A thousand subscribers show up overnight. By lunchtime the new post is pulling half its usual reach, and the advertiser who booked tomorrow's slot wants to see the numbers first. You did not buy those subscribers — a competitor sent them your way, and the damage is already in your stats.
TGuard (@channel_guardian_bot) is not a separate app or a dashboard you log into — it is a Telegram bot you add as an admin to a channel, group or chat. It sits in roughly 15,000 of them doing exactly that job: keeping the wrong accounts out, clearing out the ones already inside, and showing you who your audience really is. What follows is a review of every TGuard feature — what it does, when it fires, and where it stops.
What TGuard is, and what it is not
Worth settling this first, because search results run the names together. There is no TGuard chat to sign into and no TGuard app to install — nothing gets downloaded, and there is no separate messenger involved. The whole thing is a bot account inside Telegram, @channel_guardian_bot, and you talk to it the way you talk to any other Telegram bot. The only pages outside Telegram are the analytics tables it links you to on tguard.pro, and those open from the bot with a tap.
So if you arrived here asking what the TGuard app is: it is a Telegram bot for channel and group owners, and the shortest way to see what it does is to add it to a channel you own. Reviews from people running it live in the announcements channel linked at the end.
Join limits: the first switch worth flipping
The basic protection is unglamorous. You set how many joins are allowed per time window — say a hundred people in ten minutes — and everything above that gets banned automatically. Or, if you prefer, the bot just notifies you and leaves the decision alone.
The part people get wrong is which links to count. There are two modes: all links, or the direct one only. A channel's primary invite link counts as direct, which is why named invite links are worth creating for every ad buy — a spike on one of them is then visible immediately instead of being guesswork.
A real flood is handled differently. Once more than 500 accounts pour in within half a minute, working out which of them are real is no longer worth the delay — TGuard stops the whole wave, puts everyone on the blacklist and sends you a notification. If no limits are configured at all, though, the bot treats the influx as something you allowed and sends a warning with a setup button instead of banning. It will not act on a guess.
The abuser database and the five-channel rule
Limits catch a wave. They do nothing about the five bots an hour that trickle in below the threshold. That is what the Antivirus feature is for: every arrival is checked against a database of accounts already caught inflating other channels in the network. A match gets blocked, and if the channel runs on join requests, the request is declined before it is ever approved.
How an account lands in that database is the interesting part. Every ban in every channel of the network leaves a mark. An account banned in five or more different channels is treated as an abuser unconditionally — five independent owners do not make the same mistake at once. Below five, the verdict is softer: a solved captcha clears the suspicion, because a real person who passed a check is worth more than someone else's moderation error. There is also a list of mistakenly flagged accounts, so an owner who over-cleaned can bring people back and the network learns from it.
The abuser database is the one feature that gets better the more channels use it. Everything else works identically for the first channel and the fifteen-thousandth.
The alert threshold is three unique known abusers within an hour. You then get a notification listing the invite links they came through, and if Antivirus is on, those accounts are already gone. The bot does not oversell its accuracy either — the feature description states a 1–2% error rate outright. The mechanics are unpacked in the piece on Telegram channel bot protection.
You can also check a single account by hand, with no attack in progress: /chk with an ID or username shows whether the account is flagged, how many channels banned it, and whether it has ever solved a captcha.
Captcha, and why public channels get a different one
TGuard has two kinds of captcha, and they get confused constantly.
The first is captcha on join requests. If your channel accepts members by request, the bot messages each applicant privately and asks them to confirm they are human. Fail it, or ignore it for five minutes, and the request is declined. What happens next depends on your settings: with auto-approval on, the bot admits everyone who solved it; with auto-approval off, the requests simply reach your queue pre-filtered.
The second kind is captcha for a public channel, and the logic runs backwards. A public channel is open, there are no requests, nobody to stop at the door. So TGuard issues a special invite link: people who arrive through it and pass stay, and everyone else is removed until they solve it. You pin that link in the channel or drop it into ad creatives. There is a live demo channel — @tguard_public_captcha_test. The welcome message shown after a successful check can be replaced with your own text. More detail lives in the article on Telegram captcha for channels and groups.
Worth remembering: captcha does not replace the abuser database. The attack alert has a dedicated line for the case where bots got through the captcha and were recognised anyway — that happens.
Join requests: approval, cleanup, bulk actions
Join requests are the part that stops scaling first. TGuard can approve them automatically, and auto-approval does not switch anything else off: join limits still apply, the abuser check still runs (a known bot is banned or kicked right after admission), and captcha still gates the queue.
A backlog can be cleared in one action — "Approve all" or "Decline all", with the current count on the button. Processing runs in the background and pings you when it is done. The bot holds pending requests for seven days, which is enough not to lose the ones filed while you were away.
Spam in chats and comments
Groups and discussion chats run through a separate engine that reads the message stream and matches it against the chat's rules. There are nine rules: links, message frequency, emoji-only messages, media, audio and voice notes, stickers, senders with no username, links hidden inside text markup, and known abusers. Plus your own stop-word list.
Each rule carries its own reaction: log it, delete the message, or delete and ban. A new rule only logs by default — see what it actually fires on in your chat first, tighten later. Everything is configured on a web page linked from the bot rather than through endless chat commands. There is a safety valve too: no more than twenty rule-driven actions per chat per minute, so a badly chosen stop word cannot mow down a live conversation faster than you notice.
The stop-word matching deserves a note. Spammers do not change the word, they change how it is spelled: a Latin a for a Cyrillic one, a Greek sigma standing in for the letter "o", a zero-width space inside the word. A line like пσдраδσткα дℓя κaждσгσ στ 17 лeт reads normally to a human and slips straight past a plain rule. TGuard normalises text into two spaces — one by how characters look, one by how they sound — and searches both. Swapping alphabets wholesale (kazino in Latin) stops working as well. What gets caught in practice is covered in how to stop spam in a Telegram group.
When it is your own admin removing subscribers
Not every attack comes from outside. Any bot added to a channel gets the right to remove subscribers, and that right cannot be taken away. A disgruntled admin can do the same thing, only faster.
Raid protection covers both. For admins you set a limit: how many removals are allowed in what window — ten people an hour, for instance. The eleventh removal costs that admin their rights, and you get a notification. The owner is never counted as a raider.
For this to work smoothly, admins are best appointed through the bot: TGuard generates a link, you send it to a subscriber, they follow it, and they are promoted with exactly the rights you picked in advance. Foreign bots that start removing members are ejected from the channel, and the owner gets an alert naming the culprit. The full mechanics are in Telegram anti-raid protection.
View inflation: the bot learns your normal first
Inflated views are less obvious than inflated subscribers, and "a lot of views" means nothing on its own — the post might simply have landed. So TGuard builds a profile of the channel first: across the last hundred posts it records how many views they had one hour after publication, two hours, three, and onward across a week of hourly marks.
A new post is then compared not with other channels but with your own history at that same hour of a post's life. The alert fires at 25% above normal or higher, with a floor of a hundred views. While there is too little history to go on, the bot stays quiet — you cannot build a "normal" out of two posts. Spikes on old posts, which nobody normally revisits, are tracked separately; those are almost always bought.
If you would rather skip the statistics and just name a number, you can set the threshold by hand. Then the alert arrives on the fact of crossing it, and each subsequent alert waits until the post gains that much again. Views tracking needs a second bot in the channel, @tguard_views_protector_bot. Background on the practice itself: Telegram fake views manipulation.
Subscriber scanning: the list Telegram will not give you
You cannot open a channel's member list — Telegram simply does not show it, which is where most of the "how do I see who is subscribed" questions come from. TGuard assembles the list the long way round, through member search, which hands back no more than two hundred people at a time: the bot walks through the beginnings of names — single letters and digits first, then common combinations, and wherever two hundred was not enough, it digs deeper.
Hence two modes. A fast scan can be started once a day and takes up to ten minutes, which is enough for most channels. A deep scan has no frequency cap and finds noticeably more, but it runs for hours and requires you to create your own bot through @BotFather and hand TGuard its token: Telegram caps how often any single bot may ask, and your own bot lifts that ceiling for your own channel.
There is a third scan for deleted accounts. It works off accumulated history, so the longer TGuard has been in the channel, the more it finds. On a channel where the bot was added yesterday it will surface almost nothing, and that is not a malfunction. How to read the results: how to view all Telegram channel subscribers.
Four ways to clean a channel
Cleanup is not one button but four separate tools for four different situations.
- Last N subscribers. The attack just happened: name a number and the bot removes that many most recent joins. Channels only.
- From the table. Open the web subscriber table, filter by join date, name, geography or status, and delete the selection from there. This is also how "clean a time range" works.
- Deleted accounts. A separate operation that removes every deleted profile the bot has found. Runs in the background and reports a count when finished.
- The blacklist. Wipe it entirely, or only the entries added in the last N hours — for when a cleanup caught real people.
One setting here matters more than it looks: ban or kick. By default the bot bans, meaning the account lands in the channel blacklist and cannot come back. A kick removes without the blacklist, so the account can rejoin a second later. The setting applies to every cleanup at once, manual and automatic. And once the blacklist has grown into the thousands, it is cleared in a single action — there is a whole article on that.
Analytics: joins, audience slices, engagement
Everything the bot sees about a channel is available as web tables linked from the menu. Three groups of them.
The activity log — joins and leaves with timestamps and, more usefully, the name of the invite link each person came through. That shows how many people a specific ad buy delivered and how many of them left within a week, which tells you more about the buy than the headline growth number does.
Audience slices — all subscribers, premium and non-premium separately, CIS and non-CIS separately, plus the detected bots, deleted accounts, and "dead souls" who have not been online in a long time. What each of those actually implies is covered in Telegram subscription analytics.
Easier to look at than to read about: here is a live subscriber table from our demo channel. The columns are join date, the subscriber with "premium", "bot" and "deleted" badges, gender, country, when they were last online, status, and the invite link they came through. Everything sorts and filters, and the rows you select export to Excel or get removed from the channel right there on the page.
Engagement — which posts the audience genuinely watches. It is the same stream of view measurements, shown as a per-post chart instead of an alarm. More on that in Telegram engagement analytics.
Cleanliness certificates and finding channels to advertise in
Two features that exist for money rather than for safety.
The cleanliness certificate is a short report: the channel's cleanliness percentage, subscriber count, and the number of bots, dead and deleted accounts as of the check date. Owners forward it to advertisers as proof of audience quality, ask sellers for one before buying a channel, or repost it to their own audience. It is computed from scan data, so it is worth running a scan before generating it. Related reading: fake subscriber audits.
The reverse problem is where to buy. TGuard picks candidates from the channels already under its protection, matching by topic and shared keywords, and returns 7–15 of them with member counts and verified cleanliness percentages. Next to it sits a related feature — channels with overlapping audiences — which answers a different question: not "where should I advertise" but "what else are my subscribers into". The mechanics of similar channels are covered here.
Protected giveaways belong in the same group: entrants are screened against the TGuard database, so bots and prize farmers never reach the draw.
SOS mode: five settings on one button
When an attack is happening right now, nobody wants to read a settings menu. SOS mode applies a hard preset in one tap: a limit of 10 joins per 60 seconds across all links, block instead of notify, ban instead of kick, the abuser check on, and join requests auto-approved. One more tap turns it back off.
Separate from the mode, there is a service with the same name: if the channel is under attack and touching the settings feels risky, support handles it — stops the attack, cleans up the damage carefully, and configures protection for next time. For owners who would rather never think about this, there is managed protection, where the team takes over setup and incident response entirely.
Getting started
Setup takes a couple of minutes and looks like this:
- Open @channel_guardian_bot and press Start.
- Add the bot as an admin to your channel, group or chat.
- Grant it the right to ban and remove members — enough for baseline protection. Add "add members" for captcha and join requests, and message deletion for anti-spam.
- In the bot: My channels → pick the channel → Protection settings and cleanup → set a join limit and switch the abuser check on.
The interface is available in English, Russian, Turkish, Arabic and Chinese. The features are identical across them — switching the language changes only the wording, including the captcha message your applicants see, which is shown in the channel owner's language.
If a specific feature from this overview needs more depth, most of them have their own article in the blog, and TGuard reviews and release notes live in @channel_guardian_channel.
Frequently Asked Questions
The ban comes off: the channel blacklist can be cleared entirely or only for the last N hours, so if a cleanup caught real people you can undo it in one action. An account flagged as an abuser by mistake goes onto a separate exceptions list, and the network takes that into account on later checks. To check one specific person, run /chk with their ID or username — it shows whether they are flagged and how many channels banned them. And if you need people to be able to come back on their own, switch the blocking method from ban to kick.
Ban and remove members is enough for join-rate protection and cleanups. Captcha and join requests also need the right to add members, otherwise the bot cannot approve a request after the captcha is solved. Chat anti-spam needs message deletion. The full set of rights is only required by raid protection, where the bot promotes admins through your invite link and demotes the ones who cross the removal limit.
Both, with a different feature set. Channels get join limits, the abuser database, captcha, subscription analytics and view-inflation detection. Groups and discussion chats get message-level anti-spam, captcha at the door and the same join limits. Cleaning the last N subscribers is channel-only; in a group you use selective cleanup from the subscriber table instead.