how to stop bots filling your contact form: from honeypot to the settings that actually work
cybersecurity · Mar 31, 2026 · 4 min read
the contact form was quiet for a month, then one morning: fifty submissions about seo services, crypto recoveries and a very insistent hr department . those are not clients; they are scripts sweeping the web for forms to fill — with spam, or worse, with phishing probes aimed at whoever replies. here is how to close the door, in layers that start free and invisible.
the layers, cheapest first
- the honeypot field. a hidden input humans never see but bots dutifully fill. any submission containing it is silently discarded. it stops a surprising share of dumb bots, costs nothing, and no human ever notices it exists. this is the first thing every form should have.
- time check. a human cannot complete your form in two seconds; a script does it in half of one. reject submissions faster than a sane minimum. invisible, free, and it stacks with the honeypot.
- server-side spam filtering. most form services and hosts ship one (akismet for wordpress, the built-in filters on form platforms). it learns the patterns so you do not read them. turn it on before buying anything.
- the double-check on the reply. bots submit; humans respond. a confirmation step — reply to this email to confirm — costs the spammer an inbox they control, which most do not bother with. your real leads confirm without noticing; the fake ones vanish.
- rate limiting. twenty submissions a minute from one ip is not enthusiasm, it is a script. your host or form service can throttle it; the technique is the same one i documented from the other side in i wrote a honeypot in go — watching what the scanners do teaches exactly what to throttle.
- captcha, last. it works, and it taxes every real client to stop every bot. if the layers above hold, you may not need it; if you do, the invisible variants (scored in the background) beat the click all traffic lights ones for not losing real leads. the trade-off is honest: captchas do cost real leads sometimes — weigh it against the flood before you add it.
the maintenance connection nobody mentions
form spam surges when the form’s software is old: abandoned plugins and frameworks accumulate the very holes the scripts sweep for. the form that suddenly gets flooded is often the site asking for its updates — the discipline from is my website secure is also anti-spam defense.
FAQ
why do bots fill forms at all — what is the point?
three economies: seo spam (links in the message), phishing (a reply proves a live target), and lead resale (your hot lead gets sold to the seo agency that commissioned the sweep). none of them need your site to be big; they need your form to exist.
should i just close the form and use an email link?
you would trade bot spam for scraper spam — published email addresses get harvested and spammed forever. the form with layers is quieter than the mailto link; the receiving-end setup is part of any proper build, per web development in Parma.
how do i know a lead is fake before replying?
the tells: message that fits any business, url in the body, name like a keyboard walk, the reply-to domain freshly registered. the confirmation layer filters them before they reach your inbox at all.
the closing thought
bot spam is not an attack on you; it is weather — constant, impersonal, survivable with the right shelter. honeypot, time check, filtering, confirmation: four invisible layers and the flood becomes a trickle. save the captcha for when the numbers prove you need it, and let the real clients fill the form without proving they are human first.
if you want the form rebuilt with the layers included:
- web development in Parma — forms that reach you clean, spam handled at the door
- what should be on the home page — where the contact action belongs so the real leads find it