Spam Protection and CAPTCHA

7 min read

Spam submissions waste your time, pollute your data, and can even cost you money if your form triggers paid integrations or notifications. WittyForm provides multiple layers of spam protection that work together to keep your submissions clean while minimizing friction for legitimate respondents.

Built-in Spam Detection

Every WittyForm has built-in spam detection enabled by default at no extra cost. This system runs in the background and analyzes submissions for spam signals without adding any visible elements to your form. It checks for:

  • Submission speed — Forms submitted in under a few seconds are likely automated. Legitimate respondents need time to read and fill in fields.
  • Bot signatures — Analysis of browser behavior, mouse movements, and interaction patterns to distinguish humans from bots.
  • Known spam patterns — Content analysis that detects common spam phrases, excessive links, and known malicious payloads.
  • IP reputation — Cross-referencing the submission IP against databases of known spam sources and bot networks.

Submissions that trigger spam signals are flagged but still saved. You can review them in your responses with a spam indicator and decide whether to keep or discard them.

CAPTCHA

For forms that need stronger protection, you can enable a CAPTCHA challenge. WittyForm supports three CAPTCHA providers, each with different trade-offs between security and user experience.

reCAPTCHA v2 (“I’m not a robot”)

The classic checkbox CAPTCHA from Google. Respondents click a checkbox and may be presented with an image challenge (e.g., “Select all images with traffic lights”) if the system is not confident they are human.

  • Pros: Very effective against bots, universally recognized by users.
  • Cons: Adds visible friction. Image challenges can be time-consuming and frustrating, especially on mobile.
  • Best for: High-value forms where spam is a serious problem and you need maximum protection (contact forms on high-traffic websites, registration forms).

reCAPTCHA v3 (Invisible)

An invisible CAPTCHA from Google that runs entirely in the background. It assigns a score (0.0 to 1.0) based on user behavior, with no visible challenge. You set a threshold score below which submissions are flagged or blocked.

  • Pros: Zero friction for respondents. They never see a CAPTCHA challenge.
  • Cons: Requires fine-tuning the score threshold. May occasionally flag legitimate users, especially those using VPNs or privacy browsers.
  • Best for: Forms where user experience is paramount (checkout forms, lead generation) but you still want bot protection.

hCaptcha

A privacy-focused CAPTCHA alternative. Similar to reCAPTCHA v2 in appearance but does not rely on Google’s tracking. Respondents solve a visual challenge.

  • Pros: Better privacy than reCAPTCHA. GDPR-friendly since it does not use Google tracking cookies.
  • Cons: Similar friction to reCAPTCHA v2. Less widely recognized by users.
  • Best for: Forms targeting privacy-conscious audiences or where GDPR compliance is a concern.

Enabling CAPTCHA

  1. Open your form in the editor and go to Settings > Spam Protection.
  2. Toggle Enable CAPTCHA.
  3. Select your preferred CAPTCHA provider.
  4. Enter your site key and secret key for the provider. You can get these by creating a free account at the provider’s website (Google reCAPTCHA or hCaptcha).
  5. For reCAPTCHA v3, set the score threshold. A value of 0.5 is a good starting point. Lower values are more permissive; higher values are stricter.
  6. Save the settings. The CAPTCHA will appear on your live form.

Honeypot Fields

A honeypot field is an invisible field that is hidden from human respondents but visible to bots. Since bots typically fill in every field they find, any submission with a value in the honeypot field is automatically flagged as spam.

WittyForm’s built-in spam detection includes a honeypot by default. You do not need to configure anything — it is added automatically and is invisible to respondents. The honeypot is hidden using CSS and ARIA attributes so it does not interfere with screen readers or accessibility tools.

Honeypots are effective against simple bots but will not stop sophisticated bots that emulate human behavior. For stronger protection, combine the honeypot with CAPTCHA.

Rate Limiting

Rate limiting restricts how many submissions can come from the same source in a given time period. This prevents bots from flooding your form with hundreds of submissions.

Configuration

  • Per IP limit — Maximum number of submissions from a single IP address within a time window. The default is 10 submissions per hour. Adjust based on your form’s expected traffic patterns.
  • Global limit — Maximum total submissions per hour across all sources. This acts as a safety net against distributed attacks. Set this well above your expected peak traffic.
  • Action — Choose what happens when the limit is reached: block the submission with an error message, or accept it but flag it for review.

When a respondent hits the rate limit, they see a friendly message like “Too many submissions. Please try again later.” The message text is customizable.

IP Blocking

If you identify specific IP addresses that are sending spam, you can block them entirely:

  1. Go to Settings > Spam Protection > Blocked IPs.
  2. Enter the IP address or IP range (CIDR notation) to block.
  3. Click Add.

Blocked IPs will see the form but their submissions will be silently rejected — the form appears to submit successfully but no response is saved. This prevents the spammer from knowing they have been blocked.

You can also block an IP directly from a spam response by clicking the three-dot menu on the response and selecting “Block this IP.”

Reviewing Flagged Submissions

Submissions flagged by the spam detection system appear in your responses with a yellow spam indicator badge. To review them:

  1. In the responses view, use the Spam filter to show only flagged submissions.
  2. Review each flagged response. Check the content, submission time, and IP information.
  3. For each flagged response, you can:
    • Mark as not spam — Removes the spam flag and treats it as a legitimate response. This also helps train the spam detection system.
    • Confirm as spam — Keeps the flag and optionally blocks the IP address.
    • Delete — Permanently removes the submission.

Flagged submissions are excluded from analytics, exports, and notification triggers by default until you mark them as not spam.

Reducing Spam Without Hurting Completion Rates

The most effective spam protection is layered. Here is a recommended approach that maximizes protection while minimizing impact on real respondents:

  1. Start with built-in detection — This is always on and has zero impact on user experience. It catches most casual spam.
  2. Add reCAPTCHA v3 if needed — If you are still getting spam after built-in detection, add the invisible reCAPTCHA. Start with a threshold of 0.5 and adjust based on your false positive rate.
  3. Enable rate limiting — Set reasonable per-IP limits to prevent flood attacks. This has no impact on normal respondents.
  4. Use reCAPTCHA v2 or hCaptcha as a last resort — Only add visible CAPTCHA challenges if invisible protection is not sufficient. Be aware that visible CAPTCHAs can reduce completion rates by 10–20%.
  5. Block repeat offenders — Use IP blocking for persistent spam sources you identify in your flagged submissions.

Monitor your spam-to-legitimate ratio regularly. If you are marking many flagged submissions as “not spam,” your settings may be too aggressive. If spam is getting through unflagged, consider adding another layer.

Best Practices

  • Never disable built-in spam detection. It runs invisibly and catches more spam than you might expect.
  • Review flagged submissions weekly rather than ignoring them. Occasionally, legitimate responses get flagged, especially from users on VPNs or shared networks.
  • Use invisible reCAPTCHA v3 over visible reCAPTCHA v2 whenever possible to preserve user experience.
  • If using reCAPTCHA v3, monitor the score distribution in your Google reCAPTCHA dashboard to find the right threshold for your audience.
  • Set rate limits that accommodate your busiest expected traffic. A form shared on social media can receive bursts of legitimate traffic that might trigger overly strict limits.
  • Do not rely solely on CAPTCHA. Sophisticated bots can solve CAPTCHAs. Layered protection is always more effective than any single measure.

Ready to Build Your Form? Start With Drag and Drop

Get lifetime access for just $37. No subscriptions or recurring fees. Create beautiful forms and own the tool forever.

14-day money-back· Instant access
Spam Protection and CAPTCHA