I just installed the Ultimate Bad Bot Blocker on our Mastodon server. It blocks bad bots, spam referrers, vulnerability scanners, malicious user agents, malware, adware, ransomware, and other harmful bots. It also includes anti-DDoS protection and a Fail2Ban jail for repeat offenders
https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker