Skip to content
FormSubmit
Spam & Security

Honeypot vs Captcha: Which Form Spam Protection Should You Use?

Honeypot vs captcha compared: how each stops form spam, the accessibility, UX and privacy tradeoffs, working honeypot code, and when to add Turnstile.

FormSubmit Team

5 min read

A hidden honeypot field beside a captcha challenge, both protecting a web form from spam

In the honeypot vs captcha debate, a honeypot is the better default: it is invisible to people, has no accessibility or privacy cost, and stops most automated spam. Add a captcha such as Cloudflare Turnstile, hCaptcha or reCAPTCHA only when spam keeps getting through. The strongest form spam protection layers several cheap checks before asking humans to prove anything.

Below we compare the two approaches, show a honeypot implementation that avoids common mistakes, and explain when a captcha earns its place.

How a honeypot field works

A honeypot is a form field that humans cannot see but bots can. Simple spam bots parse the HTML, find every input and fill each one with something. A real visitor never touches the hidden field, so any submission where it has a value is almost certainly automated and can be dropped.

The key detail: the server should drop the submission silently and still return a success response. If the bot sees an error, its operator learns which field to skip.

How a captcha works

A captcha asks the browser, and sometimes the person, to prove it is human. Modern versions come in a few flavors:

  • reCAPTCHA v2 (checkbox): the "I'm not a robot" box, with an image challenge when the risk looks high.
  • reCAPTCHA v3 (invisible): no widget; it returns a score, and your server decides what score is acceptable.
  • hCaptcha: a challenge-based widget similar in spirit to reCAPTCHA v2.
  • Cloudflare Turnstile: a widget designed to verify most visitors without a puzzle, often chosen as a reCAPTCHA alternative.

In every case, the widget produces a token that gets submitted with the form, and the server must verify that token with the provider using a secret key. A captcha that is only checked in the browser offers no protection.

Honeypot vs captcha: the tradeoffs

HoneypotCaptcha
Visible to usersNoSometimes (checkbox, puzzle)
Accessibility impactNone when hidden correctlyChallenges can be hard for screen reader and keyboard users
PrivacyNo third partyLoads a third-party script and shares signals with the provider
Page weightZeroExtra JavaScript
Stops simple botsYesYes
Stops targeted botsOften notMore often
SetupOne hidden input plus a server checkAccount, keys, widget, server verification
False positivesRare (autofill edge cases)Possible, especially with strict score thresholds

The pattern is clear: honeypots are nearly free, captchas are stronger but cost friction. Accessibility deserves special weight; a challenge that a blind visitor cannot complete means a lost lead. See accessible forms for more on this.

How to implement a honeypot correctly

Most broken honeypots fail for one of two reasons: the field is hidden in a way that leaves it visible to some users, or autofill fills it in. This version avoids both:

html
<form action="https://formsubmit.app/f/YOUR_FORM_ID" method="POST">
  <label for="email">Email</label>
  <input id="email" type="email" name="email" required>

  <label for="message">Message</label>
  <textarea id="message" name="message" required></textarea>

  <input type="text" name="_gotcha" tabindex="-1" autocomplete="off"
         style="display:none" aria-hidden="true">

  <button type="submit">Send</button>
</form>

Why each attribute matters:

  • style="display:none" hides the field from sighted users and screen readers alike.
  • tabindex="-1" keeps keyboard users from tabbing into it if your CSS ever changes.
  • autocomplete="off" and a name like _gotcha (not email2 or phone) discourage autofill and password managers from populating it.
  • aria-hidden="true" is a belt-and-braces signal to assistive technology.

If you handle submissions yourself, the server check is a few lines:

js
export async function POST(request) {
  const data = await request.formData();
  if (data.get("_gotcha")) {
    return Response.json({ ok: true, id: "ignored" });
  }
  // continue processing real submissions
}

Note that it returns success, not an error.

Add a time trap

A time trap is a second invisible check. Record when the form was rendered and reject submissions that arrive impossibly fast, since bots often submit within milliseconds of loading the page.

html
<input type="hidden" name="_ts" id="ts">
<script>
  document.getElementById("ts").value = Date.now();
</script>

On the server, compare the current time with _ts. A threshold of around two seconds catches most bots without affecting people. Treat a fast submission as likely spam rather than an absolute block, because some legitimate users paste content quickly or use autofill for every field.

Layered form spam protection

Neither a honeypot nor a captcha should be your only line of defense. A practical stack, from cheapest to most intrusive:

  1. Honeypot field to drop naive bots silently.
  2. Time trap to flag instant submissions.
  3. Content heuristics such as many links, HTML or BBCode in a message, URLs in a name field, or known spam phrases.
  4. Rate limiting per IP so one source cannot flood your form.
  5. Duplicate detection for identical submissions in a short window.
  6. Domain allowlist so your endpoint only accepts posts from your own site.
  7. Captcha only if the first six are not enough.

Our stop form spam guide walks through each layer in more depth.

When to add a captcha

Add one when:

  • Spam keeps reaching your inbox after the invisible layers are in place
  • The form triggers something costly, like sending an email to the submitter or creating accounts
  • You are being targeted by a bot that renders JavaScript

Which one to choose:

  • Cloudflare Turnstile if you want minimal friction and are open to a reCAPTCHA alternative.
  • reCAPTCHA v3 if you want no widget at all and are comfortable tuning a score threshold. Generate the token right before submit, since tokens expire.
  • reCAPTCHA v2 or hCaptcha if you prefer an explicit challenge for high-risk forms.

Whichever you pick, verify the token on the server, keep the secret key out of your frontend code, and make sure the site key is configured for your domain. Each provider documents its own privacy terms, so review them alongside your privacy obligations.

How FormSubmit handles it

FormSubmit applies the honeypot (_gotcha), a time trap (_ts), content heuristics, duplicate detection, rate limiting and an optional domain allowlist on every plan, and spam does not count toward your quota. If you need more, you can bring your own reCAPTCHA v2 or v3, hCaptcha or Turnstile keys, and tokens are verified server-side. Details are in the spam protection docs and captcha docs.

Want a form with the honeypot already wired in? Grab one from the free form generator and see what is included on each plan on the pricing page.

Last updated .

Frequently asked questions

Is a honeypot better than a captcha?

A honeypot is better for user experience because real visitors never see it, but it only stops unsophisticated bots. A captcha stops more automated spam at the cost of friction, privacy and sometimes accessibility. Most sites should start with a honeypot and add a captcha only if spam persists.

Do honeypot fields still work?

Yes, against the large share of bots that fill in every field they find. Targeted bots that render the page or skip hidden fields can get past them, which is why honeypots work best as one layer among several.

What is a good reCAPTCHA alternative?

Cloudflare Turnstile and hCaptcha are common alternatives. Turnstile is designed to verify most visitors without a puzzle, and hCaptcha offers a challenge-based approach similar to reCAPTCHA v2.

Can a honeypot block real users?

Occasionally, if browser autofill or a password manager fills the hidden field. Use display none, tabindex -1 and autocomplete off, and give the field a name that autofill will not recognize.

Related resources

Keep reading

Your form backend is 60 seconds away

Sign up with Google or email, create a form, paste the endpoint. Free forever for small sites — no credit card.