Most “Instagram DM limits” articles repeat numbers nobody can trace. We build DMFa.st on Meta's API, so we went to the source: every rule below links to the Meta page it comes from, and every claim says whether Meta actually states it or whether it's an inference. Rules change, so check the date at the top.
Is Instagram DM automation allowed?
Yes, through Meta's Instagram API. It's built for exactly this: businesses and creators replying to comments, Story replies and messages at scale. What Instagram does not approve is the other kind of tool, the one that logs in with your password and taps through the app like a person.
| Feature | Official API tool | Password-based bot |
|---|---|---|
| How you connect | Instagram's login screen | You type your password into it |
| Approved by MetaApp Review for apps serving other accounts | ||
| Follows Meta's messaging limits | ||
| Can message people who never engaged | It tries | |
| You can revoke access in Instagram settings |
Private replies: one per comment, within 7 days
A private reply is the DM a business sends in response to a public comment. It's what powers comment-to-DM. Meta's rules for it:
One private reply per comment
Meta says soOnly one message can be sent to the commenter
Private RepliesMust be sent within 7 days of the comment
Meta says sowithin 7 days of the creation time of the comment
Private RepliesLands in the main inbox if they follow you, Requests if they don't
Meta says soInbox, if the person follows the Instagram professional account, or to the Request folder
Private RepliesWorks on posts, Reels, Stories, Live and ads
Meta says soInstagram professional post, reel, story, Live, or ad post
Private RepliesOn Live, only while the broadcast is running
Meta says soreplies can only be sent during the live broadcast
Private RepliesAnything more needs the person to respond first
Meta says soFollow-up messages can only be sent if the recipient responds
Private Replies
Private reply
1 message
- Comment posted
The 7 days are why “re-run missed comments” features exist: comments that arrived before you switched an automation on can still get their DM, as long as they're less than a week old.
The 24-hour messaging window
Once someone messages you, Meta lets you message them back for a while. Meta calls this the standard messaging window. Its current wording: For most user actions, it lasts 24 hours.
The exception is a person who messages you from a Click-to-Direct ad, where the window may last up to 7 days from that message
.
You can message
- They tap your button (0 h)
- They message you again (30 h)
Which actions open the window? Here's what Meta's docs say, and where they go quiet:
They send you a message
Meta says soA person sends a message to your Page or Instagram Professional account
Send MessagesThey tap a call-to-action button in the conversation
Meta says soA person clicks a call-to-action button like Get Started within a conversation
Send MessagesThey tap a quick reply
Meta says sothe title of the tapped button is posted to the conversation as a message
Quick RepliesThey tap an ice breaker or reply to your Story
Strongly impliedBoth arrive as messages from the person; Meta doesn't list them separately.
They tap a link (URL) button
Not in Meta's docsA link tap opens a web page and never reaches your app, so your automation can't react to it.
After 24 hours: the Human Agent tag
Meta allows a separate 7-day window for a person on your team to answer by hand, using the HUMAN_AGENT tag. It allows a business representative to manually respond
, and it requires successful completion of the App Review process
plus business verification (Meta, Human Agent). It's for real support conversations, not automated follow-ups, and Meta's policy says message tags must never carry promotional content.
Follow checks, and why not to gate the link
Meta's user profile API has an official field, is_user_follow_business, that indicates whether the Instagram user follows your app user
. There's a condition: you can only look it up after the person has engaged in the DM.
Being able to check a follow is not the same as being allowed to require one. Meta's Spam policy is direct about this:
So use the follow check to change the tone of the message, never to withhold what was promised:
They comment the keyword
Your private reply goes out with a quick reply, like “Send me the link”.
They tap it
A quick-reply tap posts its text into the chat as a message from them. They've now messaged you, so the follow lookup is allowed.
Everyone gets the link
Followers get a thank-you with it. Everyone else gets the same link plus an invitation to follow for more. Asking is fine. Making the link depend on it is not.
Rate limits
These are Meta's published limits for accounts connected with Instagram Login:
750
private replies per hour
Per account, comments on posts and Reels
100
messages per second
Text, links, reactions and stickers
2
Conversations API calls per second
Reading inbox threads
Source: Meta's Instagram Platform overview. Accounts connected through a Facebook Page use the Messenger API for Instagram, which lists 300 messages per second (Rate Limiting). Meta also warns that it may slow you down if too many messages are sent to a single thread
.
The limit that matters for creators is the 750 private replies an hour. A Reel that pulls thousands of keyword comments builds a queue, and every comment in it has to get its DM within 7 days:
Each bar is one hour of sending at 750 private replies.
6 h 40 min
until the last DM goes out, at full speed
Yes
every comment still inside its 7-day private-reply window
Buttons and message limits
3
buttons per message
Button template: postback or web link
640
characters above buttons
Button template text
1,000
bytes per text DM
UTF-8; emoji use several bytes
13
quick replies
Up to 20 characters each
4
ice breakers
Not shown on desktop
80
characters per card title
Generic template, up to 10 cards
Sources: Meta's Button Template, Quick Replies, Ice Breakers and Messaging API pages. Cards and quick replies aren't available on Instagram for desktop, so keep the essential text in the message itself.
Note the unit on text: Meta says message text must be 1000 bytes or less
, not 1,000 characters. Plain English letters take one byte each, most emoji take four or more, and Hindi letters take three, so the same limit holds a much shorter DM in Hindi:
68bytes of 1,000
68characters
1.0bytes per character
Room for about 932 more characters like these.
Story replies and mentions
- Both reach your automation. A Story reply or a Story mention arrives as a message, so you can answer it inside the 24-hour window.
- Private accounts:
Story mentions from a private account will only flow in if the account follows
you. - Don't save their Story. Meta:
You must not store or cache the media content on your server.
- GIF and sticker replies don't trigger the Story reply webhook.
Source: Meta, Story Mention.
Consent, opt-out and disclosure
The person has to start the conversation
Meta says sothe conversation must be initiated by that person
Send MessagesOpt-outs are honoured immediately
Meta says soImmediately respect all requests ... to block, discontinue, or otherwise opt out
Developer PoliciesBots say they're bots where the law requires it
Meta says soautomated chat experiences must disclose that a person is interacting with an automated service
Messaging APIToo much negative feedback gets you limited
Meta says somay be feature limited, paused, rate-limited or removed from Platform
Developer Policies
Three myths, checked
“Instagram caps automated DMs at 200 an hour.”
Not in Meta's docsMeta's published limits are 750 private replies an hour and 100 messages a second.Overview
“Only a person's first comment on a post can trigger a DM.”
Third-party onlyMeta says one private reply per comment, and nothing about first comments. One tool vendor describes this as an Instagram limit.
“A link button tap opens the 24-hour window.”
Not in Meta's docsMeta doesn't say, and the tap never reaches your app anyway. Use a reply button to open the conversation.
What about TikTok and Threads?
- Threads: the API covers posting, reading replies and moderating them. It has no messaging endpoints, and replies are capped:
Threads profiles are limited to 1,000 replies within a 24-hour moving period
(Meta, Threads API). - TikTok: its Business Messaging API can answer people who message you first, but can't start a conversation from a comment in most regions. Third-party providers report a 48-hour reply window and no access for accounts in the EEA, Switzerland and the UK. We couldn't check TikTok's own docs for this post.
Ready to set one up? Follow our comment-to-DM guide, and pick a keyword from our list of 60.
Sources
Checked against the live pages on .
- Meta for Developers: Private Replies
- Meta for Developers: Messaging API (Instagram Login)
- Meta for Developers: Instagram Platform overview (rate limits)
- Meta for Developers: User Profile API
- Meta for Developers: Send Messages
- Meta for Developers: Rate Limiting (Messenger API for Instagram)
- Meta for Developers: Human Agent
- Meta for Developers: Story Mention
- Meta Platform Terms: Developer Policies
- Meta Transparency Center: Spam (Community Standards)
- Meta for Developers: Threads API overview
Written by the DMFa.st team. We build on Meta's official Instagram API and check every platform rule in this post against Meta's developer documentation. Spotted something out of date? Tell us.