Blocking Bad Actors in Novi
Use the Email Blocklist and 'Mark as Spammer' features to prevent bad actors from accessing your member data and messaging your members.
What is a Bad Actor?
A bad actor is a person rather than a site bot, who is actively attempting to access your member information. These individuals may sign themselves up beneath a member company or attempt to falsely join as a member themselves (they may even pay for membership) with the purposes of scraping directories and attendee lists for contact information.
Ways to Manage Bad Actors in Novi
While deactivating a bad actor's record may work the first time, persistent individuals may sign up again and again with variations on names. For public directories with contact forms, they may also attempt to bypass sign-up and simply begin messaging your membership. Novi has features to help fight back against bad actors.
Using the Email Blocklist
Block a specific email from being able to send communications through contact forms on your site using the Email Blocklist.
To do this, access the Email Blocklist in the gear menu:
On the Email Blocklist page, click the Add Blocked Address button in the upper right to add a new email address to the list.
Admins can add an exact email, or use an asterisk * to block all emails coming from that domain (But of course, remember that you don't want to block major email domains - such as ALL gmail addresses).
For example, tom@abcompany.com blocks just the one address, while “*@abccompany.com” blocks all email addresses with that domain.
To remove an address from the list, click Remove in the Actions column.
Important Information:
- This action blocks them from sending messages through the Contact Us page, member contact forms, and offline product contact forms.
- For extra security, users on the blocklist are not notified that they are blocked, even when attempting to send additional messages.
Using the 'Mark as Spammer' Button
Allowing a bad actor to form a false sense of accomplishment may be the best defense! When denied access, a persistent individual will simply sign up again with another malicious account.
Instead of deactivating or blocking, go to the (1) Settings tab on the record, then to the Advanced section.
Click on the (2) Mark as Spammer button.

Marking the record as a spammer will:
- Hide all member contact information from any directory, Leadership Role, or committee from this user
- Hide any visible event attendee lists from this user
- Will show a 'Success' message to the user when sending messages through the Contact Us or Member-to-Member contact forms but will NOT actually send the messages
Note: To confirm what visibility spammers have after being marked, admins are able to impersonate spammers.
Still Have Questions about Security?
Feel free to contact Novi using the blue bubble or via e-mail.