The PironTRRequest a quote

Why is my contact form getting spam, and how can I stop it?

Why contact forms attract spam, visible and invisible verification methods, why server-side checks matter, and a checklist for form security.

A website’s contact form may start receiving meaningless text, advertisements in foreign languages or messages containing suspicious links. Most of these messages are sent by automated programs.

Spam does more than fill the inbox. It can cause genuine customer messages to be overlooked and can damage the reputation of the email account.

Who sends spam messages?

The programs that send these messages are called bots. Bots scan websites across the internet one after another, then fill in and submit any forms they find automatically. A small or new site is not protected from this scanning. Bot submissions can begin shortly after a form goes live.

Bots usually aim to spread advertising links, send fake offers or find a weakness in the form. Some try to use the form to relay messages to others through the site’s email infrastructure.

Visible and invisible verification

The familiar way to tell a person from a bot is a CAPTCHA test. The visitor is asked to type distorted letters or select the squares that contain a particular object. This works like a guard at a building entrance who asks everyone for identification. It is effective, but it makes every visitor wait and can lead some to leave without completing the form.

Invisible verification, which is now increasingly common, checks the visitor’s browser in the background. In most cases the visitor does not solve any test. A short confirmation is requested only when something looks suspicious. Cloudflare Turnstile and Google reCAPTCHA are widely used services in this area.

Why is checking in the browser alone not enough?

A form can be checked in two places: in the visitor’s browser and on the server the form is sent to. A check in the browser is like a “Please ring the bell” sign on a door. It guides visitors who follow the rules, but it does not lock the door.

Bots often send data directly to the server without ever opening the form page. The verification result therefore needs to be checked on the server as well. On sites that use invisible verification, the confirmation code generated in the browser is checked with the verification service by the server before the message is delivered.

Additional measures

  • Submission limits: A large number of submissions from the same source within a short time can be limited.
  • Field checks: The email address format, message length and required fields are also checked on the server.
  • Trap field: A hidden field that visitors do not see, and that only bots fill in, is added to the form. If it is filled in, the message is not delivered. Because browser autofill can also fill this field, using this method on its own can cause genuine messages to be lost.
  • Time check: Forms submitted within a few seconds of the page opening can be treated as a sign of a bot.
  • Up-to-date plugins: On WordPress sites, form and security plugins should be kept up to date. Older versions may contain vulnerabilities that bots exploit.

Forms and personal data

A contact form collects personal data such as name, email address and phone number. Under KVKK, Türkiye’s personal data protection law, a link to a personal data notice should therefore be placed near the form. The notice explains why the data is collected, how it is stored and with whom it is shared.

Verification services also receive some technical information from the visitor’s browser. It is advisable to name the service used in the privacy policy.

Checklist

  • Does the form include bot verification?
  • Is the verification result also checked on the server?
  • Are required fields and message length validated on the server?
  • Are repeated submissions from the same source limited?
  • Do genuine messages arrive? Because bot protection can also block real visitors, the form should be tested by sending test messages from different browsers and devices.
  • Are form and security plugins up to date?
  • Is there a link to the personal data notice near the form?
  • Does the site open over https://, that is, over an encrypted connection?

The Piron’s approach

Contact forms on the sites we develop use invisible verification, and the verification result is checked on the server before a message is delivered. Field format and length are also validated on the server side. A link to the personal data notice is placed next to the form.

Before launch, the form is tested with real submissions to confirm that bot protection does not block genuine messages. On WordPress sites covered by a maintenance service, form and security plugins are kept up to date.

For information about the form on your site, please get in touch through our contact page.

Let’s discuss your project.

Share your project details and we will respond with scope, timing and pricing.

Write to us by email

You can also send your project details and files by email.

hello@thepiron.com

Message us on Instagram

For short questions you can also reach us on Instagram.

Send a message
Message us on Instagram