How to tell if a LinkedIn automation tool is safe

You run outreach on accounts that are not yours. The tool that restricts one of them costs you the client, and the tool's own sales page will not tell you which one that is. This guide is the twelve questions to ask in the demo, the answer a safe tool gives to each, and a one-week test you can run on an account you own. It names no vendor, so you can take it to any of them, including us.

Updated September 10, 2026. Limits quoted are the ones LinkedIn enforced in 2026 and the ones our own system runs.

01 · What safe means

Three ways a tool loses you a client

Most safety pages talk about the first one only. An agency gets fired for all three.

The account gets restricted

A warning, then a temporary restriction, then a permanent one. On a client's account, the first rung is already a lost client.

A message goes out that nobody approved

The CMO of a prospect receives something the agency never read. This one has no warning ladder. It is one email from the client.

You inherit a data liability

The tool holds names, titles, messages and emails for people who never signed up. When one of them asks what you hold and why, the tool has to be able to answer.

02 · What LinkedIn sees

The warning, and what trips it

LinkedIn's notice says it detected a browser extension or third-party tool that goes against the User Agreement, and asks you to remove it. That is rung one. Rung two is a temporary restriction. Rung three is permanent. Nobody outside LinkedIn knows the exact detection rules, but the accounts that get restricted share the same three patterns.

Where the click happens

A browser extension runs inside your own LinkedIn session and leaves traces in the page. This is the trigger behind most first warnings, because it is the easiest one to detect.

Volume and rhythm

The same action every 30 seconds. A full day of invitations sent at 9:00. Two hundred profile views in an hour. Activity at 3 AM in the account's own timezone.

Network and device

A datacenter IP. Three countries in one day. A session that hops between a laptop and a server that share nothing but the cookie.

03 · The rubric

Twelve questions, and what a safe answer sounds like

Ask them in the demo, in this order. A vendor who answers with a number is telling you about the system. A vendor who answers with an adjective is telling you about the sales page.

  1. 01

    Where does the click happen?

    Safe: In a browser the tool runs on its own server, one persistent profile per account, so LinkedIn sees one device for that account and your own browser stays clean.

    Walk away: A Chrome extension. It is the cheapest thing to build and the first thing LinkedIn looks for.

  2. 02

    Whose IP address sends?

    Safe: One residential IP per account, fixed, matching the account's country. Ask whether two accounts ever share an address.

    Walk away: Your own IP for an extension, or a shared pool for a cloud tool. Shared means one bad account marks the others.

  3. 03

    What is the daily limit, and per what?

    Safe: A number per action type per account: invitations, messages, profile views, likes, comments, each with its own cap. The demo should show today's usage against each.

    Walk away: One "safe mode" toggle, or a single number for everything. A limit with no per-type breakdown cannot protect the action LinkedIn is watching.

  4. 04

    How does a new account start?

    Safe: At a fraction of the limit, growing per active day and shrinking on idle days, per action type. Ask for the starting percentage and the growth rate.

    Walk away: Full speed from day one, or a warm-up that is a checkbox with no number behind it.

  5. 05

    Is there a weekly invitation cap, and is it paced?

    Safe: A rolling seven-day cap, and a daily clamp derived from it, so the week's allowance is spread instead of spent by Tuesday.

    Walk away: A daily cap only. Seven days at the daily cap is over LinkedIn's weekly limit on most accounts.

  6. 06

    When does it send?

    Safe: Business hours in the account's own timezone, a start time that shifts every day, random gaps between actions, quieter weekends.

    Walk away: Whenever the queue has something. A schedule in UTC. Every action exactly N seconds apart.

  7. 07

    What happens on a rate limit or a security check?

    Safe: That action type stops for the day, the family of related actions pauses, and you get one notification. Replies to people who wrote in keep going.

    Walk away: Retry. A tool that retries a security check is a tool that turns a warning into a restriction.

  8. 08

    Where is the session cookie?

    Safe: Consumed once into an encrypted browser profile on the tool's server and never written to a database. Ask what a database dump would contain.

    Walk away: Stored, "encrypted at rest". Encrypted at rest still means one leak equals every client's LinkedIn session.

  9. 09

    Can a message leave without a human reading it?

    Safe: Not by default. Every AI draft waits in a review queue. Auto-send is a per-workflow choice you make, and the tool shows which workflows have it on.

    Walk away: Auto-send is the default and review is a premium feature.

  10. 10

    What stops a sequence?

    Safe: A reply, on any channel the tool controls. A booked meeting. An unsubscribe. A do-not-contact list that is checked at send time, not only at import.

    Walk away: The end of the sequence. Or a reply stops LinkedIn but the email steps in the other tool keep going.

  11. 11

    Does it count what the account does elsewhere?

    Safe: It measures the account's total activity, including your manual sends and any other tool, and lowers its own budget to fit. Few tools do this today.

    Walk away: It counts only its own sends. Two tools on one account, each under its own limit, are over the account's limit together.

  12. 12

    What happens to the data when you leave?

    Safe: Export of everything, deletion on request with a date, and a way to keep the do-not-contact memory so a person who opted out is never re-imported by mistake.

    Walk away: Cancel, and the account goes dark with your history inside it.

04 · The legal part

Four sentences on the law

Automating your own LinkedIn account is not a criminal offence in the EU, the UK or the US. It breaks LinkedIn's User Agreement, which bans bots and automated access, so the penalty is a restriction of the account, decided by LinkedIn.

The case people cite as permission, hiQ v. LinkedIn, is the opposite: hiQ won a narrow point on the US computer-fraud statute and then lost on breach of contract, ending in 2022 with an injunction and the deletion of everything it had scraped.

Meta v. Bright Data (January 2024) protected scraping of pages that are public while logged out. Every outreach tool works logged in, on your account, so that ruling does not reach it.

The data you collect about other people is governed separately, by data-protection law. Question 12 is that law showing up in the demo.

05 · The test

One account, one week

Demos show the dashboard. Only an account shows the behaviour.

  1. Day 1
    Connect one account you can afford to lose. Not a client's.
    The test is the account, not the demo.
  2. Day 1
    Open the activity log and write down every limit it shows for that account.
    If it shows none, you already have your answer.
  3. Day 2 to 5
    Run a small campaign in review mode. Approve by hand. Watch the send times.
    Timestamps tell you whether the pacing is real.
  4. Day 3
    Reply to yourself from another account and check what the sequence does.
    The reply is the stop signal that matters most.
  5. Day 5
    Log in to LinkedIn from your phone in the middle of a send window.
    You will see whether the tool keeps sending on top of you.
  6. Day 7
    Ask for a data export and a deletion of one lead, and time the answer.
    This is the question a client's lawyer will ask you later.
06 · Our own answers

The same twelve questions, asked of CampaignStack

Every number here is a limit the system enforces, not a target. One answer is a no, and it stays on this page until it changes.

Where does the click happen?
One encrypted Chrome profile per account on our server. Nothing sends from your browser.
Whose IP address sends?
One static residential IP per account, never shared, never rotated.
What is the daily limit, and per what?
Per action type: invitations at 3% of the account's connections (15 to 50 a day), messages 50 to 300 by tier, views, likes, comments, each on its own row.
How does a new account start?
Starts at 10% of the limit, gains 4 points per active day, decays on idle days, per action type. Accounts under 300 connections send nothing.
Is there a weekly invitation cap, and is it paced?
100 to 200 invitations per rolling week by tier, and today's allowance is clamped to one seventh of what is left.
When does it send?
8 AM to 6 PM in the account's timezone, start time shifted up to 30 minutes, 45 to 120 seconds between actions, sends down 70% at weekends.
What happens on a rate limit or a security check?
Three rate limits in 24 hours, or one security check, pause that action family for 24 hours. Replies keep going. One notification.
Where is the session cookie?
The cookie is consumed once into the encrypted profile and never written to the database. A regression test fails the build if a cookie column is ever added.
Can a message leave without a human reading it?
Review mode is the default. Auto-send is per workflow, and flagged drafts are held even there.
What stops a sequence?
A reply on LinkedIn or email cancels the lead's queued touches everywhere. A booked meeting does the same. Do-not-contact lists are re-checked at every send.
Does it count what the account does elsewhere?
Not yet. Today the budget counts what CampaignStack sends. Measuring the account's total activity and shrinking the budget to fit is built and in testing, and this line changes when it ships.
What happens to the data when you leave?
Lead lists export as CSV, workflows as JSON. Deletion and opt-out requests go through a public form, and a suppression register keeps the memory after the record is gone.

The full mechanics with the numbers are on the account safety page, the credential handling on the security page, and the data side on the data protection page.

Frequently asked questions

Is LinkedIn automation safe in 2026?

Safe enough to run an agency on, if the tool enforces limits per account and per action type, paces the week, warms new accounts up, sends from one residential IP per account, and never sends without review. Not safe with an extension, a shared IP pool, or a tool that retries a security check. No tool, ours included, can promise zero restrictions.

Is LinkedIn automation illegal?

No law forbids automating your own account. It breaks LinkedIn's User Agreement, so the penalty is contractual: a warning, then a restriction. The precedent people cite, hiQ v. LinkedIn, ended in 2022 with hiQ losing on breach of contract. The data you collect about other people is a separate matter, covered by data-protection law.

What does the LinkedIn automation warning look like?

A notice inside LinkedIn saying it detected a browser extension or third-party tool that goes against the User Agreement, asking you to remove it. It is the first rung. Ignore it and the next one is a temporary restriction.

Are cloud tools safer than browser extensions?

On the detection side, yes: an extension lives inside your own session and is the easiest thing for LinkedIn to see. A cloud tool moves the risk to the network, which is why question 2 matters more for cloud tools. A cloud tool on a shared IP pool is not safer than an extension.

How many tools can run on one LinkedIn account?

One. Each tool enforces its own limits and none of them can see the others, so two tools each under their own cap put the account over LinkedIn's. If you must overlap during a migration, halve both.

Get started

Start building your stack.

Your LinkedIn accounts will be safer with CampaignStack than doing it by hand. That's not a pitch. It's a measurable claim.