How to Stop WPForms Spam Submissions: Step-by-Step Guide (2026)
WPForms is one of the most popular form builders for WordPress, and it ships with more built-in anti-spam tooling than most competitors — but it’s not turned on by default for every feature, and none of it catches every type of spam. Here’s a practical walkthrough.
The two kinds of spam WPForms users deal with
- Bot submissions — automated, high-volume, usually nonsensical content
- Human-submitted junk — real people entering fake or low-effort information, common on lead-gen and contact forms tied to paid traffic
WPForms’ built-in tools mostly target the first category. Worth knowing that going in.
Step 1: Enable the anti-spam honeypot
WPForms includes a built-in honeypot field that’s enabled by default on new forms, but it’s worth checking if you built your form a while ago. Go to your form’s Settings → General and confirm Anti-Spam Protection is turned on. It works invisibly — bots fill the hidden field, humans never see it.
Step 2: Turn on Google reCAPTCHA or hCaptcha
Under WPForms → Settings → CAPTCHA, you can connect Google reCAPTCHA (v2 checkbox, v2 invisible, or v3) or hCaptcha as a privacy-friendlier option. v3 is generally the best balance — it scores behavior in the background without showing users a visible challenge, which keeps your conversion rate higher than a visible checkbox.
Step 3: Use the Akismet integration (Pro plans)
If you’re on a WPForms Pro plan and already run Akismet, there’s a built-in connection under Form Settings → Akismet. It checks submissions against Akismet’s spam database, the same one used for WordPress comments. Useful as an extra layer, but it shares the same limitation as elsewhere — built for bot-pattern spam, not for judging whether a human-submitted lead is genuine.
Step 4: Add custom captcha or math captcha for low-traffic forms
For smaller forms where you don’t want to set up reCAPTCHA, WPForms has a lightweight Custom Captcha field with a simple math question. It’s not sophisticated, but it filters out the laziest bots with zero setup.
Step 5: Use Smart Logic to filter junk patterns
WPForms’ conditional logic (under the field’s settings) lets you set rules like requiring a properly formatted phone number, blocking submissions with empty message fields, or restricting certain email domains. This is manual setup, but it closes off some of the most common low-effort spam patterns.
Step 6: Handle fake leads separately from bot spam
If you’ve done all of the above and you’re still seeing submissions that pass every filter but are obviously not real prospects — especially common if you’re running Google or Meta ads to a lead form — that’s not a bot problem anymore. It’s a lead-quality problem, and it needs a tool that evaluates the content and context of each submission rather than just checking for bot signatures. AI-based tools like Spamvora score every lead in real time and can flag or block ones that look human-submitted but aren’t genuine, which matters most if you’re paying per click or per lead.
Quick setup checklist
- Honeypot field confirmed active
- reCAPTCHA v3 or hCaptcha connected
- Akismet linked (Pro plans, optional)
- Field validation tightened (phone format, email domains)
- Fake-lead scoring added if running paid traffic to the form
WPForms’ native tools are a reasonable baseline, but they’re built around stopping bots, not evaluating lead quality. If most of your spam is automated, the steps above will clear the bulk of it. If your spam looks like real people submitting junk, you need something purpose-built for that.
Want fake leads filtered automatically? Spamvora integrates with WPForms and scores every submission in real time — see how it works.