WhatsApp API guide

How to avoid bans on the WhatsApp API

On the WhatsApp API, a ban is almost always a consequence of behavior: messages to people who didn't ask for them, volume that grows too fast and content that gets reported. With consent, number warm-up and gradual sending, the risk drops a lot. No serious provider promises zero risk.

By D-API engineering team5 min read

Why numbers get banned

WhatsApp doesn't publish the exact rules, but the signals that matter are well known to anyone who has operated numbers for a while. They all have to do with the recipient's experience:

  • Reports and blocks. Every time someone taps "report" or blocks the contact, the number loses reputation. A few reports in a short period are enough for a restriction.
  • Messages with no replies. A number that only sends and almost never gets a reply looks like spam, even if the content is legitimate.
  • Sudden growth. A number that talked to ten people yesterday and sends to five thousand today draws attention.
  • Machine-like patterns. Same text, same interval, in sequence to contacts who don't have the number saved.

This applies to any WhatsApp API, official or not. On the unofficial API, control is entirely yours; on the official API, Meta measures the number's quality and limits sending when it drops.

Sending best practices

Consent comes first

Only send to people who asked, and record how they asked: a checkbox at sign-up, a click on a "chat on WhatsApp" button, a request made in store. A purchased list or one scraped from groups is the shortest path to a ban. Store the date and source of consent with the contact in your database; it also helps you answer the customer who asks why they got a message.

Warming up a new number

A freshly activated number has no history. In the first weeks, use it the way a person would: conversations with contacts who reply, a few groups, messages received and sent. Only then start automating, and start with the most engaged contacts.

Gradual volume and intervals

Increase daily volume little by little and spread sends throughout the day, with varying intervals between messages. If your case requires messaging many contacts, split them across numbers and respect each one's pace. On D-API, the /api/v1/limits/{sessionId} endpoint returns the account's message quotas and restrictions, which helps you calibrate the pace:

curl https://api.d-api.cloud/api/v1/limits/sales-01 \
  -H "Authorization: YOUR_API_KEY"

Content people want to receive

Personalize with the name and the contact's real context (the order, the appointment, the invoice). Avoid unknown shortened links, all-caps text and the exact same message to thousands of people. A message the person was expecting rarely gets reported.

Reply, and let people opt out

Handle replies: a number that has conversations has a better reputation than one that only broadcasts. Process the incoming-message webhook and route it to an agent or a bot. And offer a clear way out, such as "reply STOP to unsubscribe", removing the contact from the list immediately.

Checklist before automating a number

  • Every contact on the list gave consent, and the source is recorded.
  • The number has at least a few weeks of real use, with two-way conversations.
  • The profile name, photo and description identify the business.
  • Day-one volume is small and there's a weekly growth plan.
  • Sends have varying intervals and stay within business hours.
  • Each message is personalized and has a clear reason for that contact.
  • There's an opt-out, and the request is honored immediately.
  • Replies reach your system via webhook and someone or something responds.
  • Your system tracks the connection status and stops sending if the number drops.
  • There's a plan for when a number gets restricted: who tells whom and what stops.

The role of infrastructure

Good practices reduce the chance of a ban. Infrastructure reduces the size of the problem when it happens, and keeps network issues from looking like suspicious behavior.

  • Dedicated IP per connection. Dozens of numbers going out from the same address form a pattern that doesn't look like real usage. On D-API, each connection gets a dedicated proxy with a unique IP, managed by the platform.
  • Per-instance isolation. Each connection runs in its own environment, with its own credentials and webhook. If one customer's number gets banned, the other customers' numbers keep working.
  • Stable reconnection. Connections that keep dropping and coming back generate repeated pairings. Auto-reconnect keeps the session up without anyone having to scan a QR code again at every blip.

This matters mostly for anyone operating many numbers for different customers, like a SaaS or an agency. How to organize that operation is covered in WhatsApp API with multiple numbers.

When broadcasting is the goal

If your case is communicating with a large base, consider the official API for the part that starts conversations, and the unofficial API for the support that follows. The comparison is in official vs unofficial API. For high-volume campaigns, the bulk messaging API page shows how to structure sending without burning numbers, and the D-API unofficial WhatsApp API explains the infrastructure behind each connection.

Frequently asked questions

Can I guarantee a number will never be banned?
No. WhatsApp decides on bans, using criteria that aren't public. What's within your reach is greatly reducing the chance, with consent, gradual volume and content people want to receive, and limiting the damage if it happens.
How long does it take to warm up a new number?
There's no official timeline. A practical reference is a few weeks of usage similar to a person's: back-and-forth conversations, few new contacts per day, gradual growth. Rushing this phase is the most common cause of bans on new numbers.
Does using the official API eliminate the risk of bans?
It reduces it, but doesn't eliminate it. On the official API, Meta tracks the number's quality based on blocks and reports, and may limit sending or restrict the account when quality drops. Consent and relevance still apply.
Does a banned number affect the others on the same account?
It depends on the infrastructure. If all numbers go out from the same server and the same IP, a problem can spill over to the others. On D-API, each connection runs isolated with its own IP precisely to prevent that domino effect.
What should I do when a number gets banned?
Stop automated sends from that number, review what was sent in the last few hours and to whom, and use the review request in the app itself. Before putting another number in its place, fix the cause, or the new number will go the same way.

Try D-API's WhatsApp API

3-day trial with full access. No credit card, no lock-in.