Skip to content

Common problem

Stopping contact form spam without a CAPTCHA

The short answer

A CAPTCHA works on bots, and it also works on people — on screen reader users, on anyone whose hands are unsteady, and on the visitor whose third attempt at a traffic light finally exhausts their patience. Start with the two defences a real visitor never has to pass, and only then filter what gets through on what it actually says.

Where it breaks

  1. The form
  2. The address
  3. Sending
  4. A filter
  5. The inbox
  6. A person

Which one is it?

Work down the list. Each one takes less time than the one after it, and you can stop as soon as something matches.

  1. Layer one: a honeypot

    The form
    How to tell
    A field a person cannot see and a script cannot resist filling. Costs a visitor nothing, because a visitor never knows it is there.
    What to do
    WPForms and Gravity Forms both ship one — it is a checkbox in the form’s spam settings, and on Gravity it is on by default for new forms. Contact Form 7 needs a plugin for it. This alone removes most of the crude automated volume.
  2. Layer two: how long it took

    The form
    How to tell
    Nobody reads a form, thinks about their enquiry and types it in under three seconds. A submission that fast was not typed.
    What to do
    Built into the same anti-spam settings on the builders above. Again invisible to a real visitor, who will never come close to the threshold.
  3. Layer three: what the message says

    A filter Where we come in
    How to tell
    The two layers above test how a form was filled in, not what was written in it — and what is written in it is what changed. A growing share of contact form spam is drafted by a model now, so it names your town, refers to your work and makes a plausible ask, in the register a real customer would use. It is submitted like any other message, so nothing about the submission gives it away, and a CAPTCHA does not touch this half at all.
    What to do
    Judge the message on its content. That is what we do, and the distinction we hold onto is that our mistakes are visible: anything held is kept, listed and reversible, and a week of dry run tells you what we would have held before we hold anything at all.

The argument that actually matters

Nothing stops all of it — not a CAPTCHA, not us. The real question is which kind of mistake you would rather have. A CAPTCHA’s mistakes are invisible: the customer who gave up on the third puzzle never appears in any report, and you will never know their name. A filter’s mistakes are in a list you can open, sorted, with nothing deleted. One of those you can audit.

42%

of the WordPress contact pages we could read carry a CAPTCHA — on the one platform that decides nothing for the owner. Wix owners add none at all and are not drowning; Shopify adds one for everybody. It is a reflex more than a conclusion.

From our study of 598 contact pages

Where the setting lives

The exact menu path, per builder, with the field named.

Find out where your forms actually deliver

Our free check reads your contact page and tells you what it finds. No account, nothing installed, and nothing on your site changes.

Questions people ask about this

Is a CAPTCHA really an accessibility problem?

The W3C has published on it since 2003 and has never withdrawn the position: visual puzzles exclude blind users, audio alternatives are often worse, and the newer invisible kind falls back to a puzzle exactly when someone’s setup looks unusual — which describes assistive technology fairly well.

What about the invisible ones that only score behaviour?

They are a genuine improvement on the puzzles and worth using if you use anything. Two things stay true: the score comes from a third party watching your visitors, which is a disclosure you now owe them, and a low score silently blocks a real person with no way to appeal and no record that it happened.

We already have a CAPTCHA and still get spam.

That is the usual outcome, and it is the human half you are seeing. Somebody paid to type pitches into contact forms passes a CAPTCHA the same way your customers do. It is the clearest sign that the remaining problem is the content of the message rather than the manner of the submission.

More on this

Related

We would like to count visits with Google Analytics, which sets two cookies. Decline and nothing is loaded and nothing is sent. What these are.