# Humainbox > Stop contact form spam. Keep every real enquiry. Change one field in your contact form settings. AI-written spam stops arriving, and the enquiries a person actually wrote reach whoever should answer them. No plugin, no snippet, no code. ## What makes it different Competing form-spam products require changing a form's `action` attribute or installing a plugin, which needs a developer. Humainbox needs one field: the recipient address in the form's own notification settings. Nothing else about the site changes. ## How it works 1. You add an inbox here and we give you a generated address. 2. You paste that address into your form's "send submissions to" field. 3. Mail arrives at us, is judged, and genuine enquiries are forwarded to the recipients you configured. 4. The reply address is the visitor's own, so pressing reply reaches them and not your form's automated mailbox. ## The field to change, per form builder This is the whole integration. There is no API, no plugin and no snippet — if a form can send its notification to an address you choose, it works. - **WordPress** (https://humainbox.com/integrations/wordpress): Settings → General → Administration Email Address — ⚠️ Check this is the field you mean. It is WordPress's own address — password resets, update failures, new user notices — and not your contact form's, which lives in whichever form plugin you use. — Covers the default site notifications. Most WordPress sites also use one of the form plugins below, and those have their own recipient field. - **WPForms** (https://humainbox.com/integrations/wpforms): Settings → Notifications → Send To Email Address — Set per form, so you can move one form across and leave the rest alone while you watch it. - **Contact Form 7** (https://humainbox.com/integrations/contact-form-7): Mail → To — Leave the "From" and "Additional headers" fields exactly as they are. Only the To address changes. - **Gravity Forms** (https://humainbox.com/integrations/gravity-forms): Settings → Notifications → Send To Email — If the notification is set to "Select a Field", switch it to "Enter Email" and paste the address. - **Elementor Forms** (https://humainbox.com/integrations/elementor): Form widget → Content → Actions After Submit → Email → To — Elementor Pro only — the free version has no form widget. Nothing here catches spam by default: the honeypot and reCAPTCHA are fields you add yourself. - **Webflow** (https://humainbox.com/integrations/webflow): Form settings → Email Notifications → To — On the form itself in the Designer, not in project settings — so each form moves separately. The To field takes a Workspace member from the dropdown or an address you type. - **Squarespace** (https://humainbox.com/integrations/squarespace): Form block → Storage → Email Notification — One address per form: Squarespace connects a single email to each form, so this is a swap and not an addition. - **Shopify** (https://humainbox.com/integrations/shopify): Forms → Automations → Send internal email → Email address — ⚠️ Do not use Settings → Notifications → Sender email. Shopify uses that one address for two jobs — where the storefront contact form is delivered, AND the From address your customers see on order confirmations — so pointing it at us would rewrite the sender of every email your store sends. — Not the theme's built-in contact form: that one is delivered to your store's sender address. This is the Shopify Forms app plus a Flow automation, both free on every plan. - **Wix** (https://humainbox.com/integrations/wix): Forms & Submissions → Set notifications → Send an email → Recipients — Wix moved this out of the form editor and into Automations. The recipient does not have to be a site collaborator, but it does have to exist as a contact. - **HubSpot** (https://humainbox.com/integrations/hubspot): Form → Options → Send submission email notifications to — ⚠️ HubSpot will not take an arbitrary address here — the recipient must be a HubSpot user in your account, or the notification has to be sent by a workflow instead. — HubSpot only accepts existing HubSpot users as notification recipients, so the address has to belong to one. On Professional and Enterprise a workflow can send the internal notification anywhere. - **Typeform** (https://humainbox.com/integrations/typeform): Workflow → the email step → recipients — Older accounts still see this as Create → Follow-ups. Responses stay in Results either way. ## Writing Notes on what AI-written enquiry spam looks like and what can be done about it. - **Fake form fills are training your Google Ads campaign** (https://humainbox.com/blog/fake-form-fills-google-ads) — AI-written spam: When junk submissions fire your conversion tag, the bidding learns from them and buys more of the same traffic. Why a mailbox filter cannot fix that. - **Contact form spam across client sites — an agency playbook** (https://humainbox.com/blog/agency-contact-form-spam) — Contact forms: A playbook for agencies whose clients all ask the same question: inventory every form, standardise the basics, and put a threshold in the retainer. - **GDPR and contact form spam filtering: what you are allowed to do** (https://humainbox.com/blog/gdpr-contact-form-spam-filtering) — How filtering works: Filtering contact form spam means handling personal data. What GDPR asks: a lawful basis, short retention, a line in your privacy notice, care with providers. - **Spam filter false positives: what a held enquiry really costs** (https://humainbox.com/blog/false-positives-spam-filter) — How filtering works: A spam filter can be 99% accurate and still hold one real enquiry in ten. What those misses cost, and how to measure a filter before you trust it. - **Fake legal threats through your contact form: the malware lure** (https://humainbox.com/blog/contact-form-malware-fake-legal-threats) — AI-written spam: Fake copyright complaints through contact forms have carried malware since 2021. How the lure works, how to spot one, and what to do instead of clicking. - **Who should receive your website enquiries? Routing without info@** (https://humainbox.com/blog/routing-website-enquiries) — Contact forms: A shared info@ address feels safe and quietly loses enquiries. How to route each form to a named owner, cover absences and leavers, and hold less data. - **The contact form spam you get most, and how to recognise each** (https://humainbox.com/blog/common-contact-form-spam) — AI-written spam: SEO offers, fake invoices, legal threats, guest posts: a field guide to the spam you keep getting — the tell for each, and what a real one looks like. - **How form notifications are sent, and why they get rejected** (https://humainbox.com/blog/how-form-notifications-are-sent) — Contact forms: Your visitor did not send that email — your web server did. What wp_mail does, what SPF, DKIM and DMARC check, and why “sent” does not mean delivered. - **CAPTCHA on contact forms: is reCAPTCHA enough?** (https://humainbox.com/blog/captcha-on-contact-forms) — Contact forms: A CAPTCHA checks whether a visitor is human, not whether they wrote to you. What reCAPTCHA, hCaptcha and Turnstile cost real visitors, and when they earn it. - **Contact Form 7: what reCAPTCHA and Akismet actually cost you** (https://humainbox.com/blog/contact-form-7-spam) — Contact forms: Every anti-spam layer Contact Form 7 offers, what each catches, what it costs the visitors you want, and why well-written pitches walk through all of them. - **Why your spam filter stopped catching contact form spam** (https://humainbox.com/blog/your-spam-filter-did-not-break) — AI-written spam: Contact form spam used to announce itself. Now it references your work and asks for fifteen minutes. What changed, and how to filter it without losses. - **AI-written contact form spam: what it looks like, how to spot it** (https://humainbox.com/blog/what-an-ai-sdr-actually-sends-you) — AI-written spam: Four patterns in almost every machine-written sales approach, the three things a real enquiry does that none of them manage, and what to do when one lands. - **Why blocklists do not work on a contact form** (https://humainbox.com/blog/why-blocklists-do-not-work-on-a-contact-form) — How filtering works: Every other mailbox learns who to trust. A contact form cannot, because a stranger writing for the first time is the whole point. What sender checks miss. ## Common problems, and the actual cause - **Nothing is arriving from the form** (https://humainbox.com/problems/not-receiving-contact-form-submissions): Four things can be true here, and only one of them is “the form is broken”. Check them in the order below — it is cheapest first, and the second one is the step almost nobody takes, because an address that was set correctly years ago does not feel like a cause. - **They arrive, but in the spam folder** (https://humainbox.com/problems/contact-form-emails-going-to-spam): Nearly always, the form is sending as your visitor: their address in the From line, your web server doing the sending. Nothing authorises your server to send on their behalf, so the checks Gmail and Outlook run come back failed and the message is treated as forgery. The fix is the From address, not the wording of the email. - **The spam reads like a real customer** (https://humainbox.com/problems/contact-form-spam-that-looks-real): If you are opening every message to work out whether it is real, the spam is doing its job. A growing share of it is drafted by a model now, so it has your town in it, a sentence about your work and a plausible ask. Nothing about how it was submitted gives it away — only what it says does. - **Spam, but a CAPTCHA is not an option** (https://humainbox.com/problems/stop-contact-form-spam-without-captcha): A CAPTCHA works on bots, and it also works on people — on screen reader users, on anyone whose hands are unsteady, and on the visitor whose third attempt at a traffic light finally exhausts their patience. Start with the two defences a real visitor never has to pass, and only then filter what gets through on what it actually says. - **It started all at once, this week** (https://humainbox.com/problems/suddenly-getting-contact-form-spam): Nothing on your site broke, and you did not do anything wrong. Your form reached a list — and lists get copied, sold and reused. Which is also why the first thing everyone tries, changing the email address, buys a few weeks and then stops working. - **No fault — just not sure it all arrives** (https://humainbox.com/problems/is-my-contact-form-working): A test submission proves exactly one thing: that a message sent by somebody who knows to go and look for it arrives. It says nothing about the ones you never see, and those are the only ones worth worrying about. Four questions cover the rest. ## Pricing Priced on companies, inboxes and people, never per message: a month where an inbox is hit hard costs the same as a quiet one. Every plan includes the same filtering, dry run, flood protection and message history (30 days by default, up to 90). Monthly, in EUR. - **Free** — Free: 1 company, 1 inbox, just you - **Starter** — €39/month: 1 company, 5 inboxes, up to 5 people - **Growth** — €99/month: 3 companies or brands, 10 inboxes each, unlimited people - **Agency** — €299/month: 25 client workspaces, 10 inboxes each, unlimited people ## Pages - [How it works](https://humainbox.com/how-it-works): the mechanism: what we read, how a verdict is reached, and what happens on a bad day - [Pricing](https://humainbox.com/pricing): plans priced by company, inbox and people rather than per message - [Integrations](https://humainbox.com/integrations): the setting to change in each supported form builder - [Research: 598 contact pages measured](https://humainbox.com/research/contact-pages-2026): Sept 2026 study of 598 small-business contact pages: a single static fetch finds 94.3% of contact forms on WordPress and 21.9% on Squarespace; five samples drawn five ways, method and limits published, including what the study cannot see - [Common problems](https://humainbox.com/problems): symptom-first answers: nothing arriving, notifications in spam, spam that started overnight - [For agencies](https://humainbox.com/for/agencies): running this across many client sites - [For growing teams](https://humainbox.com/for/growing-teams): routing enquiries to whoever owns them - [Quoting for work](https://humainbox.com/for/quoting-for-work): businesses where an enquiry might be a job worth thousands - [About](https://humainbox.com/about): why it exists and what we will not claim - [Privacy Policy](https://humainbox.com/legal/privacy): what is stored, for how long, and what leaves our infrastructure - [Terms of Service](https://humainbox.com/legal/terms): including the stated limits of classification ## Stated limits These are on the site and should not be omitted from any summary of it: - Classification is probabilistic and will sometimes be wrong in both directions. - No accuracy figure is published, because none could be shown with its working. - No security certification is held. - Attachments are kept and readable in the panel but are not re-attached to forwarded mail. - Messages that deterministic rules cannot decide may be sent to a language-model provider for classification. That can be switched off per account, and then only local rules run. - Every new inbox starts in dry run, where everything is delivered and only the decisions are recorded. - The published Terms and Privacy Policy accurately describe the system but have not been reviewed by a lawyer, and say so on their own pages. ## Contact hello@humainbox.com