Short answer: yes: through the official API, on a professional account, replying to people who engaged first. The longer answer is worth five minutes, because the difference between compliant automation and the risky kind is exactly where accounts get hurt.
What Meta actually permits
Instagram's platform (the same API every legitimate tool builds on) is designed around a respond-to-engagement model:
- Professional accounts only. API-based DM automation requires a Business or Creator account, free to switch to. Meta's wording is that the platform "allows your app to access data for Instagram professional accounts including both businesses and creators" (Overview).
- Engagement opens the door. Automated messages go to people who acted first: commented, replied to a story, or sent a DM. There is no sanctioned way to cold-DM strangers at scale, and that's a feature.
- One private reply per comment. Meta's private reply mechanism lets a business send one DM in response to a specific comment: "Only one message can be sent to the commenter", and it "must be sent within 7 days" of the comment, except on Instagram Live where it has to go out during the broadcast (Private Replies).
- Links ride on interaction. Sending a promotional link generally requires the person to tap a button first, an explicit opt-in inside the thread.
- The 24-hour window. Standard messages can only be sent within 24 hours of the person's last message, the messaging window. Meta's wording: "Your app has 24 hours to respond to any message sent from an Instagram user to your app user" (Send Messages). No drip campaigns into cold threads.
Is an Instagram DM bot against the rules?
It depends entirely on which of two things the word means, and they sit on opposite sides of the line.
The kind built on Meta's official API is permitted. You connect through Instagram's own login screen, the tool never sees your password, and it replies to people who engaged first. Instagram knows it is there, because it granted the access. This is what every legitimate tool in the category is, including ours.
The kind that logs in as you is not. These automate by driving the app or the website while pretending to be you, which is why they need your password rather than an authorisation. Mass-following, mass-DMing strangers, auto-liking and follow-unfollow loops all live here. This is against Instagram's terms, and it is the kind that gets accounts actioned.
The word "bot" covers both, which is why the question has no clean yes or no, and why the honest answer to "is a DM bot allowed" is "tell me which sort you mean." We say automation rather than bot for the permitted kind, not to be delicate about it, but because the two things genuinely are not the same product and the same word for both is what keeps the confusion alive.
The one-question test: does it ask for your Instagram password? A tool operating inside the rules never needs it, because Instagram's own login hands it a scoped token instead. A tool that asks for it is the other kind, whatever it calls itself.
The rules are about consent, not about machines
The thing that surprises people is that Instagram's policy is largely indifferent to whether a human or a machine composed the message. Nothing in the permitted model turns on how fast you type.
What it turns on is whether the person on the other end opened the door. A comment, a story reply, or a DM is an act of interest, and every permission above flows from one. That is why the 24-hour window exists, why a link generally needs a tap before it can be sent, and why there is no sanctioned way to message a list of strangers no matter how carefully you write to them.
Reading it this way makes the rules much easier to hold, and it predicts the answer to most edge cases you will hit. Before asking whether a tactic is allowed, ask what the person did to invite it. If the answer is nothing, the tactic is almost certainly outside the model, and a tool that offers it anyway is telling you which kind it is.
What actually gets accounts in trouble
- Unofficial tools that ask for your Instagram password. These automate by pretending to be you in the app, against the terms, and the classic path to action against an account.
- Scraping and mass cold outreach. Messaging people who never engaged, at volume, is spam in both the policy sense and the human one.
- Purchased engagement. Fake followers and pods aren't automation, but they travel in the same gray-market circles and carry the same risk.
Worth noticing what is absent from that list: replying quickly, replying often, and replying automatically. Volume inside the model is normal, and Instagram publishes its own messaging rate limits rather than leaving you to guess where the ceiling is: "750 calls per hour per Instagram professional account for private replies to comments on Instagram posts and reels" (Overview). Trouble comes from the shape of the activity, not its speed.
A quick compliance checklist for any tool
- You connect through Instagram's own login screen (OAuth), never by typing your password into the tool.
- The tool requires a professional account.
- Automations trigger on engagement, not on lists of strangers.
- Links are delivered after a tap, never pushed cold.
- The tool talks about rate limits like they matter, because they do.
inDM is built on the official API as a Meta Tech Provider, which is the category all of this describes. But run the checklist on us and everyone else. A tool that passes it is safe to build a business on; a tool that fails it is borrowing your account's future. We ran it on the incumbent ourselves, in is ManyChat safe.
One caveat on that last point, since the badge gets over-read: being an approved Meta Tech Provider means Meta reviewed the app and granted it permissions. It is not an endorsement, a recommendation, or a guarantee about how any particular tool behaves. It tells you a tool is on the official path. The checklist is still yours to run.
Sources
The platform rules above are Meta's own, read from Instagram Platform documentation on 29 August 2026:
- Instagram Platform: Send Messages: the 24-hour window ("your app has 24 hours to respond to any message sent from an Instagram user to your app user") and the text cap ("message text must be UTF-8 and be a 1000 bytes or less").
- Instagram Platform: Send a Private Reply to a Commenter: "only one message can be sent to the commenter", and the 7-day limit on sending it.
- Instagram Platform: Overview: which account types reach the messaging API at all, and the rate ceilings, including "750 calls per hour per Instagram professional account for private replies to comments on Instagram posts and reels". Meta's own page carried "Updated: Jun 30, 2026" when we read it.
What's ours and what isn't. Nothing on this page is an inDM measurement. These are Meta's published rules, quoted with the date we read them. Meta changes them without notice, so treat that date as an expiry stamp rather than a guarantee, and open the primary sources before relying on a rule for something that matters.
Meta's rules aren't the only rules
Everything above is Instagram's policy, what the platform permits. Data-protection law is a separate question with a separate answer, and the two are often confused. The short version is that Instagram's engagement-first model collects most of the consent for you, and the obligations you take on yourself start when data leaves the platform: do you need consent to send automated Instagram DMs.