Once a form is visible in search, spam arrives. The first solution that comes to mind is a CAPTCHA. But a CAPTCHA does not only stop bots — it asks real customers to do work too.
Someone fails the blurry images on a phone and closes the tab; someone using assistive technology gets stuck; someone simply cannot be bothered. And unlike the drop in spam, those losses are invisible. Which is why the order you try things in matters.
Spam is written by scripts, not people
Most form spam comes from automated scripts, and a script does not read a page the way a person does. It scans the HTML for input fields, fills every one of them, and submits immediately. That difference in behaviour is what you filter on.
Three measures that cost no conversions
A honeypot adds one extra field that people cannot see. Visitors leave it empty because they never know it exists; a script reading the HTML fills it in dutifully. Anything arriving with that field populated is spam. The value here is that the customer’s work does not increase at all.
A timing check compares when the form appeared with when it was submitted. A person needs a minimum amount of time to read and type; a script spends none. Set the threshold generously — too tight and you catch fast typists.
Server-side validation is the last gate. Checks that run in the browser can simply be skipped, so required fields, formats and lengths have to be verified again on the server. Rate limiting belongs at the same point.
If you do need a CAPTCHA
Some volumes of spam outrun all of the above. Then use one, but use it knowing the price.
First, prefer an invisible variety; several now pass most visitors through without any interaction. Second, record submission counts on both sides of the change: only by seeing whether genuine enquiries fell along with the spam can you tell whether the trade was worth it. Third, check accessibility — a form a screen reader user cannot complete is a form that excludes customers.
Treat the rise in spam as a signal too. It means your form has reached a target list, and it is a sensible moment to review the site’s wider defences. Those checks live in the Security archive, and a full vulnerability review of the site is part of our optimization program.
Next part
Filter out the spam and what remains are real leads — which are also personal data. The next part covers how much to collect, how long to keep it, and when to delete it.