Spam bots love contact forms. Here's how to shut them down without making real customers solve puzzles.
The trick to stopping contact form spam is layering quiet, invisible defences so bots fail while genuine visitors sail through. Here's what actually works.
Add a honeypot field
A hidden field humans never see but bots fill in. If it's completed, you silently discard the submission. It's invisible, free and catches a surprising amount of junk.
Use a modern CAPTCHA alternative
Old image CAPTCHAs frustrate real people. A privacy-friendly challenge like Cloudflare Turnstile verifies visitors in the background with no puzzles, blocking bots without the friction.
Validate on the server
Never trust the browser alone. Check required fields, email format and message length server-side, and verify the CAPTCHA token before doing anything with the message. This is exactly how a well-built form endpoint should work.
Rate-limit and filter
Limit how often the same visitor can submit, and filter obvious spam patterns (links, known spam phrases). Together with a honeypot and Turnstile, this stops virtually all automated spam.
Key takeaways
- A hidden honeypot field catches many bots invisibly.
- Use Turnstile instead of annoying image CAPTCHAs.
- Always validate and verify on the server, not just the browser.
- Add rate limiting to block floods.
Forms and hosting that just work
Gander Web builds fast, spam-resistant sites on secure UK hosting, contact forms included.
Talk to usFrequently asked questions
Do I still need a CAPTCHA if I have a honeypot?
A honeypot stops simple bots; pairing it with Turnstile catches the more sophisticated ones, with no friction for real visitors.
Will spam protection put off real customers?
Not if done well. Honeypots are invisible and Turnstile usually verifies silently, so genuine visitors notice nothing.
Why validate on the server if the browser already checks?
Bots bypass the browser entirely. Server-side validation is the only check you can actually trust.