

OnlyFans Restricted Words: The 2026 List and Fixes
The categorized OnlyFans restricted words list for 2026: why flagged messages silently fail, safe substitutions, and how to train chatters around it.

Cooper Walsh
Agency Operations Lead
16 min read

TL;DR: OnlyFans filters a set of restricted words in messages, captions, and profiles, and it has never published the official list. Third-party trackers compile it by testing: the largest public version, maintained by creator-tools company Social Rise, runs to 206 terms, and every category on it maps back to the platform's Acceptable Use Policy (age references, non-consent, intoxication, violence, in-person meeting language, rival platforms, and outside payment apps). The dangerous part is the failure mode: a flagged DM often just never reaches the fan, so the pitch dies silently and nobody on your team knows a sale was lost. Treat the list as a chatter training and QA asset, not trivia: teach the categories, keep a tested substitution bank, and audit transcripts weekly.
Why OnlyFans Blocks Words: The Enforcement Ladder
OnlyFans does not filter words to annoy your chatters. It filters words because its banking relationships depend on it. The platform nearly banned explicit content entirely in August 2021 under banking pressure before reversing within days, an episode covered at the time by Newsweek, and the Acceptable Use Policy that hardened in that era is the document today's word filter enforces. In 2026 the pressure is codified in card-network programs: Visa's VAMP monitoring thresholds now sit at 0.5% for excessive dispute rates and 0.7% at the enforcement tier, replacing the more forgiving VDMP regime. A platform that lets "escort" and "meet me tonight" flow through fan DMs is inviting the exact chargebacks and processor audits those thresholds punish.
Scale explains the bluntness. OnlyFans' FY2024 filing shows 377.5 million fan accounts, 4.63 million creator accounts, and $7.22 billion in gross fan spend, run by a company reporting just 46 direct employees. Human moderators (largely contracted) exist, but the first line of defense across billions of messages is software matching strings against a list. Software does not read context, which is why "meet" can trip the filter in a sentence that has nothing to do with in-person services.
The enforcement ladder, assembled from OnlyFans' Terms of Service and the platform's observable behavior, runs in four steps:
Filter block. The message or caption is stopped or stripped at the point of posting. No strike is confirmed, but repeated attempts are the kind of pattern automated systems log.
Content removal. Something got through, then a scan or a human reviewer caught it. The post or message disappears and the account may receive a warning email with correction instructions, the typical first response for minor violations according to DMCA service Rulta's analysis of OnlyFans' suspension policies.
Account review or suspension. The account locks: no posting, no messaging, existing content may be hidden, income stops while the review runs.
Termination. OnlyFans' Terms of Service reserve the right to suspend or terminate accounts and, on termination for breach, pending payments can be forfeited. With payouts holding for roughly 21 days, a terminated account can strand three weeks of gross revenue on top of the lost page.
Every step on that ladder is more expensive than the one before it, which is why the word list belongs in your operations playbook and not in a chatter's bookmarks. The broader account-level version of this discipline is covered in our guide to avoiding an OnlyFans account ban; this post stays on the words themselves.
The 2026 Restricted Words List, by Category
First, the honest caveat every competitor page skips: there is no official OnlyFans banned words list. The counts you see published (206 words at Social Rise, roughly 100 at other trackers) are third-party compilations built by testing terms against the composer, and they drift out of date the moment OnlyFans updates its filter. What does not drift is the category structure, because the categories come straight from the Acceptable Use Policy. The policy's own operative language prohibits content that "shows, promotes, advertises or refers to" a defined set of subjects, and the word filter is simply that sentence turned into string matching.
Here is the 2026 list organized the way we train it, by category rather than alphabetically:
Age and youth terms: Example triggers: teen, young, barely legal, schoolgirl, [any age under 18], Why it is restricted: Anything that could suggest a minor is the platform's existential risk; fastest escalation of any category
Non-consent and consciousness: Example triggers: forced, kidnap, abduction, hypnosis, hypnotized, chloroform, unconscious, sleeping, Why it is restricted: AUP explicitly bars lack of consent and hypnosis; a person who cannot consent is a legal event, not a fantasy
Intoxication: Example triggers: drunk, wasted, intoxicated, high, Why it is restricted: Intoxication is a named AUP category because impaired consent is no consent
Violence and injury: Example triggers: torture, strangle, suffocate, mutilation, blood, caning, Why it is restricted: Maps to the AUP's violence and sadomasochistic-abuse language
Family terms: Example triggers: incest and explicit familial pairings used sexually, Why it is restricted: Incest is a named AUP prohibition; casual pet names generally pass, explicit family framing does not
Animal terms: Example triggers: bestiality, zoophilia, animal terms in sexual context, Why it is restricted: Named AUP prohibition
Sex work and logistics: Example triggers: escort, escorting, prostitution, hooker, meet, meet up, Why it is restricted: The AUP bars escort services, sex trafficking, and prostitution; meeting language reads as arranging paid in-person services
Bodily waste: Example triggers: urine and excrement terms, Why it is restricted: Named AUP category, driven by card-network content rules
Drugs and weapons: Example triggers: specific drug names, firearms terms, Why it is restricted: Named AUP categories
Self-harm: Example triggers: self-harm and suicide terms, Why it is restricted: Named AUP category
Rival platforms: Example triggers: Fansly, ManyVids, FansOnly, Why it is restricted: Business rule, not safety rule: no free advertising for competitors
Outside payment apps: Example triggers: PayPal, Venmo, CashApp, crypto wallet terms, Why it is restricted: Signals off-platform payment, which cuts OnlyFans out of its 20% fee and voids its compliance chain
Contact exchange: Example triggers: phone numbers, requests to move to WhatsApp or Telegram, Why it is restricted: Widely reported by creator-tools guides as flagged; off-platform contact is where trafficking and chargeback risk lives
Two operator notes. One: the filter matches strings, not intent, so "meet" can block a caption about a puppy. Two: the last three categories are commercial rules rather than safety rules, but they run on the same machinery, and the payment-app category escalates unusually fast because soliciting off-platform payment attacks the platform's revenue directly. Fans typing these words at your creators is not your problem; your team typing them back is.
Silent Failures: How to Tell a Message Was Blocked
The mechanic that costs agencies real money is not the ban. It is the block nobody notices. OnlyFans does not document its filter behavior, so here is what we and the third-party trackers consistently observe in 2026, across three failure modes:
Blocked at send. The DM refuses to go through, sometimes with a generic warning that does not name the offending word, sometimes with no explanation at all.
Silently undelivered. The message appears sent on your side but never reaches the fan. Social Rise's testing describes flagged messages being deleted rather than delivered, with no callout of which word caused it.
Delivered, then flagged. The message lands but is flagged internally for review, which is how a "successful" send can still generate a warning email days later.
Profile fields and captions fail more visibly: the field takes a red outline and an error, again without identifying the word. Messages are where the silence lives.
Now the math. A 12,000-fan mass message at a $25 pay-per-view price and a 1.5% purchase rate is worth about $4,500. If one flagged word kills it and your chatter reads the empty replies as a cold list rather than a blocked send, you did not just lose $4,500, you also taught your team a false lesson about what that list responds to. Across a 20-creator roster sending daily, a single stale script can quietly cost five figures a month.
The detection SOP we run:
Pre-send scan. Every mass message passes through a restricted-words checker (Social Rise and Enforcity both publish free ones) plus a human read, because third-party checkers lag the live filter.
Delivered-count check at 30 minutes. A mass send with a delivery or view count sitting near zero against list size is presumed blocked. Investigate before resending.
Reply-pattern check. A normally responsive fan segment going completely silent on one specific message is a blocked-send symptom, not a taste symptom.
One-strike rewrite rule. If a DM fails once, chatters rewrite the sentence. They never retry with symbols or spacing tricks, for reasons the substitutions section covers.
Report the block. Every blocked send gets logged in a ten-second form (word suspected, exact sentence, surface). That log becomes your live filter map.
Safe Substitutions: Rewriting Scripts Without Killing the Sale
The rewrite skill separates a compliant roster from a broke one, because the naive fix (delete the hot word, send a limp message) bleeds conversion. We train substitutions on one rule with two classes:
Class A: the idea is allowed, the wording is flagged. Rewrite it. Class B: the idea itself is prohibited. Kill the idea, not the word. No rewrite of a hypnosis scene or an intoxication scene makes it compliant, because the Acceptable Use Policy bans the subject, not the spelling.
Class A substitutions that preserve the sale:
"we should meet up": Script-safe rewrite: "if we were together right now...", Why it still sells: Moves logistics to fantasy; desire stays, arrangement disappears
"I'm so drunk right now": Script-safe rewrite: "I'm in such a reckless mood tonight", Why it still sells: Keeps the lowered-inhibitions energy without the intoxication claim
"I'll force you to...": Script-safe rewrite: "you won't be able to say no to this one", Why it still sells: Converts coercion into irresistibility, which is consensual and stronger copy anyway
"young girl next door": Script-safe rewrite: "girl next door", Why it still sells: The archetype carries the appeal; the age word carries the risk
"send it to my PayPal / CashApp": Script-safe rewrite: "spoil me right here so I see it instantly", Why it still sells: Redirects to on-platform tips, which also protects your revenue reporting
"I post more on Fansly": Script-safe rewrite: "everything I make lives on this page", Why it still sells: Scarcity framing beats a competitor plug
Three rules govern the bank:
No leetspeak, ever. "M33t," "dr!nk," and spaced-out letters get caught as filters update, and Social Rise explicitly warns that character substitution eventually draws penalties. Worse, when a human reviewer sees evasion patterns, intent stops being deniable. A blocked message is a hiccup; a dodged filter is evidence.
Test before rostering. New substitutions go out to a small fan segment first. If delivery and purchase rates hold, the line enters the shared bank with a date stamp.
Substitutions live inside templates, not in chatters' heads. Wire the approved bank directly into your mass-message library so the compliant version is the default version. Our breakdown of mass messaging and PPV scripts covers how to structure that library so compliance and conversion are the same document, not rival documents.
Instant Blocks vs Human Review: What Escalates
Not every term carries the same charge, and OnlyFans does not publish severity tiers, so what follows is pattern reading from observed behavior across rosters and the trackers' testing, not official doctrine. It has held steady enough to train against.
Tier 1: hard blocks. Age terms, explicit non-consent terms, and clear-cut illegal-activity strings tend to stop the composer outright. These are also the categories where repeated attempts are most likely to convert into an account-level flag, because a pattern of trying to send age-adjacent language is exactly what the platform's trust and safety function exists to catch. There is no substitution work in this tier, only removal.
Tier 2: filtered with review exposure. Context-dependent terms (meeting language, intoxication words, family terms, payment apps) sometimes block, sometimes deliver and get flagged internally. This is the tier where the delivered-then-warned pattern shows up: the send works, and 48 hours later the account gets a policy email. Tier 2 is where your substitution bank earns its keep.
Tier 3: report-driven review. Language that passes the filter can still be pulled when a fan reports a conversation or a compliance sweep reads the thread. This is the tier agencies forget: the filter is not the policy. A chatter can stay string-clean and still write a conversation that plainly arranges an in-person meeting, and a human reviewer will read it exactly as written.
What escalates an account from a blocked message to a review, in rough order of observed severity: anything age-adjacent (immediate and existential), off-platform payment solicitation (attacks the revenue model), evasion patterns (converts accident into intent), and volume (one blocked send is noise, forty a month across a roster is a signature). The suspension mechanics and the recovery process when escalation does happen are covered in the account ban avoidance guide, which pairs with this post.
Training Chatters on the List: Drills and Onboarding
Here is where most agencies get it wrong: they paste a 206-word list into the onboarding doc and consider the job done. Nobody memorizes 206 words. Everybody can internalize 13 categories. Train the categories and the enforcement ladder, and chatters start recognizing risky sentences they have never seen on any list, which is the actual goal since the list changes without notice.
Our onboarding module, which slots into the broader program from our guide to hiring and training OnlyFans chatters, runs like this:
Day one: the mechanic, not the list. New chatters learn the enforcement ladder, the silent-failure modes, and the 13 categories with three example words each, then read the substitution bank cover to cover. Under two hours total.
Red-flag drill. Thirty real (sanitized) message lines, five minutes, mark every restricted term and name its category. Pass mark is 90%. Anyone hiring from the applicant side of the market will recognize this drill from our chatter job guide; we test it in interviews for exactly this reason.
Rewrite drill. Ten flagged pitch lines, rewrite each preserving the sales intent, graded on both compliance and conversion energy. A rewrite that is compliant but limp fails the drill. This is where Class A versus Class B judgment gets built: two of the ten lines are Class B and the correct answer is refusing to rewrite them.
Canary week. For a new chatter's first week, every outbound mass message and a daily sample of DMs get reviewed by the team lead before or immediately after sending.
Monthly refresher. Fifteen minutes, whatever changed in the phrase bank that month, plus the month's most instructive blocked send.
The cultural piece matters more than the drills: blocked messages must be cheap to report and expensive to hide. A chatter who quietly retries a blocked send with punctuation tricks is manufacturing Tier 3 evidence on your creator's account. So the reporting form takes ten seconds, nobody gets punished for tripping the filter honestly, and the block log gets reviewed in the weekly team meeting as shared intelligence, not as a leaderboard of shame.
QA at Scale: Auditing Transcripts Across a Roster
One creator, one chatter, you can eyeball. Twenty creators and a three-shift chat team need a system, and the system is sampling plus metrics, run inside whatever management cadence you already operate (ours is laid out in the chatting team management guide).
The audit loop we run weekly:
Sample ten conversations per chatter per week, weighted toward highest-spend fans and newest chatters. The auditor reads for restricted terms that slipped through, near-misses, and Class B ideas creeping into otherwise clean language.
Pre-clear 100% of mass messages. DM sampling can be statistical; broadcast sends cannot, because one flagged mass message fails at list scale. Every mass send passes the checker plus a human read before it queues.
Track block rate per chatter: blocked or flagged sends divided by total sends. Investigate both tails. A high block rate means training debt. A zero block rate across hundreds of sends usually means the chatter stopped reporting, which is worse.
Maintain the phrase bank as a living document. Every confirmed trigger, every approved substitution, every date. When the log shows a previously safe word starting to block, that is your filter-change alarm going off a month before any public list updates.
Hold AI tools to the same list. If any part of your chat operation uses AI assistance, the phrase bank and the Class A/Class B rule belong in the system prompt and the output filter, verbatim. An AI drafting "let's meet" at 3 a.m. carries the same account risk as a human typing it, with less judgment behind it. The full guardrail architecture is in our AI chatting compliance rules.
The output of the loop is one page per week for the operations lead: roster block rate, new confirmed triggers, chatters flagged for refresher training, and any Tier 2 warnings received. If that page takes more than 30 minutes to compile, the logging is wrong, not the workload.
When the List Changes: Monitoring Policy Updates
The filter is a moving target and OnlyFans announces none of its updates. Words that sent cleanly in January block in March; third-party lists trail the live filter by weeks. And 2026 gives specific reasons to expect the target to keep moving: owner Leonid Radvinsky died in March 2026, and in May 2026 a 16% stake was sold to Architect Capital for $535 million, valuing the company around $3.15 billion. Ownership transitions and investor positioning historically push platforms toward tighter compliance, not looser, because clean moderation numbers are part of what gets sold.
The monitoring ritual we recommend, 30 minutes a month, owned by one named person (compliance lead or head of chatting, never "the team"):
Diff the policy documents. Keep dated copies of the Acceptable Use Policy and Terms of Service; each month, compare against the live versions and log any changed language. Policy edits precede filter edits.
Watch the trackers. The third-party lists and checkers update on their own schedules; a checker adding a category is a signal even before your own logs confirm it.
Treat your block log as the primary sensor. An unexplained block on a phrase-bank-approved line is the earliest possible detection of a filter change. That is the real reason the ten-second reporting form exists.
Push changes within 24 hours. When a change is confirmed: update the bank, notify every chatter through the channel they actually read, patch affected templates, and spot-audit the next week's transcripts for stragglers.
The agencies that handle this well are not the ones with the longest word list. They are the ones where a filter change on Monday is in every chatter's hands by Tuesday and in every template by Wednesday. That speed exists because somebody built the loop before it was needed.
FAQ
Does OnlyFans publish an official restricted words list?
No. OnlyFans has never published a banned words list; its Acceptable Use Policy defines prohibited subject categories, and the word filter enforces them. Every public list, including Social Rise's widely cited 206-term version, is a third-party compilation built by testing, so treat counts and entries as approximations that lag the live filter.
Why was my OnlyFans message not delivered?
If a DM contains a flagged term, OnlyFans may block it at send with a generic warning, or the message may simply never reach the fan with no error at all. The platform does not identify which word triggered the block. Check the sentence against the category list above, rewrite the risky term, and never retry with symbol substitutions.
Are PayPal, CashApp, Venmo, and crypto terms banned on OnlyFans?
Naming outside payment apps in messages is on every major third-party restricted list, and for good reason: OnlyFans' Terms of Service require transactions to run through the platform, where it takes its 20% fee and maintains its compliance chain. Off-platform payment solicitation is one of the faster routes from a blocked message to an account review.
Will one restricted word get an account banned?
Almost never. Enforcement is a ladder: blocked message, then content removal with a warning, then account review or suspension, then termination. But categories are not equal; age-adjacent language and evasion patterns escalate much faster than a blocked "meet up," and termination for breach can forfeit pending payouts under the Terms of Service.
Can chatters bypass the filter with misspellings like "m33t"?
Briefly, and it is the worst trade in the business. Filters get updated to catch common evasions, and a pattern of dodged filters reads as deliberate intent to any human reviewer, converting an innocent block into evidence. One failed send means rewrite the idea, never re-spell the word.
Do restricted words apply to captions, bios, and streams too?
Yes. The same categories are enforced across profile text, post captions, message text, and content itself, including spoken words in videos and streams. Captions and profile fields typically fail visibly with a red outline; messages fail silently, which is why they get the most QA attention.
How do we check a script before a mass send?
Run it through a third-party restricted-words checker, then a human read against the category table, because checkers lag the live filter. Pre-clear 100% of mass messages, verify the delivered count 30 minutes after sending, and log any block in your phrase bank so the roster learns from every failure once.
Put a full marketing department behind your agency
WhaleFinders runs the niche strategy, daily content direction, and platform playbooks for OnlyFans agencies, white-label under your brand.
Join the newsletter
Be the first to read our articles.