LinkedIn does not restrict accounts for using automation. It restricts accounts for behaving like automation: mechanical timing, volume that ignores acceptance, and activity that keeps running when the signals say stop. The tool is invisible to the platform. The pattern is not.
That distinction matters, because most advice about staying safe is really advice about hiding a tool, and hiding a tool has not been the relevant problem since roughly 2021.
Detection moved from tools to behavior
The early enforcement era was technical. LinkedIn looked for browser extensions injecting into the page, for known automation signatures, for requests that did not come from a real session. The counter-play was cloud tools with dedicated addresses, and for a while it worked.
Enforcement now leans behavioral. The signals that matter are the ones a real human would not produce:
- Metronomic timing. Actions spaced at suspiciously even intervals, or a day that starts at exactly the same minute every morning.
- Around-the-clock activity. Sends at 3am local time, seven days a week, with no gaps.
- Volume decoupled from outcome. Invitation counts holding steady while acceptance rate falls through the floor.
- "I don't know this person" reports. The cheapest, strongest negative signal a recipient can send, and the one that compounds fastest.
- Identical copy at scale. The same message with a swapped first name, hundreds of times, is trivially clusterable.
- A brand-new account at full speed. Age is the largest multiplier on every other signal.
There is also a vendor-level tier that individual operators cannot control: LinkedIn has taken action against automation vendors' own presence on the platform, including deleting a well-known vendor's company page in March 2026. That is a reason to care which vendor you attach your seat to, but it is not a signal about your account.
What a restriction actually looks like
These tiers are commonly reported by operators. LinkedIn does not publish a formal ladder.
| Tier | What you see | Typical trigger | Recovery |
|---|---|---|---|
| Warning | Notice that activity looks automated | Early pattern detection | Stop, reduce pace, no lasting damage |
| Invitation restriction | Cannot send invites, rest of the account works | Low acceptance, high "I don't know this person" | Days to weeks, then restart the ramp |
| Temporary account restriction | Account locked, often an identity check | Sustained pattern, or a spike after a warning | Verification plus a waiting period |
| Permanent restriction | Account closed | Repeat offences, or severe single incident | Appeal, with a narrow success path |
The important read on that table: the cheap tiers arrive first and are survivable. Almost nobody goes from healthy to permanently closed without passing signals they chose to ignore.
The controls that actually reduce risk
Ranked by how much they matter in practice, not by how often vendors advertise them.
- Targeting. A list where the person has a genuine reason to accept is the whole ballgame. Acceptance rate is both the outcome you want and the signal that protects you. Across our own history of 861 conversations we ran a 41% acceptance rate, and it was targeting, not copy, that moved it.
- Enforced caps rather than typed ones. A limit field you can overwrite is a suggestion. The number has to live somewhere you cannot reach in a hurry.
- Warm-up ramps on new seats. Start low, climb only as acceptance holds. A ramp planner gives you the week-by-week.
- Working-hour pacing with real jitter. Human hours, human gaps, varied intervals, no weekend marathons.
- An acceptance-rate kill switch. Something that stops sending when the rate falls, rather than after a human notices next Tuesday.
- Suppression memory. Never re-invite someone you have already contacted. Importing your old exports on day one is the cheapest way to build this.
- One company, one seat, per week. Three people at the same company hearing from three of your seats in a week is a report waiting to happen.
What we publish, and what we will not
Several vendors advertise a ban rate. The claims are almost never accompanied by a methodology, a denominator, or a date.
We measure restrictions per managed seat per rolling 90 days and publish the result live on the safety page rather than in a marketing line. At the time of writing that number is still in its measuring window, because the honest thing to do with a metric that needs a denominator is to wait until you have one. We would rather show "measuring" than a number we cannot defend.
If you want an estimate of your own exposure before changing anything, the ban-risk score is eight questions and gives you a blunt verdict.
Running outreach that does not produce the pattern
The structural fix is to stop having a human decide, in the moment, whether to push past the limit.
LinkedBoost is a LinkedIn MCP server. You connect it to Claude, and the agent handles sourcing, drafting, sending, and the inbox, while the server holds the constraints:
- Daily and weekly caps enforced server-side. New seats start at 20 invitations a day and 80 a week.
- Warm-up ramps that advance on acceptance, not on the calendar.
- Every visible action passes an approval gate. Creating a sequence sends nothing; enrollment queues.
- Replies stop follow-ups immediately.
- Suppression built from your own imported history, so nobody gets a duplicate invite.
You can ask the agent for the state directly:
"What is my pacing headroom on each seat, and has acceptance dropped on any sequence this week?"
It answers from the seat, not from a settings page. Connect it to Claude and the enforcement is on from the first send.
Questions people actually ask
Can LinkedIn detect automation tools?
It can detect some directly, particularly browser extensions that modify the page. More importantly it detects behavior: mechanical timing, around-the-clock activity, volume that ignores falling acceptance, and copy that clusters. The behavioral layer is what restricts accounts in 2026.
Will I get banned for using a LinkedIn automation tool?
Not automatically. Accounts get restricted for patterns, not for tool names. Realistic risk comes from pace on a young account, weak targeting that collapses acceptance rate, and ignoring the first warning.
How long does a LinkedIn restriction last?
An invitation restriction commonly clears in days to a few weeks. A temporary account restriction usually requires identity verification plus a waiting period. Permanent restrictions require an appeal, and the success path is narrow.
What is a safe number of LinkedIn invitations per day?
There is no published safe number. LinkedIn documents roughly 100 invitations per week and nothing daily. We enforce 20 per day and 80 per week on new seats, and treat acceptance rate rather than volume as the real constraint. See the connection request limit guide.
Does a dedicated IP address prevent a ban?
It removes one old technical signal and does nothing about the behavioral ones. A dedicated address running mechanical timing at high volume on a young account is still a restricted account.