Stopping form spam works best in layers: captcha catches automated bots, password protection and closing rules shrink the window of exposure, and disciplined notification handling keeps whatever slips through from wasting your time. No single defense is perfect, and the stack matters because each layer blocks a different kind of junk.
Why your form gets spammed at all
Spam arrives because forms are open endpoints. Bots crawl the web for form URLs and submit them automatically, selling links, seeding scams, or probing for weak inboxes. Human spam farms hit forms with visible outcomes, like comments or testimonials. Once a URL lands on a bot list, submissions arrive daily unless something on the form resists.
- Automated bots that submit every open form they find, day and night.
- Scrapers probing fields for answers they can resell.
- Link sellers hoping a submission appears somewhere public.
- Low-paid or scripted workers targeting forms with visible results.
The defense stack, in order
| Defense | What it stops | Cost to real users |
|---|---|---|
| Captcha | Most automated bots | A checkbox or challenge before submitting |
| Password protection | All strangers, bots included | The form needs a shared password |
| Closing dates and submission limits | Late spam after your deadline | None, if set to match your real schedule |
| Smaller exposure | Discovery by crawlers in the first place | None |
| Notification discipline | Nothing incoming; protects your attention | None |
Setting up captcha properly
- 1
Turn it on in form settings
In SharaForms, enable captcha from the form configuration and save; public submissions now require the check.
- 2
Test as a stranger
Open the public form in a private browser window and confirm the widget appears and submits while logged out.
- 3
Watch for friction complaints
If real respondents mention the challenge, that signal beats any bot statistic; adjust rather than lose them.
- 4
Keep it on, even during quiet months
Spam returns the week protection lapses, usually in bulk.
When captcha is not enough
Targeted human spam ignores captcha. For private forms, password protection removes the public URL entirely, which suits internal requests, client intake, and anything sent to a known list. For public forms, closing the form after its real deadline and setting a submission limit both cap how much junk a long-running campaign can attract.
- Password protection for forms meant for one team, class, or client list.
- Closing dates for events, applications, and anything with a real deadline.
- Submission limits so a burst of junk cannot exceed what you will ever process.
- Turn off public indexing for forms that do not need search traffic.
Keep the junk from wasting your time
- Scan notifications before opening each submission; bot entries share patterns, like mismatched names and links.
- Delete junk in batches before exporting, so CSVs and reports stay clean.
- Watch analytics for impossible spikes; a thousand views with zero quality means protection failed somewhere.
- Never reply to spam submissions, even to complain; replies confirm a live human behind the address.
Templates to start from
Frequently asked questions
- Do captchas stop all form spam?
- No. Captcha stops most automated bots, which are the bulk of the volume, but determined human spammers and advanced bot farms sometimes pass. Treat captcha as the first layer, then add password protection or closing rules based on who genuinely needs access. Layered defenses decline gracefully when one layer is bypassed.
- How do I stop spam without a captcha?
- Shrink exposure instead: password-protect the form for known audiences, close it after the real deadline, cap submissions, and turn off public indexing if search traffic does not matter. Review notifications in batches and delete junk before exporting. This combination handles quiet forms well, though very public forms almost always need captcha eventually.
- Why did my form suddenly get spammed?
- A bot crawler found your form URL, usually from a public link, an embed, or the sitemap, and added it to a submission list that fires daily. Volume then grows in bursts rather than trickles. The response is the same regardless of trigger: enable captcha, review exposure settings, and clean existing junk from your data.
- Can I close a form automatically?
- Yes. SharaForms supports closing dates and submission limits in form settings, so a form stops accepting responses on the date you choose or once the cap is reached. Both settings also starve late spam campaigns, since closed forms reject everything, and respondents see a clear closed message instead of a broken page.
Put this to work on a real form
Free plan, unlimited forms and submissions, all three presentation modes included.

