Overview
Slack Connect allows members to message people in other organizations directly. By default on Pro and Business+ plans, members can accept DM invitations from any organization β including ones that haven't been verified by Slack. Restricting these invitations to verified organizations only reduces the risk of social engineering, phishing, and impersonation attacks from bad actors operating under fake or unvetted workspaces.
Prerequisites
Workspace Owner/Admin (Pro & Business+ plans) or Org Owner/Admin (Enterprise plans)
A paid Slack plan
Your organization is verified by Slack
Instructions
Pro and Business+ plans
From your desktop, click Admin in the sidebar
Select Workspace settings from the menu
Click the Permissions tab
Next to Slack Connect for direct messages, click Expand
Below Allow direct message invitations from unverified organizations, uncheck Enable for Slack Connect
Click Save
Enterprise plans
On Enterprise plans, this is restricted by default. To confirm the setting:
From your desktop, click your organization name in the sidebar
Select Tools & settings from the menu, then click Organization settings
Click Slack Connect in the left sidebar, then select Settings
Select the Direct Messages tab
Next to Let members accept DM invitations from unverified organizations, click Edit
Ensure Enable is unchecked
Click Save Setting
Note: This setting only affects members' ability to accept invitations from unverified organizations β it does not prevent members from sending DM invitations to unverified organizations themselves.
