Guides / How to build

How to Build a Forum: Categories, Threads, Search and Spam Control

How to build a discussion forum: categories, threads, search, accepted answers, SEO-friendly thread pages, and the spam and moderation tools you need.

Mythex Team · 2026-09-29 · 6 min read

A forum is a set of categories, threads inside them and replies inside those, plus accounts, search and moderation. It differs from a chat group because conversations are organised by topic and stay useful for years — someone can find a three-year-old thread through search and still get their answer. To build one, get the thread page and search right, make threads readable by search engines if the forum is public, and have spam and moderation tools ready before the first real member signs up.

What a forum needs

Pages

  • Category list — the front page for most forums, with each category's description and latest activity.
  • Thread list — threads in a category, sorted by latest reply, with reply counts and a marker for solved or pinned threads.
  • Thread page — the first post and all replies in order, with quoting, reactions and a reply box.
  • New thread form — title, category, body, optional tags.
  • Search — across titles and post text, with filters by category.
  • User profile — name, avatar, join date, post count, recent posts.
  • Moderation queue — reported posts and posts waiting for approval.

Data

TableKey fields
Usersname, avatar, role, trust level, join date, status
Categoriesname, slug, description, sort order, who can post
Threadstitle, slug, category, author, pinned, locked, solved, last reply time
Poststhread, author, body, created, edited, hidden
Reactionspost, user, type
Reportspost, reporter, reason, status, moderator's decision
Subscriptionsuser, thread (to notify on new replies)

Storing "last reply time" and "reply count" on the thread itself keeps the thread list fast, instead of counting posts every time the page loads.

Permissions

  • Guests can read public categories.
  • Members can post and reply, and edit their own posts for a limited time.
  • Moderators can hide, move, lock, pin and merge threads, and suspend users.
  • Admins manage categories and roles.

A private category must be checked on the server on every request — the thread page, search results, RSS and notifications all need the same check, or private posts leak through a side door. See how to add role-based access control.

Decisions and trade-offs

Flat or nested replies. Flat threads (replies in time order, with quoting) are easier to read and the standard for most forums. Nested replies (Reddit-style trees) suit debate but get hard to follow on phones. Pick flat unless you have a reason not to.

Q&A mode. For support and help forums, let the person who asked mark one reply as the accepted answer, and show it right under the question. This single feature makes old threads far more useful.

Public for SEO, or private. Public thread pages can bring steady search traffic, but only if search engines can read them. That means each thread has its own clean URL, a real <title>, and the posts in the HTML rather than loaded later by JavaScript. Ask for server-rendered or pre-rendered thread pages if search traffic matters. More in SEO for AI-built websites.

Rich text or Markdown. Markdown with a preview is easy to store safely. A visual editor is friendlier for non-technical members. Either way, clean the HTML before displaying it, so nobody can inject scripts into a post.

Search. Postgres full-text search is plenty for a forum's first years. A dedicated search service only becomes worth it at large scale. See how to add search to your app.

Spam and moderation, before launch

Forums attract automated spam faster than almost any other kind of site, because each post is a public page that can carry a link. Plan for it from the start:

  1. Trust levels. New accounts can't post links or images, and their first two or three posts wait for approval. After that, they post freely.
  2. Rate limits. A cap on posts per minute and per day for new accounts.
  3. Email verification before posting.
  4. Report button on every post, feeding a moderation queue.
  5. Nofollow on user links, so spammers gain nothing from search engines.
  6. A moderation log, so moderators can see who did what and why.
  7. Clear rules pinned in every category.

Example first prompt

Build a public Q&A forum for home espresso enthusiasts. Categories: Machines, Grinders, Technique, Beans, Buy and Sell. Anyone can read; members sign up with email and password and verify their email before posting. Thread pages at /t/[slug] must be server-rendered with a unique title and meta description so search engines can read them. Replies are flat, in time order, with quoting and a thumbs-up reaction. The person who started a thread can mark one reply as the accepted answer, shown under the question. New members' first three posts wait for moderator approval, and they can't post links until approved. Moderators can hide, lock, pin and move threads, see a queue of reported posts, and every action is logged. Add search across titles and posts with a category filter, and in-app notifications for new replies to threads I follow. Store everything in a database.

Build steps

  1. Thread page first. Seed a few categories and fifty realistic threads. Get reading, quoting and replying right on a phone.
  2. Category and thread lists. Sorting by latest activity, pinned threads at the top, solved markers.
  3. Accounts and verification. See how to add login to your app.
  4. Moderation and trust levels. Approval queue, reports, hide, lock, move, log. Test as a brand-new account trying to post a link.
  5. Search. Try searches your members would really type.
  6. SEO. Publish, open a thread, view the page source and check the posts are in the HTML. Add a sitemap of threads.
  7. Seed real content. Write the first twenty useful threads yourself, or invite a few experts to. An empty forum doesn't get its first post.

Common mistakes

  • Launching empty. Nobody wants to post first. Seed real questions and answers.
  • Too many categories. Five busy categories beat twenty quiet ones. Split later.
  • No approval for new accounts. Spam bots find new forums quickly.
  • Unsanitised post HTML. A script inside a post can take over other users' sessions. Always clean user content.
  • Private categories that leak. Check search results and notifications, not just the thread page.
  • Counting replies on every page load. Store counts on the thread and update them when posts change.
  • No way to delete an account. Decide what happens to a departing member's posts.

When forum software is the better choice

Open-source and hosted forum software, such as Discourse, has had years to refine trust levels, anti-spam, email integration, moderation and mobile layouts. If you want a general-purpose forum and don't need it to be part of another app, installing or subscribing to one of these is usually quicker and safer than building. Chat tools suit fast conversation but are poor at keeping answers findable.

Build your own when the forum is part of your product — a support forum inside your SaaS, a Q&A section on a marketplace — when you need custom data attached to threads (the machine model, the order, the course lesson), or when you want the forum's design and URLs to be fully yours. For a broader members' space with profiles and events, see how to build a community platform.

Building it with Mythex

In Mythex you describe the forum in chat, try it in the live preview, and publish it to a public address, with a custom domain on the Pro plan. Mythex adds a dedicated Postgres database for users, threads and posts when the app needs it, and file storage for avatars and images. The default stack is a browser-rendered Vite and React app, so for a public forum ask for server-rendered thread pages (Next.js is an option) and follow the SEO recipe. Member login and email are bring-your-own: pick an approach and a provider, store keys as project secrets, and the agent wires them in. Use /test to have the agent click through posting and moderation before you publish, and read our security checklist for AI-built apps before you open sign-ups.

Questions

What does a forum website need?

Categories, threads with replies, user accounts, search, and moderation tools. Most forums also need notifications for replies, a way to mark the best answer in Q&A threads, and spam protection for new accounts.

Should a forum be public or private?

A public forum can bring in search traffic, because each thread is a page people find on Google. A private forum is better for sensitive topics or paying members. Many forums keep reading public and require an account only to post.

How do I stop spam on a forum?

Limit what new accounts can do: hold their first posts for approval, block links until they have been active a while, rate-limit posting, and give members a report button. Verify email addresses at sign-up and log moderator actions.

Is it better to use forum software like Discourse?

If you need a full-featured forum quickly, established forum software is the safer choice: it has years of moderation and anti-spam features. Build your own when the forum is part of a larger app or needs data and workflows that general forum software doesn't have.

Keep reading

  • How to Add Role-Based Access Control (RBAC) to Your App — Add roles and permissions to your app safely: pick a model, store roles, check them on the server for every request, and test that users can't see others' data.
  • How to Add Search to Your App: From Simple Filters to Full-Text Search — How to add search to your app: simple filters, database full-text search, or a hosted search engine — which to pick, prompts to use, and mistakes to avoid.
  • How to Build a Blog with AI: Posts, Editor, SEO and Hosting — Build your own blog with an AI app builder: posts, an editor, categories, newsletter signup and SEO search engines can read, plus when a platform fits better.
  • How to Build a Booking App: Slots, Availability, Reminders and Deposits — How to build a booking app with AI: services, availability and time slots, double-booking rules, time zones, reminders, deposits, and when Calendly is enough.
  • How to Build a Budget App: Categories, Transactions, Imports and Reports — Build a personal or household budget app: budgeting methods, transactions, CSV imports vs bank connections, handling money correctly, and privacy.
  • How to Build a Changelog Page: Entries, Tags, RSS and 'What's New' — How to build a product changelog page: what each entry needs, files vs database, tags, RSS, email updates, an in-app 'what's new' badge, and writing tips.

Start building free · Templates · Docs