Protect Your Website from Spam Attacks

Lewis Elliott

16 October 2025

Spam farms are networks of low-paid human operators designed to bypass traditional anti-spam measures. They often work around common defences by employing humans to solve anti-spam tests at scale. The goal is to flood contact forms with submissions, either to promote content, harvest data or to test for vulnerabilities.

The scale of these operations can be astonishing. In an article with UN News, Benedikt Hofmann, a United Nations Office on Drugs and Crime (UNODC) official, described after visiting a scam farm in the Philippines:

“The scale and sophistication of the compound is surprising. This does not look very different from a well-established tech company. Some 700 people were discovered on this compound when it was raided in March, and that’s not as many as other compounds we know about.”

Contact form spam is not just a minor nuisance; it can be part of a large, organised and well-resourced criminal operation. Spam farms can overwhelm websites, bypass traditional anti-spam measures and could pose broader security risks if left unchecked.

What damage can contact form spam do to my business?

Spam farms are not just a nuisance; they pose a serious threat to your business.

These contact form submissions can contain malicious links or code that puts your website and customer data at risk.

Phishing via contact form enquiries can happen when attackers submit messages designed to trick you or your staff into revealing sensitive information, clicking on malicious links or downloading harmful attachments. These submissions can look legitimate at first glance, mimicking real enquiries with professional-sounding requests or urgent calls for action. Even automated bots and artificial intelligence can be programmed to generate convincing phishing messages, making them harder to detect.

Employees who don’t recognise a phishing attempt might inadvertently expose credentials, financial data or client information. Both spam farms and sophisticated bots can coordinate phishing campaigns at scale, highlighting that no business, large or small, is immune. The result is not just wasted time but serious security risks and potential reputational damage.

Furthermore, by flooding contact forms with fake inquiries, you may not be able to find genuine leads under mountains of spam, making it easy to miss important messages from real customers.

This not only slows down your response time but can also cost you sales and damage your reputation. Imagine a potential client reaching out, only for their message to get lost in a flood of automated submissions? Experience tells us that every missed enquiry is a missed opportunity.

How can I prevent becoming a victim?

Spam farms and automated bots are persistent. Teams are working flat-out to create ways of accessing your website contact form as we speak. While it is an ongoing battle, experience tells us that there are practical ways to protect your website and ensure genuine enquiries get through.

These are the four strategies we have found most useful in reducing this spam:

More mandatory contact form fields

Adding more required fields to your contact form can deter spam from automated bots because simple forms with only a name and email are easy targets and are far easier to program. Forms that ask for additional details, such as a budget or company name, require more effort and human thinking. Multi-step forms can take this further by splitting questions into multiple stages, which discourages both bots and manual spammers who want to submit everything quickly.

“Honeypot traps” and hidden fields

Honeypot traps are invisible form fields designed to trap bots. Humans never see them, but automated bots fill in every field they find. Submissions containing data in these hidden fields can be flagged as spam and discarded automatically. This method works quietly behind the scenes without interrupting the user experience and is a simple yet highly effective way to block both automated bots.

CAPTCHA tests

CAPTCHA stands for 'Completely Automated Public Turing test to tell Computers and Humans Apart'.

It has long been a key tool for stopping automated spam on contact forms, requiring users to prove they’re human before submitting. Traditional CAPTCHAs, like distorted text or image puzzles, often annoyed real users so many avoided submitting an online enquiry.

Modern solutions such as Google reCAPTCHA v3 work quietly in the background by analysing user behaviour to detect bots without interrupting the experience. For websites that prefer alternatives, invisible CAPTCHAs or simple challenge questions like a basic math problem can also be effective, providing an extra layer of protection against both automated bots and spam farms, while keeping forms user-friendly.

Location blocking and geofencing

Geo-restrictions allow you to limit access to your contact forms based on the user’s location. If your business only serves a specific country or region, you can prevent submissions from outside your target area. For example, if your business only offers financial advice to people in the UK, this geofencing would mean that only viewers with a UK IP address can access your website.

While reducing spam from regions commonly associated with automated bots and spam farm operations, this can improve the quality of leads by preventing viewers from outside the geofence from accessing your website.