About this tool
26-point Discord privacy audit: DM filters, friend requests, server discovery, activity status, connections and 2FA, scored by risk profile.
This checklist scores a Discord account against 26 real privacy and security controls — the safe direct-messaging filter, per-server DM overrides, friend-request sources, phone and email discovery, activity status, connections, authorised apps and two-factor authentication — weighting each by how much exposure it actually closes. It gives particular weight to the two settings Discord users most often get wrong: the DM default only applies to servers you join afterwards, and every server you already joined keeps its own override. Five risk profiles re-score the same list, and five controls are marked critical and cap the score at 69% while any of them is still open.
Open Discord Privacy Settings Checklist on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
The DM override that survives the global toggle is scored as its own critical item, because it is the single most common false sense of security on Discord.
Five profiles re-weight the five exposure axes, so a teen account and a server owner are not graded against the same priorities.
The checklist runs entirely in your browser and never asks for a username, token, password or code.
Two settings, and both are needed. Turn off “Allow direct messages from server members” in User Settings > Privacy & Safety, which covers servers you join from then on, and then open each server you already belong to and switch off its own Privacy Settings > Direct Messages override. The global toggle does not retroactively change servers you already joined.
Not from a normal voice or video call — Discord routes voice through its own servers rather than connecting the two devices directly, so the other party sees Discord's address, not yours. The real leaks are screen sharing, which exposes window titles, notifications and file paths, and clicking links sent to you, where the destination site logs your address like any website would.
No. Messages belong to the channel they were posted in, so they stay visible after deletion, reattributed to a Deleted User. If you want your text gone you have to delete the messages yourself before disabling the account, and messages in servers you were removed from cannot be reached at all.
Session token theft, not password guessing. Being talked into pasting a script into the browser console — usually framed as a free Nitro offer or a giveaway bot — hands over a token that grants full account access and bypasses two-factor authentication entirely. If you have ever done it, change your password immediately, which invalidates existing tokens.