Back to blog

Telegram rich messages: what moderation sees in blocks, buttons and polls

Check nested text, captions, hidden URLs, buttons and edits in Defendy. Understand the separate gaps around poll content, link previews and attached files before testing your group.

A post can look like a short announcement while its useful content sits inside an expandable section, a table cell or a button. Checking the opening sentence alone leaves the administrator with the wrong picture. The practical question is which parts reach the moderation filters, and which parts still need another control.

Defendy's reviewed implementation collects ordinary text and captions, supported nested rich-message text and button destinations for moderation. Poll-specific content and a separately supplied link-preview URL are outside that extraction path. This guide explains those boundaries and a way to test them without using real spam or penalizing uninvolved members.

First identify what kind of message you are looking at

Telegram's RichMessage format stores content as blocks. A visually formatted message is not necessarily using it. Bold text or a quotation in an ordinary message can still be ordinary text with formatting information attached.

For a moderator, three cases matter:

  • Formatting inside the submitted message. A member types text and formats some of it as a quotation, spoiler or code. Those words still belong to the current message's content.
  • A structured rich message. The submitted content contains supported paragraphs, lists, tables, expandable sections or media captions. The relevant text may be several levels inside the structure.
  • A reply to somebody else's message. The client shows earlier content above the new reply. Defendy's shared extractor does not recursively copy that earlier message or its separate reply-quote field into the reply author's moderation text.

This distinction protects legitimate reporting. A member replying “Please check this” should not acquire the complete text of the offending original just because Telegram displays it as context. If they paste the offending text into their own message, it becomes their submitted content and can match a filter. Use the member-report process rather than publicly reposting harmful material.

What enters the reviewed moderation path

The extraction step assembles text and preserves link information for the existing filters. It does not make the final policy decision.

Ordinary messages: the current message's text, formatting/link entities, caption and caption entities are read. A linked phrase can carry a destination different from its visible label. The destination remains relevant even when the caption looks harmless.

Nested rich text: supported paragraphs, headings and footers are read through their formatting. List labels and contents, table cells and captions, expandable-section summaries and contents, quotations and their credits are included. Collages and slideshows are traversed for their supported blocks and captions. Hiding a section on screen does not intentionally exempt its text from this extraction.

Rich media blocks: captions associated with supported photo, video, animation, audio, voice, document and map blocks are included. Reading a document's caption does not read the document. There is no OCR, antivirus scan, image-safety classification, speech transcription or file-body inspection in this parser. Use the separate media moderation guide when deciding which attachments to permit.

Buttons: supported inline-keyboard and rich-message button labels are included in moderation content, along with explicit URL, login-URL and Web App destinations when present. A callback button's internal callback data is not read as message text. Extracting a destination also does not visit its website or certify what happens after a click.

A useful test is a single harmless marker split across plain and bold fragments inside one paragraph. The reviewed parser joins adjacent rich-text fragments without inserting an artificial space; otherwise formatting alone could change the word a filter receives. Separate blocks remain separated. That implementation detail is useful for your test plan, but it is not a promise to recognize every obfuscated word.

A quote or button label must not become an instruction

Content checks and commands have different jobs. A prohibited link in a quotation can still matter to moderation. A quotation containing /ban, however, should not be treated as an administrator asking to ban somebody.

The reviewed command handling excludes command-like material in quoted, code, button and certain generated regions. Rich command input is deliberately narrow: a supported single paragraph, rather than an arbitrary block somewhere in a larger post. This separation lets the moderation path inspect content without promoting every visible command example into an action.

For routine administration, send a plain command separately and use the command reference. Do not embed a real sanction command in a complex demonstration post to find out whether it executes. Use non-destructive examples in a dedicated test group.

A poll can contain more than a question and answer labels. Telegram documents a link attached to a poll option. That link is not an ordinary message button.

At the reviewed revision, the shared extractor does not read the poll's question, description, option text, quiz explanation, their entities or poll-media link destinations. These fields therefore do not acquire the same text/link-filter coverage merely because a poll is delivered as a message. The presence of poll data in the received update is not evidence that a filter uses it.

For a community that needs pre-publication control over every poll, arrange staff review or review Telegram's native poll-sending permission in your client. Do not advertise an unverified Defendy “poll scanner.” If polls stay open to members, put them on the manual review checklist and tell members how to report a questionable option.

There is a similar boundary around link-preview options. The extractor does not separately consume link_preview_options.url. A URL also present in ordinary text or a supported link entity can still be extracted through that route. Neither hiding a preview nor showing one establishes whether the destination is permitted. The preview's image, title and destination page are not independently inspected by this parser.

Keep these cases distinct in support requests: “URL in message text,” “URL behind a button,” “URL attached to a poll option,” and “URL supplied only for a preview” describe different inputs.

Extraction is only the first step

An extracted URL still follows your link-filter settings. A supported nested word still needs an enabled filter and a matching rule. A stop-word list and a profanity filter address different policies; neither becomes a complete content-safety system because it can receive rich text.

The normal chain can stop at an earlier matching filter. For example, a prohibited URL may cause the action before the text-spam check is reached. Record the actual reason where the moderation log provides it, rather than concluding that every later filter passed.

AI also has its own eligibility and configuration. Rich-text extraction does not establish that every message is sent to an AI model or that the model sees attachments. The ChatGPT moderation guide distinguishes a moderator's manual use of a model from Defendy's supported AI checks.

Include edited messages and sender differences

The reviewed group handlers use the shared moderation content for both new and edited messages. Test an allowed post that is later changed to contain your harmless prohibited marker. Testing only new posts misses that part of the workflow. Telegram exposes edits through a separate edited-message update, so the bot must actually receive the relevant update too.

Use an ordinary consenting member for member-policy checks. Administrator messages are marked for a moderation exemption in the reviewed path, and automatic posts from the linked channel follow a trusted analytics-only route. A successful publication by an administrator therefore cannot prove that a member filter is broken. Likewise, a test sent through another bot may have different delivery or sender conditions. Record the real sender type and consult the channel-sender guide when needed.

A controlled acceptance test

Use a separate group with disposable content. Choose a made-up marker for a temporary stop-word rule and a harmless destination under your control for URL checks. Record the saved settings first. Check deletion, warning accumulation and punishment duration: choosing “None” for a member penalty does not necessarily disable message deletion.

The following are proposed checks, not results of a live Telegram test performed for this article.

Test the location of the content, not just the message's appearance

CaseWhat to verify
Plain control and allowed control

The marker triggers the intended rule; a similar allowed sentence survives.

Nested paragraph, table or expandable section

The same marker reaches the rule inside each supported structure, including a collapsed section.

Quotation inside the submitted body

The content follows the agreed policy; a harmless command example does not execute.

Reply to the marker message

A clean reply is not treated as if it contains all of the earlier message.

Caption and button destination

Test the marker in the caption and a blocked test URL behind a benign button label separately.

Poll and preview-only URL

Record the extraction gap and your manual or native-permission fallback; do not count survival as a clean scan.

Allowed message edited later

Verify the intended action after the marker or supported URL is added.

Member and staff controls

Record sender status so an exemption is not confused with missing content.

Change one variable at a time. If a case fails, keep its message link where available, time, sender type, expected result and actual result in a restricted note. Prefer a minimal synthetic reproduction to a raw Telegram update, which can contain unrelated personal information. Remove the temporary rule and restore any affected test-account restrictions afterward.

What this review can establish

The described coverage is based on implementation review dated 7 October 2026. It is not confirmation of the version deployed in your group, a fresh live test, or a guarantee for every future Telegram format. Unsupported structures, parse limits, delivery failures and oversized messages remain reasons to avoid a blanket “everything is scanned” claim.

A workable policy names the supported content paths, gives moderators a route for the uncovered ones and verifies both unwanted and legitimate messages. Start with the beginner moderation workflow if those responsibilities are not yet assigned. Rich formatting changes where to look; your rules still determine what to do.