Skip to content

Common problem

Your contact form started getting spam out of nowhere

The short answer

Nothing on your site broke, and you did not do anything wrong. Your form reached a list — and lists get copied, sold and reused. Which is also why the first thing everyone tries, changing the email address, buys a few weeks and then stops working.

Where it breaks

  1. The form
  2. The address
  3. Sending
  4. A filter
  5. The inbox
  6. A person

Which one is it?

Work down the list. Each one takes less time than the one after it, and you can stop as soon as something matches.

  1. Your address was harvested

    The address
    How to tell
    The clue is in the mail: it is addressed to a mailbox that appears in your page source, or in a mailto: link, or in a WHOIS record from before privacy was standard.
    What to do
    Take the address out of the page and let the form carry it instead. This does not undo the harvest — it stops the next one, and it is worth doing once properly.
  2. Your form got indexed and added to a submitter list

    The form
    How to tell
    The mail is addressed to nobody in particular and arrives through the form rather than to a mailbox. The volume arrives in bursts, from many addresses, at hours nobody is awake.
    What to do
    A honeypot and a timing check stop most of it and cost your visitors nothing. See the page on doing this without a CAPTCHA.
  3. Something on the site changed shortly before it started

    The form
    How to tell
    Cast your mind back two or three weeks: a new form, a rebuilt page, a plugin update, a site finally coming out from behind a staging password.
    What to do
    Not a cause to fix so much as a date to have. It tells you which form to look at first, and whether an older, quieter form has been open all along.
  4. The part that is actually costing you

    A filter Where we come in
    How to tell
    The annoyance is the volume. The cost is that somewhere in this week’s pile is somebody who wants to give you work, and they now look exactly like everything else you are deleting quickly — because most of the pile was written by a model, in the same polite, specific register that person used.
    What to do
    This is the part worth solving properly rather than quickly: hold the machine-written ones and pass the rest through untouched. Run it in dry run first — for a week nothing changes, and at the end you get a list of what would have been held, to check before you trust it.

What does not work

Changing your email address — it gets harvested again, and you have now broken every link and business card that pointed at the old one. Deleting and rebuilding the form — the submission URL has the same shape and the list finds it again. Blocking by IP address — they rotate faster than you can add rules. Keyword blocklists — the arms race you lose slowly, and the words on every list of blocked terms are words real customers use: loan, investment, SEO, marketing, design.

44.4%

of WordPress contact pages print an email address straight into the markup, where anything that reads pages can copy it. On Wix it is 79.2%. That is the mechanism by which an address reaches a list, measured rather than guessed at.

From our study of 598 contact pages

Where the setting lives

The exact menu path, per builder, with the field named.

Find out where your forms actually deliver

Our free check reads your contact page and tells you what it finds. No account, nothing installed, and nothing on your site changes.

Questions people ask about this

Will it stop on its own if I ignore it?

Generally not. A form that submits successfully stays on the list because it works. The volume tends to plateau rather than fall.

Should I take the form down?

That ends the spam and the enquiries in the same move, and the enquiries do not come back when you put it up again — the people who would have sent them have already gone somewhere else. It is the one remedy that is reliably worse than the problem.

Is any of this a sign the site is compromised?

Form spam by itself is not. Worth separating: spam arriving through your form is a list problem, whereas spam being sent out from your domain to strangers is a compromise and needs dealing with today.

More on this

Related

Last checked 20 September 2026. Everything this page says about somebody else's product comes from their own documentation:

We would like to count visits with Google Analytics, which sets two cookies. Decline and nothing is loaded and nothing is sent. What these are.