Spam protection is on for every form and every plan. Submissions pass through several layers; anything that looks like spam is stored in the form's Spam folder and doesn't count toward your monthly quota or trigger emails and integrations.
Layers
Honeypot
A hidden field (default name _gotcha) that people never see but naive bots fill in. Any value → the submission is discarded silently.
<input type="text" name="_gotcha" style="display:none" tabindex="-1" autocomplete="off">You can rename the honeypot field in form settings if a bot learns the default name.
Time-to-submit
If your form sends _ts (the timestamp when the page rendered), submissions arriving faster than your threshold (default 2 seconds) are scored as likely spam. All JavaScript snippets from the form generator include it.
Content heuristics
We score link density, HTML/BBCode links, well-known spam phrases, URLs in name fields, mostly-uppercase text, empty submissions and long runs of foreign script combined with links.
Your blocked keywords
Add words or phrases in settings; any match marks the submission as spam.
Duplicates and rate limiting
Identical submissions to the same form within 10 minutes are flagged. Each IP can submit up to 20 times per minute per form; each form accepts up to 600 per minute.
Sensitivity
Each form has a sensitivity setting that controls how high the combined score must be:
| Sensitivity | Threshold | Use when |
|---|---|---|
| Low | 0.9 | You rarely get spam and false positives would be costly |
| Medium (default) | 0.7 | Most sites |
| High | 0.5 | Your form is heavily targeted |
Need more?
- Add a captcha — reCAPTCHA, hCaptcha or Turnstile with your own keys.
- Restrict submissions to your site with the domain allowlist.
Read the full playbook in how to stop form spam.