14 July 2026 · BotShark Team
How to spot a bot yourself, before you ever need a tool for it
You don't need software to catch most bots — you need to know where to look. Here's the checklist we'd run through ourselves, and the honest point where doing it by eye starts to fall apart.
You click on a profile because something about a reply felt off, and now you're staring at it trying to decide: real person, or not? This is a genuinely useful skill to have on its own, no software required, and most of it comes down to nine things you can check in a couple of minutes. We'll walk through all of them, then get honest about where eyeballing a profile stops working — because it does, and knowing where that line is matters as much as the checklist itself.
None of this requires an account, a login, or anything you can't do from a profile page you're already looking at.
1. How much are they actually posting, and how fast
Open their profile and just scroll. A real person's posting pace has some kind of ceiling — work, sleep, having a life — even for someone who's genuinely very online. If you're looking at an account with tens or dozens of posts a day, sustained for weeks, or a 90-day-old account that's already pushed out several thousand posts, that's a pace that's hard to explain as one person typing on a phone. Lay checklists built for exactly this kind of manual review flag this combination — new account, huge volume — as one of the more reliable tells precisely because it's so hard to fake in the other direction (MakeUseOf, "How to Spot a Bot on Twitter").
2. Does it ever go quiet
Scroll through a few days of timestamps. Real people have a rhythm — a dip somewhere for sleep, a slower patch during a work day, a different shape on weekends. An account posting at 3am and 3pm with equal enthusiasm, every day, with no recurring gap, is behaving less like a person and more like infrastructure. Security researchers who study this for a living use exactly this signal at scale: humans have to sleep, and a script doesn't, so a sustained absence of any quiet period is one of the more dependable ways to flag automation (CHEQ, "When Traffic Never Sleeps: Detecting Bots with Entropy").
3. Check the follower-to-following ratio
This one takes about five seconds. Look at the two numbers at the top of the profile. If an account is following thirty or forty thousand people and has a few hundred followers, that's not a person who's curious about a lot of accounts — that's the mass-follow-and-hope-some-follow-back playbook, and it's one of the oldest, cheapest growth tricks around. It's also a pattern the numbers themselves give away: research modelling this exact mechanic found bot accounts running this strategy get follow-back rates around 0.76–0.86%, meaning an account following ten thousand people should organically expect roughly 80 real follow-backs, nowhere near what a lopsided ratio like this implies came from genuine interest (ResearchGate, "A Game Theoretic Analysis of the Twitter Follow-Unfollow Mechanism"). We wrote a full breakdown of this specific pattern if you want the deeper version: the follow-for-follow growth account.
4. Look at the profile itself, not just the posts
Default avatar, or a photo that looks a little too polished and stock-catalogue for a personal account. A bio that's blank, or just emoji and a link. A handle ending in a long string of random digits — a normal side effect of an account being generated in bulk rather than chosen by a person who cared what it looked like. None of these alone means much; plenty of real people have a lazy bio. It's the cluster of them together that's the actual signal, and it's exactly the kind of thing manual review checklists built by platforms and security teams lean on first, because it's the cheapest thing to check before anything else (TwitterAudit, "How to Detect Twitter Bots: A Six-Point Checklist").
5. Reverse image search the profile photo
This one's a genuinely underused two-minute check. Save the profile photo, then drop it into a reverse image search. If the same face shows up as three different names on three different platforms, or turns out to be a stock photo, an influencer's shot, or someone else's LinkedIn headshot entirely, you've got your answer. It works because most operators running an account at any real volume don't bother generating a fresh photo for every single profile — they reuse the same handful of images across a whole batch, which is exactly what a reverse search is built to catch.
6. Original words, or just other people's
Scroll the timeline again, this time paying attention to what's actually original versus what's just a repost. An account that's almost entirely retweets, with barely a sentence of its own opinion attached, isn't sharing things it found interesting — in enough volume, it's doing a very specific job: making something look more popular than it is by hitting the repost button over and over. We've written the deep-dive on this one too, including the actual retweet-to-like ratio researchers use to catch it: the retweet amplifier.
7. Read a few replies, then read a few more
If the account replies constantly, check whether the replies actually differ from each other. "Great point!", "This 100%", "Couldn't agree more 🔥" showing up under completely unrelated posts, word for word, is about as close to a smoking gun as this gets — a real person's replies vary with what they're actually reacting to, even if their vocabulary is limited. Full version: the template reply spammer.
8. Does anyone reply back
This is the flip side of point 7. An account that posts and replies constantly but gets almost nothing back — no real conversation, no one engaging with its own posts despite the volume — is broadcasting, not participating. On its own this can just mean an account hasn't found its audience yet. Combined with everything else on this list, it's a strong tell that the "conversation" only ever flows one direction.
9. Does the account's history actually add up
Check when the account was created against how it's behaving now. A profile that sat essentially silent for a year or more and then suddenly came alive with a completely different posting style, or one that's changed its actual @handle more than once, is showing a discontinuity that's hard to explain as one continuous person. Two deep-dives here if you want them: the bought or repurposed account and the recycled sockpuppet.
Where doing this by eye starts to fall apart
Here's the honest part. Every check above works on one account at a time, and that's exactly where it stops scaling. Some of the most convincing bot activity isn't about any single account behaving strangely — it's several accounts, each individually pretty unremarkable, all posting near-identical phrasing within minutes of each other. Catching that means comparing accounts against each other, not just reading one profile carefully.
There's also research suggesting we're not as good at this as we'd like to think, even on individual accounts. A study asking people to judge whether each of a set of Twitter personas was human or bot found performance was inconsistent, and heavier social media users sometimes did worse, not better, particularly when judging accounts that felt like part of their own online circle (Kenny, Fischhoff, Davis, Carley & Canfield, "Duped by Bots: Why Some are Better than Others at Detecting Fake Social Media Personas," Human Factors).
And the free, public tool that used to make some of this easier for anyone to check — Botometer, a machine-learning classifier built by researchers at Indiana University — largely stopped being usable for live lookups after X cut off free access to the data it depended on in 2023, according to reporting at the time (Botometer, Indiana University).
None of that means the checklist above isn't worth running — it genuinely catches a lot, and it costs you nothing but a couple of minutes. It just means there's a real ceiling on what one person, looking at one profile, can reliably catch alone. That's the specific gap BotShark is built to close — running every one of these checks automatically, at once, across an account's full history, and cross-referencing accounts against each other for the coordinated patterns that are basically invisible one profile at a time.
Sources: