Mass DMing to promote OnlyFans on X, the platform formerly called Twitter, runs straight into its spam rules: X's Authenticity policy lists sending bulk, aggressive, high-volume unsolicited direct messages as content spam, and its automation rules only allow automated DMs to people who asked to hear from you first and have an easy way to opt out. What X does leave open is an opt-in inbox, where fans start the conversation and you answer them as a person.
This page maps the rules that touch creator messaging, hashtags, follows and tools, as published on X's help centre on 1 October 2026. It deliberately contains no bulk-messaging method. Day-to-day engagement routines are in our X community engagement workflow; the labelling rules for adult media are in our X adult content policy guide.
Where X keeps its spam rules
The X Rules page summarises platform manipulation and spam in one sentence: you may not use X to artificially amplify or suppress information, or behave in ways that manipulate or disrupt people's experience. Its “learn more” link leads to the Authenticity policy, dated April 2025, which holds the detailed lists of what counts as inauthentic accounts, behaviours and content. Many older guides point to a separate platform manipulation page; follow the Authenticity policy, because that is where the X Rules send you today.
Three other pages fill in the detail. The automation rules, updated April 2026, are written mainly for developers but carry a direct note for ordinary users. The limits page sets technical caps on actions. The Direct Messages help page explains message requests and the settings that decide who can reach you.
What X treats as DM spam
Under the heading Content Spam, the Authenticity policy says you may not post or share content in a bulk, duplicative, irrelevant or unsolicited way that disrupts people's experience. Several items on its not-allowed list describe exactly what a promotional DM campaign looks like:
- sending bulk, aggressive, high-volume unsolicited replies, mentions or direct messages;
- repeatedly sending messages made of links without commentary, so that bare links become most of what your account sends;
- sending identical direct messages, the inbox version of what X calls copypasta;
- replying to other people's posts with promotion unrelated to what they wrote.
None of those items depends on software. The list describes behaviour, so a person pasting the same pitch into inbox after inbox by hand fits it as neatly as a script does. The useful question before any outreach is not “is a tool sending this?” but “did this person ask to hear from me?”
Automated messages and the opt-in rule
The automation rules are not hostile to automation as such. Their “Do” list includes building solutions that automatically respond to users in Direct Messages, while the “Don't” list includes spamming or bothering users and sending them unsolicited messages. The line is drawn at consent: automated DMs are allowed only when, before the message is sent, the recipient has requested or clearly shown an intent on X to be contacted by you by DM, for example by messaging you first, and when you give a clear, easy way to opt out and honour opt-outs promptly.
One ground rule matters more to adult creators than any other. The automation rules say not to Direct Message, mention or reply to users with potentially sensitive content, profanity included, unless they have clearly indicated in advance that they want to receive it. A welcome auto-reply therefore has to be safe for work, whatever the account usually posts.
The same page closes off the tools many growth services sell. It says not to use non-API forms of automation, such as scripting the X website, and warns that doing so may result in permanent suspension. It also says that a user authorising an app through OAuth is not, by itself, enough consent for automated actions through that account: the app must describe the actions, get express consent and honour a request to stop. For users, the page puts responsibility plainly: you are ultimately responsible for actions taken with your account or by applications associated with it, and X may filter your posts from search or suspend the account if automated activity breaks its rules. If an agency or assistant runs your inbox, settle those permissions in writing first; our agency account access checklist lists what to agree.
Hashtags, follows and engagement swaps
The Authenticity policy reaches beyond the inbox. On hashtags, it prohibits using trending or popular tags to subvert a conversation or to drive traffic to accounts, websites, products or services, and posting excessive, unrelated hashtags in a single post or across many posts. A promo post riding an unrelated trend is the textbook case.
Its Engagement Spam section lists coordinating to exchange engagement such as likes, replies, reposts or follows, paying others to inflate metrics, follow churn, indiscriminate following of unrelated accounts in a short period, aggressive or automated engagement meant to drive traffic, copying another account's followers, and using or promoting third-party services that do any of these. Repost rings and “engagement trains” sold to creators fit the description of coordinated engagement exchange. X's account behaviour best practices page adds that automated proactive following and automated unfollowing are not allowed.
Extra accounts are governed by the same policy. The Authenticity policy says X allows users to create or operate up to ten accounts for different, non-duplicative purposes, and it lists a personal account alongside pseudonymous or hobby accounts as allowed. It prohibits running several accounts that boost the same hashtags, engage with the same posts or cross-post the same content, and it bans ban evasion through new or repurposed accounts, adding that X may suspend other accounts it believes the same person operates. A backup account that reposts your main account's promos is not a spare; it is a second exposure.
Technical limits are ceilings, not targets
X's limits page lists a daily cap of 500 sent Direct Messages and a technical follow limit of 400 per day, and it adds that the follow figure is a technical account limit only, with additional rules prohibiting aggressive following. The limits count actions from every device and app, including third-party tools.
The same limits page is not internally consistent on posting: it gives 50 original posts and 200 replies per day for unverified accounts, then later refers to a post limit of 2,400 updates per day. We could not reconcile the two from X's text, so do not build a posting schedule around either figure. More importantly, staying under a cap does not make unsolicited messaging acceptable. The spam rules describe bulk, unsolicited and duplicative behaviour, and nothing on the limits page says that volume under the cap is approved.
Allowed, limited or prohibited
Use this table to sort a proposed tactic before anyone spends time on it. The status reflects our reading of the rule text cited in the last column.
| Tactic | Status | Rule text it turns on |
|---|---|---|
| Answering, by hand, fans who messaged you first | Allowed | Ordinary use of message requests on the Direct Messages help page |
| An automated, safe-for-work welcome reply to someone who wrote first, with a way to stop it | Limited: consent and opt-out required | Automation rules on automated Direct Messages |
| Auto-messaging every new follower with a link to your page | Avoid: a follow is not the opt-in X describes | Automation rules, whose example of opt-in is the person messaging you first |
| Sending one pitch to many accounts that never contacted you | Prohibited | Authenticity policy: bulk unsolicited and identical DMs |
| Mature media or profanity in a message nobody requested | Prohibited | Automation ground rules and X's unwanted sexual content rule |
| Bare link messages forming most of what the account sends | Prohibited | Authenticity policy: links shared without commentary |
| Tagging promo posts with unrelated trending hashtags | Prohibited | Authenticity policy: hashtag misuse to drive traffic |
| Joining repost rings or engagement-swap groups | Prohibited | Authenticity policy: coordinated engagement exchange |
| Mass follow-then-unfollow cycles, or following by bot | Prohibited | Authenticity policy on follow churn; best practices page on automated following |
| A second account with a genuinely different purpose, such as safe-for-work behind-the-scenes posts | Allowed within the account limit | Authenticity policy on multiple accounts |
| Extra accounts that repost the main account's promotions | Prohibited | Authenticity policy: duplicative multi-account activity |
| A scheduling tool that posts through X's API with your consent | Allowed; you stay responsible for it | Automation rules note for X users |
| Browser scripts or extensions that click and send on the website for you | Prohibited | Automation rules on non-API automation |
An opt-in DM workflow checklist
The compliant alternative to mass messaging is an inbox that fans choose to enter. The settings referred to below come from X's Direct Messages help page.
- Decide who may write to you. In the Direct Messages part of your privacy settings, choose whether to allow message requests from everyone; X says that with this on, anyone can message you and add you to group conversations.
- If you sell X Subscriptions, look at the option to allow messages from your subscribers, which the help page says is off by default.
- Invite contact in public instead of pitching in private: a pinned post or bio line saying fans are welcome to message you puts the first move with them.
- Work through requests deliberately. X keeps messages from people you don't follow in a Requests area until you accept them, and filters lower-quality requests by default in its mobile apps, so check the filtered section before assuming nobody wrote.
- Keep the first reply short and safe for work; share anything more mature only after the person has clearly asked for it.
- If an auto-reply is part of the setup, say that it is automated, include how to stop further messages, and stop the moment someone asks.
- Write to the person in front of you. Never paste the same block of text into conversation after conversation.
- Answer what was asked before sharing a link, so links never become the bulk of what the account sends.
- Keep a simple consent log: who started the conversation, what they asked for, and any request to stop.
- Review the apps connected to your X account each month and revoke any you don't recognise, using the Apps area of your settings described on X's compromised account page.
- Put these rules into the written brief for anyone else who works the inbox, including chatters and agencies.
If X is connected to your OnlyFans account, the same consent rules apply to anything sent or posted through that connection; our guide to linking X to OnlyFans explains how to review and revoke it.
When X decides an account is spamming
The automation rules name filtering your posts from search results and suspension among the actions X may take. The Authenticity policy adds the multi-account consequence: once an account is suspended, X may also suspend any other account it believes the same person or entity is operating in breach of that suspension, however long ago the other account was created. Opening a fresh account to carry on is itself a listed violation, so recovery has to go through X's appeal routes, not around them.
Before appealing, stop whatever triggered the action, disconnect tools you cannot vouch for, and write down what the account sent and when. A short, factual appeal that shows the behaviour has ended is easier to assess than a general denial. For how X compares with other networks on promotion and messaging, see our rules map for OnlyFans promotion.
Limitations of this guide
We read X's published policies; we cannot see its spam classifiers, the thresholds they use, or how an individual case was reviewed, and X does not publish those. The statuses in the table are our reading of the rule text, not a ruling from X, and a tactic marked allowed can still be actioned if it is carried out in a way that looks bulk or unsolicited. The limits page contradicts itself on posting caps, the automation rules are written chiefly for developers, and every page cited here can change without notice. Re-check the sources before you rely on any row, and get qualified advice if an account suspension affects contracts or income.