Skip to content

Squarespace contact form spam: why reCAPTCHA lets it through

Squarespace forms have reCAPTCHA switched on by default, and the spam still arrives. Why that happens, what our study of 598 contact pages found on Squarespace, and what is worth changing.

Humainbox 8 min read
In this piece
  1. What Squarespace gives you
  2. Why the well-written ones get through
  3. What we saw when we looked at Squarespace sites
  4. The order worth doing things in
  5. Moving the filter from the form to the message
  6. Where it is hard
  7. Further reading

If your website is on Squarespace, you probably did not set up any spam protection on your contact form. You did not need to. Squarespace switches Google reCAPTCHA on for every form block by default, and it adds a spam check of its own. And the spam still arrives.

That is not a setting you missed. It is what happens when a filter checks whether a visitor is a bot, and the message you are getting was sent by something that is not one, or at least does not look like one. This post covers what Squarespace does for you, why it lets the well-written messages through, what we found when we looked at Squarespace sites from the outside, and what is worth changing.

What Squarespace gives you

Squarespace's help pages describe three things.

Squarespace is honest about the limit. The same help page says there is no way to block all spam from reaching you, and its main advice is to keep reCAPTCHA on.

Why the well-written ones get through

reCAPTCHA answers one question: does this visit look like a person using a browser? For a long time that was the same question as "is this spam?", because spam was sent by simple scripts that did not behave like people.

That is no longer true. A lot of what reaches small businesses now is written by a language model for your business specifically and sent through a real browser, sometimes by a person and sometimes by a tool that drives one. It looks like this:

Hi there,

I came across your studio while looking at wedding photographers in Bath, and your coastal portfolio really stood out. We help creative businesses like yours get booked out months in advance.

Would you be open to a quick 15-minute call this week?

reCAPTCHA v3 saw a normal visit and gave it a good score, and in the sense it measures, that was correct. Squarespace's content check found nothing suspicious, because the message is polite, spelled correctly and written for you. Nothing about how it was sent gives it away. Only what it says does: it praises your work, names your town, and asks for your time without asking about anything you sell.

We have written more about why the old filters cannot see this kind of message and the patterns it leaves in the text.

What we saw when we looked at Squarespace sites

In September 2026 we read 598 small-business contact pages twice: once the way a simple program reads a page, by fetching the code the server sends, and once in a real browser. Squarespace stood out.

  • The simple read found 7 of the 32 Squarespace forms a browser could see, 21.9%. On WordPress the same read found 94.3%. Squarespace draws its forms with JavaScript after the page loads, so a program that only reads the code does not see them.
  • None of the 14 CAPTCHAs a browser saw on Squarespace sites were in that code. The protection is as hidden as the form.
  • 8 of the 10 Squarespace pages we could read printed an email address in the page code. The sample is small, so treat that as a warning rather than a rate.
  • 57.8% of the Squarespace sites had no DMARC record. More on that below.

Two honest caveats. First, the 21.9% moved: with the first 21 Squarespace forms it was 14.3%, and it rose as the sample grew. We printed both. Second, the fact that simple programs miss your form does not protect you. The spam in your inbox came from tools that do run the page, or from people. What the finding does tell you is that any tool which reads pages without a browser, whether an audit, a lead finder or an AI assistant, can be confidently wrong about a Squarespace site: it will report no form and no protection when both are there.

The order worth doing things in

Keep reCAPTCHA on. It still removes the crude, scripted traffic, and that traffic has not gone away. If you turned it off at some point, turn it back on: it is on the form block's Content tab, and Squarespace notes it is required if you want visitors to upload files.

Then, in this order:

  1. Check where the form sends its notifications. Open the page, click the form block, click the pencil icon, and look at the Email Notification field on the Content tab. Older guides, including some of Squarespace's own pages, still point to the Storage tab. Make sure the address is one somebody reads every day.
  2. Take your email address off the page. If your contact page shows your address as plain text, bots can copy it from the code and it can end up on lists, whatever you do to the form. The form is there so that you do not need to publish the address at all.
  3. Add a DMARC record to your domain. DMARC tells Gmail and Outlook what to do with email that claims to come from your domain but did not. Without it, more mail forged in your name gets through. If your domain is with Squarespace, you add it under DNS as a TXT record named _dmarc, and Squarespace notes you can only add one DMARC record per domain. Our free contact page check shows whether you have one and gives you a starting record to copy.
  4. Report the spam that gets through. It will not stop the next message, but it tells Squarespace what its own check missed.

And stop doing the things that only hurt customers:

  • Do not add more required fields. A tool that fills forms for a living does not mind a longer form. A customer on a phone does.
  • Do not reply to the pitches, even to say no. A reply confirms that a real person reads the inbox behind the form.

Moving the filter from the form to the message

Once reCAPTCHA is doing its job, what is left needs something that reads each message and asks whether a person wrote it to your business. That has to happen after the form, because nothing about the visit is wrong.

On Squarespace this needs no code and no plugin. The Email Notification field takes any address. Humainbox gives each form its own address; you put it in that field, it checks every message and, once the inbox is active, sends on the ones a person wrote and holds the rest with a written reason you can check. Nothing it holds is deleted. The Squarespace integration page shows the field, and how it works covers the rest.

Whatever you use, test it before trusting it. In Humainbox that is dry run, which delivers everything as before and records what it would have held. Leave it for a week and compare its decisions with your own.

Where it is hard

  • One address per form. Squarespace connects only one email address to each form. If two people need the enquiries, Squarespace's own suggestion is to forward the mail in your email provider. Humainbox gets around this differently: the form sends to its one address, and each inbox can pass enquiries on to several people.
  • Your other storage keeps working. If the form also sends submissions to a mailing list, Google Drive or Mailchimp, those connections are separate from the email notification and are not filtered by changing it.
  • Replying to the enquiry. Notifications come from [email protected], and Squarespace says that if your form has an email field, you can reply to the email to respond to the person who submitted it. Send yourself a test with an outside address and press reply, before and after any change, to be sure the reply still reaches the visitor.

Further reading

Try it on your own mail

Stop contact form spam

Change one setting in your contact form. Spam stops arriving, and real enquiries go to whoever should answer them. Try it for a week with nothing switched on.

We would like to count visits with Google Analytics, which sets two cookies. Decline and nothing is loaded and nothing is sent. What these are.