Message tags are the least glamorous part of Instagram automation and one of the fastest ways to get an account restricted. Meta removed CONFIRMED_EVENT_UPDATE on 27 April 2026, and using deprecated tags is now treated as a policy signal rather than a harmless integration bug.
If you maintain your own Graph API integration, this is a 20-minute audit worth doing today.

What tags are for (and what they are not)
By default, you can only message an Instagram user within 24 hours of their last message to you. That is the standard messaging window.
Tags are narrow exceptions to that window for specific, non-promotional purposes. They are not a general-purpose extension, and Meta is unambiguous: no tag permits promotional content outside the window.
Two things follow:
- A tag is a declaration about *why* you are messaging. Declaring falsely is the violation.
- If your reason is "I want to sell them something later," no tag covers it.
The one that matters: HUMAN_AGENT
For automation tools, HUMAN_AGENT is the tag that carries real weight. It permits a human-composed reply up to 7 days after the recipient's last message.
The intent is customer support: a real person reads the query and writes back. That is a genuinely common need — someone DMs a question at 2 AM Sunday, you answer Monday morning.
The line is bright and worth stating plainly: HUMAN_AGENT means a human wrote this message. Using it to deliver bot-generated marketing misrepresents the message to Meta. That misrepresentation is precisely what enforcement systems are built to catch.
In StackPicks AutoDM, the manual reply box in your Inbox sends with HUMAN_AGENT — because you typed it. Our AI follow-up agent does not use that tag; it operates inside the standard window where no tag is needed.
Comment-triggered DMs need no tag at all
This is the most common integration mistake we see.
If someone comments on your post and you want to DM them, you do **not** need a message tag. You need the Private Reply API, which addresses the recipient by comment_id and grants a 7-day window on its own.
Reaching for a tag to send a *first* message to a commenter means you are using the wrong endpoint.
Rule of thumb:
- First message to a commenter → Private Reply, no tag
- Reply inside 24h of their message → standard messaging, no tag
- Human reply up to 7 days after their message → HUMAN_AGENT
- Anything promotional outside 24h → not permitted, full stop

How to audit your integration
- Grep your codebase for every tag string you send
- Compare that list against Meta's current documented tags — delete anything missing
- Search your logs for HTTP 400 responses mentioning tags
- Confirm your comment-to-DM path sends no tag at all
Step 3 catches the sneaky case: a rarely-hit code path with a hardcoded deprecated tag that has been quietly failing for months.
Why this list will change again
Meta adjusts the tag set periodically, and the removal cadence has accelerated. Anything you read about message tags — including this post — should be checked against the official Messenger Platform documentation before you ship.
We date our posts and re-audit them for exactly this reason. This one is current as of 6 August 2026.
Related reading
- Instagram Private Reply API — Why Your Auto-DM Fails for Non-Followers — the correct endpoint for comment triggers
- Instagram Auto-DM Compliance 2026 — the wider allowed-vs-banned picture
- Instagram DM Limits 2026 — the other thing that silently breaks integrations