How to stop contact form spam without annoying real users
· 7 min read
Forty messages a day about SEO services, cryptocurrency and guest posting, and somewhere in the middle, a genuine customer asking for a quote. That is the moment most owners go looking for a CAPTCHA. Before you add one, it is worth knowing that every measure you use to stop contact form spam also costs you a slice of real enquiries. The goal is not zero spam. It is the lowest total damage, counting both the junk you read and the customers who gave up.
This article sets out a ladder of defences, from ones nobody notices to ones everyone hates, and how to decide where on that ladder your form belongs.
First, measure what you are actually dealing with
Spend a week counting before you change anything. Note how many submissions arrive per day, how many are junk, and roughly how long you spend clearing them. Then look at the pattern, because different spam calls for different answers.
- Bulk bot spam: dozens of identical or near-identical messages, often with links, arriving at odd hours. Automated and easy to defeat.
- Targeted service pitches: a human or a semi-automated tool sending outreach that mentions your business name. Harder to filter technically, easier to handle with a rule in your email client.
- Abuse of your own emails: forms that put user text into the subject line or the From field of a notification email can be used to relay spam elsewhere. This one is urgent and is a coding fix, not a filter.
- Fake orders or signups: more serious, because they consume stock, send real SMS, or cost you payment gateway fees.
Five junk messages a day is an annoyance. Five hundred is a different problem with different solutions. Knowing which you have prevents you from over-fortifying a form that only needs a small nudge.
The ladder: lightest defences first
Rung 1: invisible checks
These run without the visitor knowing. A hidden field that humans never see and bots fill in, a check on how quickly the form was submitted, and a limit on how many times one address can post in an hour. They cost nothing in conversions and stop a surprising share of automated traffic. The next article in this series covers how each one works in detail.
Rung 2: content and context rules
Reject or quarantine submissions that contain obvious markers: multiple URLs in a short message, BBCode tags, non-Latin scripts you never receive legitimately, or known spam phrases. Keep these rules conservative and always store rejected submissions rather than deleting them, so you can check for false positives.
Rung 3: make the form less convenient to attack
Requiring JavaScript to build part of the form, using a token that ties the submission to a session, and avoiding a predictable endpoint name all raise the effort needed. None is impossible to defeat, but most spam tools chase the easiest targets.
Rung 4: friction the user can see
A simple question ("What is 4 plus 3?"), a checkbox confirming intent, or an emailed confirmation link before the message reaches you. Real people can pass these, but some will not bother, especially on mobile.
Rung 5: CAPTCHA
Modern invisible or score-based services are far less intrusive than the old distorted-text boxes, but they still add a third-party script, they still occasionally challenge legitimate users, and they are harder for people using screen readers or older phones. Treat CAPTCHA as the answer when the lower rungs have genuinely failed, not as step one.
Weigh the cost of each rung in lost enquiries
Suppose your contact form brings 30 enquiries a month and each converts at ten percent into work worth a few thousand rupees. If a visible challenge causes even two people a month to give up, that can cost more than the twenty minutes you spend deleting spam.
That calculation flips for a form that gets thousands of submissions or one that triggers real costs such as SMS sends. The question to keep asking is not "will this stop spam" but "what does this cost me, and is the spam costing more".
Watch the numbers after any change. Compare form submissions in GA4 or your own database for the two weeks before and after. A sudden drop in total submissions that includes genuine ones is a sign you went a rung too high.
Fix the things that make your form attractive
Some forms get hit harder than others because of how they are built. Check these before adding defences:
- Never put user input in email headers. The From address on your notification should be a fixed address you control, with the visitor's address in Reply-To.
- Do not publish the endpoint openly. A generic handler that accepts any field names and emails them is an open invitation.
- Remove old forms. Abandoned pages from a previous site version often still accept posts.
- Check your plugins. Outdated form plugins with known vulnerabilities attract targeted traffic, not just noise.
- Do not display submissions publicly without moderation, since visible output is the whole point for link spammers.
Handle the spam that still gets through
No layer catches everything, so make the residue cheap to deal with. Route form notifications to a dedicated address rather than your personal inbox. Apply a filter that labels likely junk instead of deleting it. Store every submission in a database table with a status column, so your team works from a list with a "mark as spam" button rather than from email.
That last change alone often removes most of the frustration. The problem for many owners is not the existence of spam, it is that it is mixed into the same inbox as the real work.
Pick your starting point this week
For a typical small business site, start with the invisible checks plus a rate limit, store all submissions with a status, and stop there. Watch for a month. If bulk junk continues at a level that genuinely wastes time, add a content rule or a lightweight question before you reach for anything heavier. If you would like the form, its storage and its notification emails reviewed together, our team can do that as part of ongoing website support.
Frequently asked questions
Does adding a CAPTCHA hurt SEO?
Not directly, since search engines do not rank pages on the presence of a CAPTCHA. The indirect risks are a slower page from the extra script and lower conversions, both of which matter more than any ranking effect.
Why did spam start suddenly on a form that was quiet for years?
Usually because a scanner found your endpoint and added it to a list. A site redesign, a new plugin, or your URL appearing in a public directory can all trigger it. The volume often fades once submissions start failing consistently.
Should I block entire countries or IP ranges?
Be cautious. Blocking broad ranges catches customers travelling, using a VPN or on a mobile network whose addresses are shared. A temporary block on a specific abusive address is safer than a permanent country-wide rule.
Is it worth removing the contact form and showing only an email address?
Rarely. A published address attracts its own harvesting, and you lose the structured fields that make enquiries easy to handle. Keeping the form and filtering it usually beats removing it.
Thinking about a website?
See what a package covers and what it costs, or ask us about your own project.