legitimate commenters on an ad are not pasting links, so a rule that hides comments containing any URL clears out the bulk of link spam with very few false positives.

Add a shortener watchlist

Layer a specific list of common shortener domains on top: bit.ly, t.ly, tinyurl, cutt.ly, and similar. These almost never appear in genuine customer comments on an ad, so hiding anything that mentions them is safe and effective.

Catch the off-platform redirects

Add phrase rules for the language spammers use when they cannot post a raw link: "link in bio," "DM for details," "check my profile," "get yours here." Tune these carefully, since some overlap with normal customer questions, and prefer hiding over deleting so a mistaken match is recoverable.

Cover your languages

If you advertise across regions, remember that spammers work in every language you do. Build your pattern rules to run regardless of the comment's language, and add localized versions of the "link in bio" style phrases for each market you serve.

Real examples of link spam to plan for

The specific scams repeat across almost every ad account. Build your rules with these in mind:

  • Fake support pages. "Having issues with your order? Our team can help: [shortlink]." It mimics your customer service and sends angry or confused buyers to a phishing form that harvests their details.
  • Phishing shorteners. A raw bit.ly or t.ly link with a vague promise of a refund, prize, or discount. The shortener hides the destination so neither the shopper nor a basic filter can tell where it goes.
  • Fake giveaway redirects. "You won! Claim here." posted under a promoted post, riding on the trust your ad already built with the audience.
  • Impersonation replies. A comment from an account using your logo and a near-identical name, dropping a link to a lookalike store. With tens of millions of impersonating profiles removed by Meta in a single year, this is common enough to plan for directly.

Each of these leads with urgency or a reward, then hands off to a link. That structure is exactly what your URL and shortener rules are designed to catch.

How real-time detection hides links before customers click

Rules are only as good as their timing. A link comment that gets hidden the next morning already did its job overnight. The goal is to hide it in the window between when it posts and when a customer notices it.

This is where automation built on Meta's official tools matters. Meta's Graph API and webhooks let an approved tool receive a notification the instant a comment is posted, evaluate it against your rules, and hide it within seconds, with no scraping and no manual watching. That last point is worth underlining: staying on the official API keeps you compliant and avoids the account risk that comes with unofficial scraping.

Sweep Inbox is one tool built this way. It runs on Meta's official Graph API and webhooks, pulls every comment from all your connected Pages into a single inbox, and applies your keyword and pattern rules in real time so link spam is hidden in a few seconds. For an agency juggling many client Pages, or a brand scaling several ads at once, that turns comment moderation from a constant chore into a set of rules that run on their own across 50+ languages.

The practical payoff is simple: fewer hijacked clicks, a cleaner comment section under every ad, and hours you no longer spend refreshing threads to catch the next shortener before it spreads.

Lock down your comment sections

Start with the one rule that does the most work: hide any comment that contains a URL, then add a shortener watchlist and a short list of "link in bio" phrases. Test it against last week's comments to check for false positives, and prefer hiding over deleting so nothing is lost.

If you are running more than a couple of ads, or managing Pages for clients, set those rules to run automatically through a tool on Meta's official API so link comments are gone before a shopper ever sees them. Your next campaign will keep the clicks you paid for instead of handing them to a scammer.

Frequently asked questions

How do I hide comments with links on my Facebook or Instagram ads?

Open the comment on your ad, select the menu, and choose Hide comment. The comment stays visible only to the person who wrote it and their friends, so it disappears for everyone else. To do this at scale, use rules or a moderation tool that hides link comments automatically.

Does hiding a comment notify the person who posted it?

No. Facebook does not notify the commenter when you hide their comment. They and their friends can still see it, which reduces the chance they repost or escalate.

What is the difference between hiding and deleting a comment?

Hiding keeps the comment visible only to its author and their friends, which avoids provoking spammers. Deleting removes it entirely but is more visible to the poster. Most brands hide spam and reserve deletion for extreme cases.

Why do link comments keep appearing on my ads even after I block keywords?

Spammers dodge keyword filters by using URL shorteners, spacing out characters, or writing 'link in bio' instead of a full URL. Pattern-based rules that detect any URL structure catch these variations that plain keyword lists miss.