How to stop contact form spam without losing real enquiries
Honeypots, time traps, Turnstile, reCAPTCHA, hCaptcha and Akismet compared on what they cost real visitors, and why you should hold spam, not delete it.
- Updated
Short answer
Start with checks your visitors never see: a honeypot field and a minimum time to submit stop most bot spam, and Cloudflare Turnstile catches most of the rest without a puzzle. Set your form plugin to hold suspected spam in a separate folder rather than delete it, and check that folder weekly so a real enquiry caught by mistake still gets an answer.
Key takeaways
- Bots and human spammers need different defences, so use two layers of checks.
- Honeypots, time traps and Cloudflare Turnstile cost real visitors almost nothing.
- Puzzles, keyword lists and country blocks catch more but can turn away genuine customers.
- Hold suspected spam instead of deleting it, and check the held folder once a week.
What is a honeypot field?
A honeypot is a form field hidden from people but visible to bots, which fill in every field they find. If it comes back filled in, the submission is almost certainly from a bot.
On this page
- Where does contact form spam come from?
- Which anti-spam methods cost real visitors the least?
- How to set it up in Contact Form 7, WPForms and Gravity Forms
- What's a sensible set-up for most small business sites?
- Why should you hold spam instead of deleting it?
- How does Formcrier's spam filter work?
- FAQ
- Sources and method
Where does contact form spam come from?
Most contact form spam comes from bots that find forms automatically and fill in every field they see, and the rest comes from people paid to paste sales pitches into forms by hand. The two need different defences. A bot trips over hidden fields and timing checks, while a person typing an SEO offer passes every CAPTCHA because they are a real person.
That is why Contact Form 7's own documentation advises using two or more of its spam modules together. One layer catches the bots quietly, and a second one looks at what was written. Neither should stand between a real customer and the send button for longer than a second.
Which anti-spam methods cost real visitors the least?
Hidden checks that the visitor never sees cost the least: a honeypot field, a time trap and an invisible challenge such as Cloudflare Turnstile. Puzzles and blocklists catch more in some cases, but each one risks turning away a customer who was ready to buy.
| Method | What the visitor sees | Privacy and cost | Risk to real enquiries |
|---|---|---|---|
| Honeypot field | Nothing | No third party, free | Very low, unless a browser autofills the hidden field |
| Time trap (minimum time to submit) | Nothing | No third party, free | Low, if the minimum is a couple of seconds |
| Cloudflare Turnstile | Usually nothing; Managed mode may show a checkbox | Free at the time of writing [CHECK]; Cloudflare says it doesn't read form entries | Low |
| Google reCAPTCHA v3 | A small badge, no puzzle | Sends data to Google and sets a cookie; free tier limited (see FAQs) | Medium: a low score can block a real person with no way to retry |
| Google reCAPTCHA v2 checkbox | "I'm not a robot", sometimes image puzzles | As above | Medium: puzzles put some people off |
| hCaptcha | A checkbox, often with image puzzles on the free plan | Free Basic plan; no-puzzle modes are on paid plans | Medium |
| Akismet | Nothing | Sends the message to Akismet; paid for commercial sites | Low to medium: it judges content |
| Keyword and link filters | Nothing | No third party, free | Medium: a real customer can use a blocked word |
| Country blocks and server rules | A blocked page or error | Depends on your host or firewall | High for anyone abroad or on a VPN |
For most small business sites, a honeypot and a time trap stop the bulk of bot spam on their own. Add Turnstile if bots still get through, and Akismet or a short keyword list if hand-typed pitches are the problem.
Be wary of image puzzles in particular. They are hardest for people with poor eyesight and for anyone squinting at a small phone screen, and a customer with a burst pipe has little patience for picking out traffic lights. If you do use a visible CAPTCHA, put it only on the form that gets the spam, not on every form on the site.
How to set it up in Contact Form 7, WPForms and Gravity Forms
All three have a free invisible check, built in or as an add-on, and each can keep suspected spam for you to review, though Contact Form 7 needs its companion plugin for that.
Contact Form 7
Contact Form 7 has a Cloudflare Turnstile integration under Contact → Integration, where you paste the site key and secret key; it adds the widget for you. Its reCAPTCHA integration uses v3 only, and treats a score under 0.50 as spam by default. It also supports Akismet and WordPress's disallowed list of words and IP addresses. The plugin doesn't keep messages itself, so install its companion plugin Flamingo if you want a record: Flamingo shows held messages with the reason they were marked as spam. If the problem is that genuine messages never arrive, see Contact Form 7 not sending email: a checklist.
WPForms
In the form builder, open Settings → Spam Protection and Security. The modern anti-spam protection (a honeypot-based check) and a minimum time to submit are there, along with an option to store spam entries so you can review them, plus country, keyword and email filters. reCAPTCHA, hCaptcha and Turnstile are available on every licence, according to WPForms' documentation. For notification problems rather than spam, see WPForms notifications not sending.
Gravity Forms
Open the form's Settings → Form Settings and find the Spam Detection box. Turn on the honeypot and choose Create an entry and mark it as spam instead of "Do not create an entry", then add the Submission Speed Check. The Akismet, Cloudflare Turnstile and reCAPTCHA add-ons come with every Gravity Forms licence. Held entries appear under the form's Entries, in a separate Spam tab.
What's a sensible set-up for most small business sites?
Start with the checks visitors can't see, and only add more when real spam still gets through.
-
Turn on the hidden checks
Switch on your form plugin's honeypot and minimum time to submit. They cost real visitors nothing.
-
Hold spam, don't delete it
Pick the setting that keeps suspected spam in a separate folder or tab instead of rejecting it outright.
-
Add Cloudflare Turnstile if bots still get through
Create a widget in your Cloudflare dashboard, choose Managed mode and paste the two keys into your form plugin.
-
Deal with hand-typed pitches separately
Use Akismet or a short list of words that only spammers use, such as the names of the services they sell.
-
Send yourself a test
Fill in the form as a customer would, from your phone as well as a computer, and check it arrives.
Why should you hold spam instead of deleting it?
Every filter gets some real enquiries wrong, and a deleted enquiry can't be recovered or answered. A customer who pastes a link to a photo of their leaking boiler looks a lot like a spammer to a link filter. So does someone on a VPN, someone who fills the form in very quickly from autofill, or someone writing about "backlinks" because that's their business.
Shopify works this way by default: its contact form still delivers messages it thinks are spam, with [SPAM] at the start of the subject, so you can filter them instead of losing them. Do the same with your form plugin. Then check the held folder once a week, and if you find a real enquiry in it, look at why it was caught and loosen that one rule.
Real enquiries in a spam folder tend to give themselves away. Look for:
a full name with a local phone number or postcode
a reply to a quote or email you sent
your own town, products or services mentioned by name
a short, slightly awkward message with no links at all
Spam in your form plugin's folder is a different problem from your form emails landing in your mail provider's spam folder. That one is about email authentication, covered in WordPress form emails going to spam.
How does Formcrier's spam filter work?
Formcrier, which sends each form submission to your phone, has its own spam filter for each site that looks for a filled-in trap field, a form sent within 2 seconds of the page loading, several links, common spam phrases and repeat submissions. On the Normal level it holds a submission when a trap field was filled in or two of the other signs appear together; Strict holds on one sign alone. Spam is saved but nobody is alerted, it doesn't count towards your plan, and pressing Not spam sends the alert straight away. The details are in Spam and limits.
Frequently asked questions
Partly. At the time of writing, Google's reCAPTCHA Essentials tier is free for up to 10,000 assessments a month per Google Cloud organisation, and needs a billing account [CHECK]. A small business form rarely gets near that, but an agency running many sites under one organisation might.
No. Cloudflare says Turnstile can be added to any website without sending its traffic through Cloudflare. You only need a free Cloudflare account to create the widget and get the keys.
Because it probably was. CAPTCHAs and honeypots stop bots, not people paid to fill in forms, so use Akismet or a short keyword list for sales pitches and accept that the odd one will get through.
Only if you're sure no real customer will ever write from there. Country blocks also catch customers on holiday and anyone whose VPN or mobile network routes them abroad, and they never see a reason why.
Sources and method
Settings names and plans were checked against each product's own documentation on 1 Oct 2026. Contact Form 7's site blocked automated reading, so its pages were checked through search excerpts; the editor should open them once before publishing.
- Contact Form 7, I get spam messages through my contact forms. How can I stop them?, accessed 1 Oct 2026
- Contact Form 7, Cloudflare Turnstile integration, accessed 1 Oct 2026
- Contact Form 7, reCAPTCHA (v3), accessed 1 Oct 2026
- Contact Form 7, Why is this message marked “Spam”?, accessed 1 Oct 2026
- WPForms, How to prevent spam in WPForms, accessed 1 Oct 2026
- Gravity Forms, Ultimate guide: Gravity Forms anti-spam protection for WordPress, accessed 1 Oct 2026
- Cloudflare, Turnstile overview, accessed 1 Oct 2026
- Cloudflare, Turnstile plans, accessed 1 Oct 2026
- Google, reCAPTCHA versions and v3 documentation, accessed 1 Oct 2026
- Google, reCAPTCHA FAQ (cookies and badge), accessed 1 Oct 2026
- Google Cloud, Compare reCAPTCHA tiers, accessed 1 Oct 2026
- hCaptcha, Pricing and FAQ, accessed 1 Oct 2026
- Akismet, Pricing, accessed 1 Oct 2026
- Shopify Help Center, Add a contact page to your online store, accessed 1 Oct 2026
Tim builds websites for UK service businesses and made Formcrier after clients kept missing enquiries sent by email.