BG Beter Geregeld ICT
Security zonder IT-afdeling · 5 min leestijd · 12 August 2026

Contact form flooded with spam? How to keep your inbox clean without losing customers

A contact form should bring in business, not mountains of rubbish. Practical steps to filter out spam without losing real customers in the process.

You open your email in the morning and see twenty messages submitted through your website's contact form. One of them is a genuine customer. The rest? Offers for SEO services from abroad, "investment proposals," and garbled English texts stuffed with links. Sound familiar?

Spam via contact forms is a creeping problem. It takes time to wade through, and the real danger is that at some point you stop reading messages carefully. That's exactly when a genuine quote request slips through the cracks. Time to tackle it — without making your website unnecessarily difficult for visitors.

Why are you suddenly getting so much spam?

Contact forms are mostly not filled in by people, but by automated scripts (bots). These crawl the web looking for forms and blast them with standard messages. This happens all day long, in enormous volumes. If your site has recently gained visibility — for example after an update, migration, or new pages — the volume can suddenly spike.

The good news: you can filter out the vast majority with a few simple tweaks. You don't need to set up a complex security system.

Five measures that actually work

1. Add a hidden "honeypot" field

A honeypot is an extra input field that is invisible to regular visitors, but visible to bots. If something fills it in, it's almost certainly a bot and the form discards the message. Almost every professional form plugin (such as Contact Form 7, WPForms, or Gravity Forms in WordPress) has this built in. Enabling it takes two minutes and often filters out 70 to 90% of the rubbish.

2. Use a modern captcha — but not the annoying kind

The classic "click on all the traffic lights" captchas put real customers off. Instead, opt for an invisible variant such as Cloudflare Turnstile or hCaptcha Invisible. These check in the background whether the behaviour looks human, without the visitor having to do anything. Better for your conversion rate and effective against bots.

3. Limit the number of fields

The fewer fields, the less attractive your form is to bots looking to dump lengthy messages. Only ask for what you truly need: name, email address, message. A phone number or company name can always be requested later. An added bonus: regular visitors fill it in faster too.

4. Block suspicious content

A lot of spam contains words like "SEO services," "crypto," or Cyrillic characters. Most form plugins let you set up a list of blocked words. Messages containing those words are then discarded immediately. Be careful, though: filtering too aggressively means a customer who mentions "SEO" could lose their message.

5. Log submissions and check your thank-you page

Make sure every submitted form is stored somewhere (in your plugin or database), so you can retrieve it if needed. And pay attention to the thank-you page: bots ignore it, but real people don't. If you see in Google Analytics that 200 forms were submitted but nobody reached the thank-you page, you know something is off.

What if things really get out of hand?

Sometimes there's more going on. If you're receiving thousands of submissions per day, your server may become overloaded, or your mail server may end up on a blacklist for others (because your domain is forwarding all those spam messages). In that case, it helps to:

  • Put a firewall in front of your site (Cloudflare has a free option that already filters a lot of traffic)
  • Set up rate limiting: a maximum of X submissions per IP address per hour
  • Check that your mail settings are correct, so legitimate messages get delivered and spam isn't quietly being forwarded in your name

That last point is related to SPF, DKIM, and DMARC — the settings that determine who is allowed to send email on behalf of your domain. If these aren't configured correctly, spam that comes in via your form and gets forwarded to your own inbox can still cause problems with your other mail.

The pitfall: filtering too strictly

It's tempting to lock everything down. But consider this: if one in ten visitors gives up because the form doesn't work, that costs you more than half an hour of clicking away spam per week. Test your form yourself regularly, including from your phone. And occasionally ask customers what they thought of the process.

A little effort, a big difference

Most SMB sites we come across have no anti-spam measures active at all. A real shame, because in an hour's work you can eliminate 90% of the rubbish. And you'll immediately be able to see which messages actually matter.

Want to know whether your contact form is set up properly, or would you like someone to look at the broader security of your website? We'll go through it together. Or start with a structure check yourself to see where else on your site there's room for improvement.

Onderwerpen

#security #Wordpress #Website Onderhoud #Spam #Contactformulier

Volledige gids: Security for SMBs without an IT department: what should you do this quarter?

Dit artikel is onderdeel van onze uitgebreide Security zonder IT-afdeling-gids. Lees de pillar voor het complete plaatje.

Lees de pillar →