All articles

How to Stop Google Forms Spam: 7 Ways to Block Bots and Fake Responses

October 10, 2026·By GoodInbound team

Google Forms has no CAPTCHA or spam filter. Seven ways to stop spam responses, from built-in settings and validation rules to screening every response before it reaches you.

Google Forms has no CAPTCHA and no spam filter. Anyone with the link can submit, and so can any script or browser extension, which is why public forms fill up with junk rows, fake sign-ups, and sales pitches. You can't add reCAPTCHA to a Google Form, but you can make spam harder to send, stop it once it's sent, and keep it from reaching you.

The first four fixes below use only Google Forms settings. The rest cover what to do when spam gets through anyway.

Why Google Forms gets so much spam

Three things make Google Forms an easy target:

  1. The link is public. A form shared on a website, a social post, or a QR code gets picked up by scrapers within days.
  2. Submitting is trivial to automate. Browser extensions like Borang advertise filling and submitting Google Forms automatically, with random answers, on a schedule. Simple scripts can post responses without even opening the page.
  3. There's no check on what's written. A response is accepted as long as required questions are answered in the right format. A sales pitch or a fake sign-up passes just like a real reply.

1. Limit to one response per person

In the form, open Settings → Responses and turn on Limit to 1 response. Respondents now have to sign in with a Google account, and each account can submit once.

This is the strongest built-in fix. Extension and script tools can't easily get past a required sign-in, so automated spam mostly stops.

The trade-off is friction. People without a Google account, or who don't want to sign in to answer a contact form, will leave. It suits internal surveys and event sign-ups better than public lead forms. If everyone answering is in your company, Restrict to users in your organization does the same job with no extra friction.

2. Add a question bots get wrong

Add a required Short answer question such as "What is 4 + 4?". Open its ⋮ menu, choose Response validation, set it to Number → Equal to → 8, and add an error message.

It stops scripts that fill every field with random text. It won't stop tools that let the spammer set answers, or a person typing spam by hand, so treat it as a speed bump.

3. Validate email answers

For an email question, use Response validation → Text → Email so malformed addresses are rejected. Better still, under Settings → Responses, set Collect email addresses to Verified. Google then records the signed-in respondent's address instead of trusting what they type.

Verified addresses require sign-in, so this has the same trade-off as fix 1. Format validation alone doesn't catch disposable inboxes or someone using another person's real address.

A lot of Google Forms spam is links: SEO offers, phishing pages, and crypto sites. On paragraph and short-answer questions, add Response validation → Regular expression → Doesn't match with this pattern:

https?://|www\.

Responses containing a link are rejected with your error message. Only do this on questions where real respondents never need to paste a URL.

5. Close or move the form when you aren't collecting

Spam keeps arriving as long as the form is open. Under the Responses tab, turn off Accepting responses once an event or survey ends. If a form needs to stay live, avoid posting its raw link where scrapers look, such as public directories and comment sections. Embed it on your own page instead.

6. Screen every response before it reaches you

Settings can only make spam harder to send. To deal with what still gets through, screen each response as it lands. With an Apps Script on the form's linked spreadsheet, every new response can be sent to the GoodInbound Lead Screen API. The API labels it lead, review, spam, junk, or bot and gives a one-line reason, which the script writes next to the response.

Setup takes about ten minutes:

  1. In Google Forms, open Responses → Link to Sheets so responses land in a spreadsheet.
  2. In GoodInbound, create a secret key under Settings → MCP & APIs.
  3. In the spreadsheet, open Extensions → Apps Script and paste the script below.
  4. In Apps Script, open Project Settings → Script Properties and add GOODINBOUND_SECRET_KEY with your key, so the key never sits in the code.
  5. Open Triggers, add a trigger for screenResponse, and set the event to From spreadsheet → On form submit.
// Labels each new Google Forms response with GoodInbound Lead Screen.
// Writes the label and reason in the two columns after the response.
function screenResponse(e) {
  const key = PropertiesService.getScriptProperties().getProperty("GOODINBOUND_SECRET_KEY");
  const fields = {};
  for (const [question, answers] of Object.entries(e.namedValues)) {
    // Field names can be up to 100 characters.
    if (question !== "Timestamp") fields[question.slice(0, 100)] = answers.join(", ");
  }

  const res = UrlFetchApp.fetch("https://goodinbound.com/api/v1/leadscreen/screens", {
    method: "post",
    contentType: "application/json",
    headers: { Authorization: "Bearer " + key },
    payload: JSON.stringify({
      fields: fields,
      form: { id: "google-forms-contact", name: "Contact (Google Forms)" },
    }),
    muteHttpExceptions: true,
  });

  const result = JSON.parse(res.getContentText());
  const sheet = e.range.getSheet();
  const column = e.range.getLastColumn() + 1;
  sheet.getRange(e.range.getRow(), column, 1, 2).setValues([[result.label || "unscreened", result.reason || ""]]);
}

You can sort or filter the sheet by label, or add a few lines that email your team only when the label is lead. Responses stay in the sheet whatever their label, so a real reply screened out by mistake is never lost.

The check that matters most here reads the message itself, and it's what catches sales pitches from real people and fake sign-ups that look real. It's part of the Pro plan, $29 a month for 2,500 screened submissions. On Free, an API screen can only check the email address and your own rules, because Google Forms doesn't pass on the browser and network details the other checks use. Each screened response counts as one submission.

7. Use a form that screens responses for you

For public lead forms that get spam every day, such as contact, quote, and demo requests, Google Forms is the wrong tool. It was built for surveys. A form backend that screens every submission removes both the spam and the cleanup. GoodInbound's hosted forms and headless form endpoint label every submission the same way and only notify you about the labels you choose, without a CAPTCHA or a required sign-in.

Which fix should you use?

Situation Best fix
Internal survey or event sign-up Limit to 1 response, or restrict to your organization
Public form that gets occasional junk Validation question, email validation, and link blocking
Public form that gets daily spam or pitches Screen each response (fix 6)
Contact, quote, or demo request form A form that screens every submission (fix 7)

FAQ

Does Google Forms have a CAPTCHA?

No. Google Forms has no CAPTCHA option, and you can't add reCAPTCHA to a Google-hosted form. The closest built-in options are requiring sign-in with Limit to 1 response, and a validation question that bots answer wrong.

Can Google Forms be botted?

Yes. Browser extensions and scripts can fill in and submit a public Google Form over and over with random answers. Requiring sign-in stops most of them. Screening each response catches what gets through.

How do I delete spam responses from Google Forms?

In the form, open Responses → Individual, find the response, and click the trash icon. To clean up in bulk, delete the rows in the linked spreadsheet. That doesn't remove them from the form's own response summary, so delete them in Forms too if the summary matters.

Why am I getting spam from a Google Form I never filled in?

That's a different problem. Scammers create their own Google Forms and use them to send phishing emails from Google's servers. Don't click the links, and report the form using the Report abuse link at the bottom of it.

Switch in 5 minutes

Setup with your agents