Skip to main content

Block Unverified Direct Message Invitations in Slack

How to restrict members from accepting Slack Connect direct message invitations from unverified organizations.

Written by Kavi Harshawat

Overview

Slack Connect allows members to message people in other organizations directly. By default on Pro and Business+ plans, members can accept DM invitations from any organization β€” including ones that haven't been verified by Slack. Restricting these invitations to verified organizations only reduces the risk of social engineering, phishing, and impersonation attacks from bad actors operating under fake or unvetted workspaces.

Prerequisites

  • Workspace Owner/Admin (Pro & Business+ plans) or Org Owner/Admin (Enterprise plans)

  • A paid Slack plan

  • Your organization is verified by Slack

Instructions

Pro and Business+ plans

  1. From your desktop, click Admin in the sidebar

  2. Select Workspace settings from the menu

  3. Click the Permissions tab

  4. Next to Slack Connect for direct messages, click Expand

  5. Below Allow direct message invitations from unverified organizations, uncheck Enable for Slack Connect

  6. Click Save

Enterprise plans

On Enterprise plans, this is restricted by default. To confirm the setting:

  1. From your desktop, click your organization name in the sidebar

  2. Select Tools & settings from the menu, then click Organization settings

  3. Click Slack Connect in the left sidebar, then select Settings

  4. Select the Direct Messages tab

  5. Next to Let members accept DM invitations from unverified organizations, click Edit

  6. Ensure Enable is unchecked

  7. Click Save Setting

Note: This setting only affects members' ability to accept invitations from unverified organizations β€” it does not prevent members from sending DM invitations to unverified organizations themselves.

Did this answer your question?