Stop Contact Form Spam Without Making Your Customers Solve Puzzles

KJONGSysSupport, Website Design

If you have a contact form on your website, you have probably noticed the junk that comes through it: crypto schemes, fake SEO offers, messages in languages you do not do business in. For years the standard answer was to bolt a CAPTCHA onto the form and make your real visitors squint at distorted letters or click every square containing a traffic light.

There is a better way now, and after rolling it out across a number of client sites this year, we can say it works remarkably well.

The Problem With Traditional CAPTCHAs

CAPTCHAs put the burden on the wrong person. The spammer is running automated software that has gotten quite good at solving puzzles, while your legitimate customer, the person actually trying to give you money, is the one stuck proving they are human. Every extra step on a contact form costs you real inquiries. Some visitors give up. Others fail the puzzle on mobile and never try again.

Google’s reCAPTCHA improved on this with its invisible “score” system, but it comes with its own baggage: it phones home to Google on every page load, it can silently reject real people with low scores, and the privacy implications make some visitors (and some regulations) unhappy.

What We Use Instead: Cloudflare Turnstile

Turnstile is a free alternative from Cloudflare that verifies visitors without puzzles. In most cases your visitor sees nothing at all, or at most a brief checkmark animation. Behind the scenes it runs a series of small, non-intrusive browser checks that are easy for a real browser being used by a real person and hard for spam software to fake.

We switched several client websites from reCAPTCHA to Turnstile this year, including our own. On one client’s site that had been receiving a steady stream of cryptocurrency spam through its contact form, the junk stopped completely the day Turnstile went live, and months later it has not come back. Just as important, real inquiries kept arriving. Nobody got locked out.

Belt and Suspenders: The Honeypot

Alongside Turnstile we usually add a second, even simpler defense called a honeypot. It is an invisible field added to the form that human visitors never see. Spam software, which fills in every field it finds, fills it in anyway, and the form quietly rejects the submission. It costs nothing, adds zero friction, and catches a surprising amount of the lazier spam on its own.

One Gotcha Worth Knowing

If you use WordPress, most form plugins have Turnstile integrations available, and Cloudflare’s own documentation covers the rest. One thing we learned the hard way: after installing a Turnstile plugin, always submit a real test through your own form. Some plugins do not actually enforce the check until a successful test has been recorded, so a setup that looks complete in the dashboard may be doing nothing at all on the live site. Two minutes of testing tells you for sure.

Protect the Login Page Too

Your contact form is not the only target. If your website runs on WordPress, its login page gets hammered around the clock by bots guessing passwords. The same Turnstile check can be applied there, which shuts down automated login attempts without making life harder for you or your staff.

Spam through your website is not just an annoyance. It buries real customer inquiries, and if your site sends an automatic reply to every submission, it can even damage your email reputation. If your forms are overrun or you are still making customers solve puzzles, get in touch and we can help you switch to something better.