If your inbox is full of fake enquiries, SEO pitches and random links, you are dealing with contact form spam in WordPress, and the usual advice to just add reCAPTCHA is often not enough today. In this guide I will walk you through a layered way to stop it: a honeypot and timing check first, a CAPTCHA only when you need one, and content filtering plus edge rules behind them.
The goal is not to find one perfect plugin. It is to stack simple defenses, cheapest first, so real visitors never notice them and your spam count drops.
Why contact form spam happens
Form spam is not one problem. It is at least three, and each one needs a different defense.
- Naive bots scrape the web and submit to any form they find. There are a lot of them, but they are not sophisticated.
- Targeted scripts are written against your specific form. They inspect your HTML, spot hidden fields and skip them.
- Human spam is typed by real people, such as SEO agencies, link sellers and opportunists. It has real keystrokes behind it and looks like a normal submission.
A honeypot stops the first type. A good CAPTCHA helps with the second. Only content filtering has a chance against the third. That is why relying on a single tool never fully works.
Layer 1: honeypot and timing checks
How a honeypot works
A honeypot is a form field that real visitors never see but bots fill in automatically. If the hidden field comes back with a value, the submission is flagged as spam. It costs nothing, needs no third-party script and adds zero friction for your visitors.
How to set one up properly
- Use a believable field name such as website or company, not honeypot, so bots are tempted to fill it.
- Do not hide it with display:none alone. More advanced bots look for that pattern.
- Keep it accessible: mark the field as aria-hidden, set tabindex to -1 and turn autocomplete off so screen readers, keyboard users and browser autofill do not trigger it by mistake.
- Always check the honeypot value on the server side, not only in the browser.
Add a time check
Bots submit forms in milliseconds, while a person needs several seconds at least. Rejecting submissions that arrive faster than a human could type catches automated traffic that slips past the honeypot.
Where honeypots fall short
Bots that render the page in a headless browser can recognize hidden fields and leave them empty. Human spammers are not affected at all. Treat a honeypot as a free first layer, not the whole defense.
Layer 2: CAPTCHA options
Add a CAPTCHA when a honeypot and timing check are not enough for WordPress contact form spam protection, and add it only to the forms that are actually being attacked. It is the one defense that adds friction for real users.
| Option | Visitor experience | Cost | Worth knowing |
|---|---|---|---|
| Cloudflare Turnstile | Usually invisible, may show a checkbox if it is unsure | Free | Privacy-focused, no image puzzles |
| Google reCAPTCHA v3 | Invisible, score-based | Free up to 10,000 assessments per month, paid above that | Quota is easy to exceed, see below |
| Google reCAPTCHA v2 | Checkbox and image challenges | Same quota as v3 | More visible friction for visitors |
| hCaptcha | Can show image challenges | Free tier plus paid plans (check current pricing) | Positioned as a privacy-friendlier alternative |
The reCAPTCHA quota trap
Google’s billing documentation lists a free tier of up to 10,000 assessments per calendar month per organization, aggregated across all accounts and sites. Once you go over, requests return a 429 quota error, which can break form submissions. Three details catch people out:
- An assessment is not a form submission. If you load reCAPTCHA v3 on every page, every page view counts.
- Bot traffic uses up the quota too, so a site under attack can hit the limit sooner than a clean one.
- If you manage several client sites under one Google Cloud organization, they share the same allowance. One traffic spike or bot flood can break forms on every site.
My default recommendation
For most WordPress sites I start with Cloudflare Turnstile. It is free, mostly invisible and works with the popular form plugins, and recent versions of Contact Form 7 include Turnstile support. Use reCAPTCHA v3 only if you specifically need its score-based detection and are comfortable with the Google Cloud billing model.
One warning: do not install old self-hosted CAPTCHA plugins that have not been updated in years. The Securimage plugin, for example, was closed on WordPress.org in 2023 because of a security vulnerability.
Layer 3: content and rule filtering
This layer is what catches human spam, because it looks at what was written instead of who submitted it.
- Akismet checks submissions against a global spam database and can filter both comments and contact form entries.
- Antispam Bee is a free option for comments, with settings to block by country, language or time of day.
- Simple rules such as limiting links in the message field, blocking obvious spam keywords and requiring a valid email format remove a lot of junk.
- Email address encoding stops bots from harvesting addresses published on your pages, which reduces spam at the source.
If comments are the main problem, you may not need them at all. See my guide on how to disable comments in WordPress.
Layer 4: stop it at the edge
The best spam submission is the one that never reaches WordPress. Rate limiting and firewall rules at the CDN level block repeat offenders before they load your site or trigger your form plugin. I used this approach to stop a comment spam flood on a real site, and you can read how it worked in my case study: blocking WordPress comment spam with Cloudflare.
Which stack should you use?
- Small brochure site: honeypot, time check and Akismet.
- Lead generation site with steady spam: honeypot, Cloudflare Turnstile and content rules.
- WooCommerce or membership site: all four layers, with Turnstile on registration, login and checkout.
- Agency managing many client sites: avoid putting every client on one shared reCAPTCHA project, and set up spam rules per site.
How to test that it works
Do not assume a setup works because the plugin says it is active. Test it:
- Submit the form yourself in a private browser window, logged out, and confirm the email arrives.
- Re-test after enabling a caching or optimization plugin, since those can interfere with form scripts.
- Check your spam folder or spam log for a week to catch false positives, meaning real enquiries that were blocked.
- Track spam count before and after each change so you know which layer is actually helping.
Common mistakes to avoid
- Relying on a single layer and assuming the problem is solved.
- Hiding a honeypot with display:none only, or breaking accessibility for screen reader users.
- Running reCAPTCHA v3 on every page and burning through the free quota.
- Adding a CAPTCHA to every form when only one is being attacked.
- Never checking for false positives, so real leads get lost quietly.
Need help fixing contact form spam on your WordPress site?
If spam is costing you time or real leads, I can set up and test the right protection for your site as part of my WordPress Website Maintenance & Support service.
Frequently asked questions
Is a honeypot enough to stop contact form spam?
For low-effort bots, often yes. But bots that read your page like a browser can skip hidden fields, and human spammers ignore them completely. Use a honeypot as the first layer and add others if spam continues.
Is reCAPTCHA still free?
Google offers a free tier of up to 10,000 assessments per month per organization. Above that you pay, and the quota is shared across all your sites. Check Google’s current billing documentation before relying on it.
What is the best CAPTCHA for WordPress?
For most sites, Cloudflare Turnstile is a good default because it is free and usually invisible. reCAPTCHA v3 suits sites that need score-based detection, and hCaptcha is an alternative if you prefer its approach to privacy.
Does a CAPTCHA hurt form conversions?
Visible challenges add friction, and some visitors will abandon the form. Invisible options and honeypots reduce that risk, which is why I recommend using a CAPTCHA only where it is really needed.
Can I stop form spam without a CAPTCHA?
Yes. A honeypot, a time check, content filtering such as Akismet and rate limiting at the edge can block most spam without asking visitors to prove anything.


