The honest answer, first

You are new to this, you want to send a handful of connection requests a day, and you do not want to lose a profile you spent years building. The question usually gets asked in five words: is it safe or nah?

No vendor, us included, can promise you that nothing will happen to your account. Anyone who does is selling you a feeling. What the evidence supports is that behaviour and volume matter more than which tool you use, and that is not our marketing line. It is what practitioners say to each other rather than to customers.

One, on three years of campaigns: "Ran LinkedIn campaigns for 3 years without a single ban or problem. Just use the right tools, be human and don't take the piss." Another, same thread: "The bans people report usually come from aggressive volume, not the tools themselves." The other camp deserves its say: "LinkedIn automation is risky, period. We keep LinkedIn light and intentional and let email do the heavy lifting." And the mental model most people hold: "they don't detect heyreach directly, they detect automation patterns (timing, behavior, device/ip signals) at scale."

Notice what is missing from all of it: a number. Nobody cites one because there is nothing to cite. A buyer wrote the brief for this page without meaning to: "I keep seeing the same question come up in this community with no real honest answers. Just tool websites recommending themselves or affiliate posts."

Practitioner quotes collected 4 September 2026 from the Arctic Shift Reddit archive (r/coldemail, r/b2bmarketing, 9 April 2026) and two public LinkedIn threads totalling 165 comments.

What LinkedIn actually publishes

One policy matters here, and it is short. LinkedIn's prohibited software and extensions policy bans "any third party software, including 'crawlers', bots, browser plug-ins, or browser extensions that scrape, modify the appearance of, or automate activity on LinkedIn's website", and says members "risk having their accounts restricted or shut down".

Two things about it get misreported constantly. It names no tool: no approved list, no blocked list, no tier of tolerated vendors. And it carries no statistic. It says risk, not rate.

The invitation pages are just as bare. Limits "are in place to prevent misuse and promote thoughtful networking" and apply to "All LinkedIn members, including those with Basic and Premium accounts". Hit one and "your account may be temporarily restricted from sending invitations. This restriction typically lasts one week." LinkedIn names causes rather than caps: "You've sent many invitations within a short amount of time", "Many of your invitations have been ignored, left pending, or marked as spam by the recipients", and "If you send an excessive number of invitations and we suspect the use of an automation tool, we may suspend or restrict your account."

On search, the commercial use limit page is blunter: "We are not able to display the exact number of searches or views you have left and we also cannot lift the limit upon request." A separate page warns that third-party plug-ins "may run searches and view profiles in the background, which can cause you to surpass the limit without actually seeing any of the incremental warnings."

Now the finding that matters most. LinkedIn publishes no enforcement statistics of any kind, and no invitation or connection-request number anywhere. We checked its Community Report for July to December 2025, where such a number would live. It reports fake-account removals, a 99.7% proactive-detection figure for fake accounts, spam and scam content, copyright removals and government requests. Nothing on restrictions of real accounts using third-party automation, and nothing per tool.

Fetched 5 September 2026: LinkedIn Help a1341387, a550555, a551012, a564226, a526164, and LinkedIn's Community Report for July to December 2025.

So where does "20 to 25 a day" come from?

Nowhere.

We fetched four LinkedIn Help articles in full on 5 September 2026 and parsed the text rather than skimming it. The complete set of integers across all four: five personalised messages a month for Basic and free members, 30,000 first-degree connections as a network ceiling, and durations. No daily figure. No weekly figure. No monthly invitation figure.

Meanwhile every answer online lands on the same two numbers, 20 to 25 requests a day or 100 to 150 a week, and not one attaches a citation. Not the vendor blogs, not the agency guides, not the forum replies quoting the vendor blogs.

That does not make it bad advice. Twenty a day is modest, well inside what a person does by hand, and nowhere near the causes LinkedIn does name. Use it as a habit. Do not use it as a threshold, because a threshold implies a published edge, and implies that 19 is fine and 26 is not. If you want a ramp rather than a number off a blog, our invitation limit calculator treats it as a schedule.

The 40 percent figure, and how it was made

Search this topic in 2026 and you meet one sentence: roughly 40% of accounts using non-compliant automation tools were restricted in Q1 2026. It gains authority the further it travels from its origin. Here is the chain.

The origin, uncited

northlight.ai, verbatim: "LinkedIn's enforcement against automation tools got serious in Q1 2026. The number that matters: roughly 40% of accounts using non-compliant automation tools received some form of restriction between January and March 2026."

No hyperlink, no citation, no sample size, no methodology. We checked that page programmatically for the words study, survey, sample, methodology and dataset. None appears on it. The paragraph sits directly above the product pitch, and it names no tools at all.

Step one: an attribution that is not in the original

joinvalley.co, published 11 May 2026 and updated 31 August 2026, restates it as "Northlight.ai's Q1 2026 analysis quantified this pattern: roughly 40% of accounts using non-compliant automation tools ... received some form of restriction between January and March 2026", with an inserted clause, "explicitly naming HeyReach, Expandi, Dripify, and Waalaxy". Northlight names none of those four. That step turns a vague assertion into an apparent finding about specific products.

Step two: it becomes a study

anybiz.io restates it as "A first-quarter analysis by Northlight estimated...". A search engine's own AI summary then returned it to us as "A Northlight.ai study on Q1 2026 found...". In four steps, an uncited sentence became a study cited by a machine that millions of people treat as a reference.

The primary-source check

LinkedIn's Transparency Center reports fake accounts, spam and scams, content violations, copyright removals and government requests. It publishes no statistics on restrictions tied to third-party automation tools, and no per-tool enforcement rates. There is no primary source from which a 40 percent figure could be derived by anyone. A related claim on the origin page, that a 2026 transparency report showed a large rise in automated account removals, conflates fake-account removals (which LinkedIn reports) with restrictions of real accounts using automation (which it does not).

Two caveats we owe you. All four of those sites sell products competing with the tools the figure implicates, and so do we, which is why every step above is quoted rather than characterised. And on one fetch of the Northlight page we found the figure stated twice, while a second independent fetch did not find it, so the page may have been edited between our checks. Nothing structural changes: no primary source exists, so the number could not have been right at any point.

The best line in the genre comes from linkedinsider.blog, immediately before it cites its own uncited statistics: "anyone citing a precise 'X percent of accounts got banned in 2026' is almost certainly fabricating the number."

Chain and primary-source check verified 4 and 5 September 2026 by direct fetch of northlight.ai, joinvalley.co, anybiz.io, linkedinsider.blog and LinkedIn's Transparency Center.

What has actually happened, from the dockets

Court records do not care what anyone's marketing says, so we swept every federal case captioned LinkedIn Corporation v. since mid-2024 through CourtListener's RECAP archive. Since 2024, LinkedIn has sued exactly two vendors, and both are data-API companies rather than outreach automation tools.

DateCaseWhat is on the docket
24 Jan 2025LinkedIn Corp. v. Nubela Pte. Ltd., Proxycurl LLC, Steven Goh, Bach Le, No. 3:25-cv-00828 (N.D. Cal.)Six claims: breach of contract, fraud, CFAA, trademark, misappropriation
4 Jul 2025ProxycurlShut down. Founder: "there is no winning in fighting this", of a business he described as $10M revenue
25 Jul 2025LinkedIn Corp. v. NubelaJudgment entered. We read the docket entry, not the judgment document, so we state the fact and the date and no terms
2 Oct 2025LinkedIn Corp. v. ProAPIs Inc., No. 5:25-cv-08393 (N.D. Cal., reassigned from 3:25-cv-08393)Eight counts, alleging more than a million fake accounts, "hundreds if not thousands of new accounts per day", an API sold at up to $15,000 a month
9 Feb 2026LinkedIn Corp. v. ProAPIsAgreement in principle, terms undisclosed. As of 3 September 2026 no settlement, injunction or judgment has been entered

Enforcement that reaches a courtroom targets industrial-scale extraction and fake-account infrastructure, not a founder sending thirty invitations a day from their own profile. Note also that press coverage here is unreliable: two respected outlets each printed a different wrong docket number for ProAPIs, which is why we read the docket instead.

The HeyReach event, only as HeyReach stated it

This gets cited constantly as proof that automation gets people banned, so here is what is supportable, from the vendor's own two posts rather than from anyone selling an alternative. On 25 March 2026 LinkedIn removed HeyReach's company page and restricted four executive personal profiles. No notice, no stated reason. The chief executive wrote the same day that it had "zero impact" on customers or the product, and both posts state that customer accounts were never touched. HeyReach called the restrictions temporary. No evidence of mass customer suspensions, IP blocks or API action exists, from LinkedIn or anyone else. The same executive named Apollo.io and lemlist as having had company pages removed the same way, and both pages are live today, verified by direct fetch on 4 September 2026.

The architecture argument is circular

Once you accept that no enforcement data exists, the next question is which kind of tool is exposed. The category has a confident answer, and it has two of them, and they are opposites.

Published positionPublisherWhat that publisher sells
Cloud infrastructure is what exposed HeyReachnorthlight.aiA macOS app running in your own browser session, positioned against cloud proxies
Cloud infrastructure is what exposed HeyReachjoinvalley.coCloud, with a dedicated IP per LinkedIn account
Cloud infrastructure is what exposed HeyReachlinkedinsider.blogA marketing site for Reachium, which sells on an API claim and rents accounts
Cloud is safest, browser extensions are the riskcleverly.coA done-for-you agency at $397 to $997 a month that discloses no architecture at all
Cloud is safest, browser extensions are the risklinkednav.comIts own Chrome extension plus "server-side execution via headless browsers"
Cloud is safest, browser extensions are the risksyncgtm.comA LinkedIn outreach platform. We recorded the position and did not verify the architecture

Six publishers, two mutually exclusive conclusions, no data behind either. The safe architecture is always whatever the publisher sells. LinkedNav goes furthest, calling its server-side approach "much safer than simple API-side requests, which LinkedIn's security system flags almost instantly", contradicting a direct competitor in the same market on the same day.

That rule applies to us too. Leadsforlinked is a Chrome extension. Browser extensions are named explicitly in LinkedIn's prohibited software policy. We are not going to pretend that sentence excludes us.

An honest concession. Valley states on its own site that it enforces daily caps as hard limits users cannot change. We have only the vendor's word for the implementation, and its wording refers to published LinkedIn limits that do not exist. But as a design choice, taking the dial away from the user is more protective than trusting the user to be sensible, and Leadsforlinked leaves that choice to you. If you know you will get impatient, a tool that refuses to let you speed up is genuinely a better fit.

"Just use a verified-API tool" is not a thing

The most seductive advice in this category is to sidestep the argument by buying a tool that works through LinkedIn's own documented interfaces. It cannot be done, and the reason is on Microsoft's developer site.

Microsoft Learn, updated 3 June 2026, documents LinkedIn's entire developer surface as six business lines and no more: Consumer, Compliance, Learning, Marketing, Sales and Talent Solutions. Consumer is sign-in, sharing and verification. Sales Solutions is Analytics, Display and Sync Services. Compliance is described as being for "monitoring, archiving, and management of communications for enterprises in regulated industries."

No LinkedIn API that Microsoft documents sends a connection request, sends a message to another member, or performs a people search. There is no endpoint that could implement LinkedIn outreach automation. Two related facts from the same documentation set: the Sales Navigator API programme has been closed to new partners since roughly May 2025, with no waitlist and no timeline, and LinkedIn's API Terms of Use have not been updated since 13 December 2022, which deflates an entire genre of posts about 2026 developer-terms changes.

The claim is actively sold. Reachium's site, fetched 5 September 2026: "Reachium uses LinkedIn's verified API, not a Chrome extension or scraper." We are not saying Reachium misrepresents its product, because we cannot see inside it. We are saying that the platform owner's own developer documentation describes no interface that could do what that sentence describes. Check any verified-API claim against Microsoft Learn before you pay for it.

A correction we owe you. Earlier guidance published in this project repeated the compliant-API idea and used it to argue that extension architecture was uniquely exposed. That was wrong, and we found it wrong by reading the documentation rather than the competition.

Where your credentials actually live

The most direct version of the safety question is the one people ask when nobody is performing: "I am guessing its scraping using my profile creds?" It deserves a plain mechanical answer.

A browser extension does not log into LinkedIn. You do, in your own browser, exactly as you would with nothing installed. The session belongs to your browser. The extension reads pages that load in that session, which is why it can only ever see what you could see by opening those pages yourself. You never type a LinkedIn password into Leadsforlinked, and none is uploaded anywhere, because we never receive one. Your Leadsforlinked account password is a separate credential, and our privacy policy states it is hashed and never stored in plaintext. We process only publicly visible LinkedIn data from profiles, posts, events and groups, and not private messages, connections-only fields or paid LinkedIn data.

The counterpoint, honestly. A cloud tool has to hold a live LinkedIn session on its own infrastructure to act while your laptop is closed, which generally means storing a session token and acting from an IP that is not yours. An extension avoids that and takes on a different cost: it runs in your browser, and LinkedIn's own Help page warns that third-party plug-ins can consume your commercial use limit in the background without showing you the warnings. Both shapes carry something.

Our pacing, as a mechanism rather than an adjective

Human-like is not a specification, so here is what the extension does. Delays between actions are drawn from a normal distribution rather than a fixed interval, so gaps vary the way a person's do instead of repeating a signature. Page loads are separated by several seconds. Every click scrolls its target into view and pauses before clicking, rather than firing at an element the viewport never showed. On the free tier, leads are released twenty at a time every hour rather than in one burst, which is a throttle rather than a setting you can raise.

It also runs on the account you already have. No new accounts, no rented profiles, no proxy pool. That matters because the wall people hit in 2026 is account supply: "I cannot even create Linkedin accounts. Linkedin asks for a phone number, and instantly deletes the account asking for a government ID 24 hours later." One vendor sells the way around that, offering created profiles at $387 a month for three and stating in its own help centre that they are not associated to real people. We have no evidence about what happens to those accounts and will not invent any. We simply do not need them, and at low volume neither do you.

Try it on your own account, 100 free leads, no card

If you get restricted for 24 hours

This happens, it happens to people who were not being aggressive, and the panic is worse than the event. One person described a 24-hour lockout after using a Chrome extension to check emails on a handful of profiles, with no campaign running at all, and wrote that it was "halting my business". Another put it more coolly: "24-hour lockout feels less like punishment and more like LinkedIn saying, 'we noticed'."

Here is the only guidance on this with a source behind it, and it is LinkedIn's own.

  • Stop the automation. Nothing in LinkedIn's text suggests continuing helps, and its named causes are cumulative.
  • Expect to wait. An invitation restriction "typically lasts one week", and "Most restrictions will automatically be removed within one week."
  • Do not expect Support to help. LinkedIn states that it "cannot remove or shorten the wait period" and that "LinkedIn Support cannot disclose the type or reason for the restriction."
  • Withdrawing invitations does not lift it. LinkedIn says outright that "Withdrawing pending invitations will not remove the restriction". It still helps later, since ignored and pending invitations are a named cause, but after withdrawing you cannot re-invite the same person for up to three weeks.
  • Search limits run on a different clock. The commercial use limit resets at midnight PST on the first of the month, and cancelling a paid plan does not reset it.
  • For a large pending pile, allow longer. LinkedIn's recovery guidance escalates from waiting a few hours, to a few days, to "up to one month" where too many invitations are outstanding.

What you will not find here is a recovery rate, an appeal template with a success percentage, or an average restriction length. Those numbers fill this search result and none of them has a source, for the same reason the 40 percent figure has none. If a page tells you that 87 percent of appeals succeed, it made that up.

The last word belongs to a practitioner: "They own the audience. They own the data. They own the rules." A restriction is a reminder of a dependency, not a verdict on you. The people who handle it best already had a second channel, an exported list they own, and a habit of modest volume that kept them nowhere near the edge.

Frequently asked questions

Is LinkedIn automation safe or nah?

Nobody can honestly promise you that nothing will happen to your account. LinkedIn's prohibited software policy names browser extensions, bots and crawlers, says members risk having their accounts restricted or shut down, and names no tool. Its Help pages blame volume, timing and complaints rather than brands. Practitioners who run outreach for years describe the same three things: modest volume, human-looking pacing, and messages nobody reports.

What are the actual limits?

LinkedIn does not publish one. We fetched four LinkedIn Help articles in full on 5 September 2026 and parsed them. The only numbers in them are five personalised connection messages a month on a free account, a ceiling of 30,000 first-degree connections, and durations such as one week and three weeks. No daily figure and no weekly figure appears on any LinkedIn page. For search, LinkedIn says it is not able to display the exact number of searches you have left.

Is it scraping using my profile creds?

No password of yours reaches us. A browser extension runs inside the LinkedIn session you signed into yourself, in your own browser, and reads the pages that load in it. You never type a LinkedIn password into Leadsforlinked and none is uploaded anywhere. Your Leadsforlinked account password is separate, and our privacy policy states it is hashed and never stored in plaintext. We process only publicly visible LinkedIn data.

If LinkedIn can ban the vendor itself, what does that mean for my account?

Less than the retellings suggest. On 25 March 2026 LinkedIn removed HeyReach's company page and restricted four executive profiles. HeyReach's own two posts say customer accounts were untouched and call the restrictions temporary, and no evidence of mass customer suspensions, IP blocks or API action has been published by anyone. Its chief executive named Apollo.io and lemlist as having had the same done to their pages, and both are live today.

How can I avoid getting my account banned and keep using LinkedIn safely?

Work from what LinkedIn itself names as causes. It names sending many invitations within a short amount of time, invitations that sit ignored or get marked as spam, and an excessive number of invitations where an automation tool is suspected. That points at three habits: keep daily volume modest, withdraw old pending invitations so the ignored pile stops growing, and write messages specific enough that nobody reports them.

I got restricted for 24 hours, what now?

Stop the automation first, because continuing to trip the same signal is the one thing that reliably extends it. Then wait: LinkedIn says it cannot remove or shorten the wait period, that Support cannot disclose the type or reason, and that most restrictions are removed automatically within one week. Withdrawing pending invitations will not lift one already in place. Ignore any page quoting a recovery rate, because no such statistic exists.

I do not want to get my Sales Navigator subscription wasted.

Two things get confused here. A Sales Navigator seat is a subscription you buy, and a restriction is applied to your member account rather than to the seat. One detail is worth knowing: LinkedIn states that if you cancel a paid plan your commercial use limit will not be reset upon cancellation. Also check whether the tool you are buying requires Sales Navigator at all. Leadsforlinked works on standard LinkedIn search.

Is LinkedIn outreach possible at all?

Yes, on the account you already have. The people who conclude it is impossible are usually the ones whose plan needs a supply of new LinkedIn accounts, and that supply is the part that broke: LinkedIn asks a new account for a phone number and then for government identification. One vendor sells created profiles at 387 dollars a month for three, stating in its own help centre that they are not associated to real people. Leadsforlinked runs on your existing account.