How to Stop Contact Form Spam in 2026: Bots, Sales Pitches, and Fake Leads
Contact form spam comes in three kinds: bots, fake sign-ups, and sales pitches. Which methods stop each, from honeypots and CAPTCHAs to message screening.
To stop contact form spam, work out which kind you're getting, then match the fix to it. Most bots are stopped by honeypots, time checks, server-side validation, and rate limiting. Fake sign-ups need email checks. Sales pitches from real people get past all of those, CAPTCHAs included, and only stop when something reads the message.
This guide covers each method, which kind of spam it stops and which it doesn't, the WordPress options, and what to do with the spam that still gets through.
GoodInbound Lead Screen stops all three kinds of contact form spam. It adds one script to the form you already have and screens every submission in the background, with no CAPTCHA:
- Bots and fake sign-ups are caught from how the form was filled in, the network it came from, and the email address, with nothing for visitors to solve.
- Sales pitches from people and AI are caught by reading what the message actually asks for.
- Every submission gets a label and a reason, and nothing is deleted, so a real lead screened out by mistake is one click from your inbox.
- You only hear about the labels you choose, by email, Slack, or Telegram, and only real leads reach your CRM and ad platforms.
The free plan screens 500 submissions a month; the message check that catches sales pitches is on Pro. Start free, or read on for every method.
The three kinds of contact form spam
Almost every unwanted submission falls into one of three groups, and each needs a different fix.
- Bots. Scripts that fill in forms automatically, or skip the form and post straight to the URL it submits to. They arrive in bursts, often seconds apart, with near-identical text, random names, and links.
- Fake or throwaway sign-ups. A disposable address, someone else's email, gibberish, or a test fill like
test@test.com. Sometimes it's a bot, sometimes a person who wants your download without giving a real address. Either way, it isn't a lead. - People selling to you. SEO agencies, dev shops, link sellers, lead-gen offers, and recruiters, with real names and real company domains. More of them are now written with AI, so they mention your company by name and read like a genuine inquiry until the second paragraph.
To see which you have, open your last 20 submissions. Bursts of near-identical messages point to bots. Throwaway domains, and names that don't match the address, point to fake sign-ups. And a pitch is a pitch, however polite.
Which method stops which kind of spam
Each method covers some of the three and misses the rest. Friction is what a real visitor has to do.
| Method | Bots | Fake sign-ups | Sales pitches | Visitor friction |
|---|---|---|---|---|
| Honeypot field | Simple bots | No | No | None |
| Time check | Fast bots | No | No | None |
| reCAPTCHA v2, hCaptcha | Many | No | No | High: a checkbox, sometimes image puzzles |
| reCAPTCHA v3, Turnstile | Many | No | No | Low: usually none |
| Server-side validation and rate limiting | Direct posts and floods | Malformed entries only | No | None |
| Email checks (disposable, MX) | Some | Most throwaway addresses | No | None |
| Keyword blocklist | Repeat link spam | Some | Some, with false positives | None, until it blocks a real lead |
| Akismet, CleanTalk | Many | Some | Repeat campaigns only | None |
| Screening each submission | Most | Most | Most, when it reads the message | None |
No method here proves an email belongs to the person typing it. Only a confirmation email does that, and it's worth the extra step only where a fake sign-up costs you something, like a free trial.
Stop bots on the server: honeypots, time checks, and rate limits
Start with the checks that cost visitors nothing. A honeypot is a field hidden from people but present in the HTML: bots that fill in every field fill it in too, and your server rejects the submission. A time check rejects submissions that arrive faster than a person could type. Both stop simple bots and nothing else, since smarter bots skip hidden fields and wait, and a person writing a pitch passes both without noticing. How to stop contact form spam without a CAPTCHA covers both in detail, along with the other invisible checks.
Then make the server do the work. Browser checks like required and type="email" never run when a bot posts straight to your form's URL, so repeat them on the server:
- Reject what can't be real. Missing required fields, an invalid email, a URL in the name field, a one-word message or a 20,000-character one, and fields your form doesn't have.
- Verify every token once. CAPTCHA tokens, signed timestamps, and CSRF tokens only count if the server checks them and rejects reused ones.
- Rate limit by IP and by email. A few submissions per IP per hour is plenty for a contact form. Most CDNs and firewalls, Cloudflare's included, can rate limit a single path with no code changes.
- Don't echo the message in auto-replies. If your form emails visitors a copy of what they wrote, a spammer can enter any address and use your mail server to deliver their text.
You can't hide a form's endpoint from anyone who reads your page source, and renaming fields only buys a quiet week. What you can keep private is your email address. A mailto: link or a plain-text address gets scraped and spammed directly, with no form in the way to filter anything. Use an endpoint that keeps the address on the server, as in HTML form to email.
CAPTCHAs: what they stop and what they don't
A CAPTCHA tries to tell a person from a script before the form is accepted. Four are common on contact forms:
- reCAPTCHA v2 shows the "I'm not a robot" checkbox and adds a challenge when Google is unsure. The invisible variant only challenges the most suspicious traffic.
- reCAPTCHA v3 never shows a challenge. It returns a score from 0.0 (likely a bot) to 1.0 (likely a person), and your server decides what to do. Google suggests starting with a threshold of 0.5.
- hCaptcha works much like reCAPTCHA v2. The free plan shows challenges; the low-friction passive mode starts on Pro at $99 a month, billed yearly.
- Cloudflare Turnstile is free, with unlimited challenges and up to 20 widgets per account, and works on sites that don't use Cloudflare. Its managed mode shows a checkbox only when a visitor looks risky.
reCAPTCHA is now billed through Google Cloud, and the free tier covers 10,000 assessments a month per organization, shared across all your sites. (Prices and limits checked October 2026.)
All four share three limits:
- They only work if your server checks the token. A bot that posts straight to your endpoint never loads the widget. Cloudflare's own docs say the Turnstile widget alone doesn't protect your form.
- Some bots get through. Score-based checks miss bots that behave enough like people, and paid solving services handle visible puzzles.
- They do nothing about people. A recruiter or an SEO agency passes any CAPTCHA because they're human. That's why forms with reCAPTCHA turned on still collect pitches every day.
If reCAPTCHA is already on your form and spam still arrives, start with why reCAPTCHA isn't stopping your spam. To pick a version, see reCAPTCHA v2 vs v3. To replace it, compare Turnstile and reCAPTCHA, or see the wider list of reCAPTCHA alternatives.
Check the email address
Fake sign-ups give themselves away in the address more often than in the message. Three checks catch most of them:
- Syntax. Catches typos and keyboard mashing.
- Mail server. Look up the domain's MX records. A domain that can't receive email can't belong to a real contact. Treat a missing record as a strong signal rather than an automatic reject, because a few domains accept mail without one.
- Disposable domains. Check the domain against a list of throwaway providers. The open-source disposable-email-domains list is a common starting point, but new throwaway domains appear constantly, so a copy you made once goes stale.
A minimal mail server check in Node.js:
import { resolveMx } from "node:dns/promises";
async function hasMailServer(email) {
const domain = email.split("@").pop();
try {
const records = await resolveMx(domain);
return records.length > 0;
} catch {
return false;
}
}
To test a single address by hand, use the disposable email checker. What none of these checks catch is a real address that belongs to someone else. If a fake sign-up costs you money, send a confirmation link first.
Keyword blocklists and spam-filtering services
Keyword blocklists reject submissions containing words you choose, like "backlinks", "guest post", or any link at all. They work against repeat link spam, and they're also the most common way forms lose real leads. Block "SEO" and you block the prospect asking whether you can fix theirs. Block links and you block the visitor who pastes their own website. Pitches rarely repeat word for word, especially AI-written ones, so the list keeps growing and keeps missing. If you use one, keep it short and send matches to review instead of rejecting them.
Spam-filtering services score each submission against spam they've seen across many sites:
- Akismet, from Automattic, comes bundled with WordPress and has an API for other sites. The Personal plan is name-your-price for personal sites; commercial plans start at $9.95 a month, billed yearly, for 500 checks a month on one site.
- CleanTalk costs $12 a year for one website and has an API for sites outside WordPress.
Prices checked October 2026. Both are good at known spam: link drops, repeat campaigns, and addresses or IPs already seen spamming elsewhere. They're weaker on a polite, one-off pitch from a real agency with a clean address, because nothing about it looks like the spam those networks learned from.
Stop WordPress contact form spam
Most WordPress form plugins have spam settings built in. Turn those on before installing anything else.
- Akismet. Activate it with an API key under Settings → Akismet Anti-Spam. Contact Form 7, WPForms, Gravity Forms, Fluent Forms, and Jetpack forms can all send submissions to it.
- Contact Form 7. Under Contact → Integration, connect Cloudflare Turnstile or reCAPTCHA v3. For Akismet, add options to your form-tags, such as
[text* your-name akismet:author]and[email* your-email akismet:author_email]. Words and IPs in Settings → Discussion → Disallowed Comment Keys also block Contact Form 7 submissions, so the blocklist warning above applies. - WPForms. In the form builder, open Settings → Spam Protection and Security. Modern anti-spam protection (honeypot-based, on by default) and a minimum time to submit, 2 seconds by default, handle simple bots. WPForms also supports Akismet, reCAPTCHA, hCaptcha, Turnstile, custom question CAPTCHAs, country and keyword filters, an email allowlist and denylist, and storing spam entries instead of discarding them. Turn that last one on.
- Honeypot plugins. For forms without one built in, WP Armour inserts a honeypot with JavaScript into Contact Form 7, WPForms, Elementor forms, and others, and CF7 Apps adds a honeypot field to Contact Form 7.
Every option on that list targets bots or known spam. None of them is built to tell a sales pitch from a real inquiry. (On Google Forms, none of this is available, not even a CAPTCHA. See how to stop Google Forms spam.)
Screen every submission before it reaches you
Each method above looks at one thing. Screening looks at all of them for every submission and decides what it is. That's what GoodInbound Lead Screen does, in five checks:
- Your rules. Domains you always treat as leads, or always treat as spam.
- Behavior. Fill time, typing cadence, pastes, pointer and touch movement, automation tells, and a honeypot, collected invisibly by the script on your page.
- Network. Datacenter IPs, VPNs, proxies, Tor, and bursts from one IP.
- Identity. Email syntax, the mail server, disposable, free, and role-address lists, domain age, and gibberish.
- Context. Reads the whole message against what your business sells, and catches sales pitches, recruiting, link building, and off-topic requests.
Each submission gets a label with a one-line reason: lead, review, spam (a person selling something), junk (fake or unusable), or bot. The free plan runs the first four checks on 500 submissions a month. The message check is part of Pro, $29 a month for 2,500 screened submissions.
Setup is one script tag on the form you already have, whether it's HubSpot, Marketo, Webflow, WordPress, Framer, or plain HTML. For server-side or no-code setups there's an HTTP API, or you can use GoodInbound's own hosted forms.
Sales pitches are the kind every other method misses, so they have their own guide: how to stop sales pitches from your contact form. To see how a submission you've already received would be labeled, paste it into the free form spam checker.
Label what gets through, don't delete it
No setup is perfect in both directions. Some spam will get through, and some real leads will look like spam.
- Keep everything, sorted by label. A rule that silently drops submissions also drops the real lead it misfires on, and you never find out. In GoodInbound, screened-out submissions stay in the inbox, can be rescued in one click, and each correction teaches the screen.
- Choose what interrupts you. Get real leads and anything that needs review instantly, put pitches in a daily summary, and mute junk and bots. GoodInbound sets this per label, by email, Slack, or Telegram.
- Keep spam out of the rest of your stack. A fake lead in your CRM gets a follow-up sequence. One that fires an ad conversion tells Google Ads, Meta, or LinkedIn to find more people like it. GoodInbound only passes real leads on to your CRM, workflows, and ad platforms.
- Test after every change. Send a message from your phone and one with a link in it, and make sure both arrive.
If you'd rather not build and maintain all of this yourself, GoodInbound runs it on the form you already have. Start free with 500 screened submissions a month, or see pricing for the message check on Pro.
FAQ
Why is my contact form suddenly getting so much spam?
Usually because your form was found. It was crawled, listed somewhere, or added to a spam tool's target list, and from then on it gets posted to automatically. A sudden wave of sales pitches usually means your site landed on an outreach list. Neither stops on its own, so add the matching fix from the table above.
Does reCAPTCHA stop contact form spam?
It stops a share of bots, as long as your server verifies every token. It doesn't stop people, so sales pitches and hand-typed spam get through, along with fake sign-ups that use a real-looking address.
Can you stop contact form spam without a CAPTCHA?
Yes. A honeypot, a time check, server-side validation, and rate limiting stop most bots invisibly. Email checks handle throwaway sign-ups, and screening that reads the message handles pitches. None of it asks visitors to do anything.
Should I remove my contact form and publish my email address instead?
No. A published address gets scraped and spammed directly, and you lose everything a form tells you about how a message was sent: fill time, behavior, and the network it came from. The spam just moves to your inbox.
Is contact form spam dangerous?
Mostly it wastes time, but some of it carries phishing links, so don't click links in submissions you weren't expecting. The quieter risk is in your data: spam that reaches your CRM or counts as an ad conversion skews your reporting and your ad targeting.
Should I delete spam submissions?
Not right away. Keeping them, labeled, lets you rescue real leads a filter caught by mistake and spot patterns worth a rule. Mute them in your notifications instead, and clear them out on a schedule if storage matters.