Skip to main content
.com domains from $2.99 — WHOIS privacy at no extra charge

How-to · Beginner · 30 minutes

How to Protect Forms From Spam

Stop the bot flood without making real customers prove themselves first — a practical, jargon-free walkthrough with the classic mistake flagged before you make it.

Straight answer first

The job: stop the bot flood without making real customers prove themselves first. Time to allow: 30 minutes. Skill needed: beginner.

Below you get the exact steps, the classic snag, and a tip from the support desk. Where our platform handles a step for you, the guide says so rather than making you do the robot's work.

Written by the Hosting Seller staff · Checked 1 August 2026

Beginner

Difficulty level

30 minutes

Time to allow

5

Stages

24/7

Help at any hour

This guide assumes no expertise at all — just a hosting account, a browser and 30 minutes of attention. Every instruction works on our platform exactly as written, and carries over to any standard cPanel host.

Rule of the road: read the snag section before you begin rather than after. It is harvested from the tickets of people who did it the other way round.

The overview before the detail

From start to finish, you will set a honeypot first, check how fast the form was filled, reach for a modern captcha only if needed, filter the obvious spam text and store every entry as well as emailing.

No stage needs code or a terminal unless the guide says so outright, and where it does, the exact commands are printed. The full step-by-step sits below; the sections around it give the context that makes it stick.

The mistake nearly everyone makes

Opening with a hard visible CAPTCHA. At the margins the puzzle turns away measurably more people than bots, trading real enquiries for spam that a honeypot would have caught without anybody noticing it happen.

Forewarned really is forearmed here. This one mistake accounts for most of the frustration the subject produces, and it is entirely avoidable once somebody names it.

The trick worth borrowing

Never publish a bare mailto: address anywhere on the site. Scrapers harvest it within days, and that mailbox then carries a spam subscription for the rest of its natural life. A protected form is exactly what the public contact surface is for.

Small habits like this are the real difference between people who find hosting easy and people who find it stressful. The tools are identical; the working method is not.

The parts we have already done for you

We have automated the steps that do not deserve your time: certificates issue and reissue themselves, the installer handles application setup, the daily backup covers the what-if, and per-site settings live in a panel instead of a config file. The guide above covers what remains — the part that is actually about your site.

And when a step misbehaves anyway, support answers at any hour with the actual fix, not a knowledge-base link and a shrug. Half our best guides began life as a pattern in the ticket queue.

A shield icon standing in for site security and DDoS filtering

Why the job is simpler on our plans

Tutorials age badly when they are written against imaginary hosting. These are written against ours: the same panel, the same installer and the same defaults you will meet.

SSL comes free with every plan and reissues itself before it lapses, so nobody has to diary the padlock.

  • Step by step, tested exactly as printed
  • The snag flagged before you reach it
  • The dull steps are already automated
  • People on hand at any hour if you stall

Why Hosting Seller

On every plan, as standard

The snag, named early

The classic mistake for this exact job is flagged before step one, so 30 minutes stays 30 minutes.

Scoped honestly

Stop the bot flood without making real customers prove themselves first is a beginner-level task — this guide budgets 30 minutes and says which steps the platform absorbs.

Help on the counter

Stuck on step three at midnight? Support answers at any hour, mid-guide included.

5 steps, no filler

Each stage is a few minutes of steady clicking, with the fiddly parts marked as fiddly.

Works exactly as written

Every step tested on the platform we run — no 'your host may differ' hand-waving anywhere.

The undo is always named

Where a step could bite, the guide says so and tells you how to put it back again.

First Steps

From choosing to live

  1. 1

    Set a honeypot first

    An invisible field no human ever fills in. Bots complete everything they find and give themselves away at zero cost to real visitors. Most form plugins offer it as a single toggle.

  2. 2

    Check how fast the form was filled

    A submission completed in two seconds came from a script. A minimum-time check sweeps up the paste-and-fire bots that walk straight past the honeypot.

  3. 3

    Reach for a modern CAPTCHA only if needed

    Invisible reCAPTCHA or Turnstile scores the interaction without a puzzle. Save visible challenges for forms genuinely under siege, because every puzzle costs you real enquiries.

  4. 4

    Filter the obvious spam text

    A blocklist for the classic signatures — messages stuffed with links, the eternal keywords — trims whatever gets past the behavioural checks.

  5. 5

    Store every entry as well as emailing

    Form plugins that save submissions give you the audit trail. With entries stored, aggressive filtering can never quietly cost you a real lead without anybody noticing.

In the Box

Packed with every plan

  • Real people on the counter, every hour of every day
  • SSH, Git and Composer on the plans built for developers
  • WebP image optimisation built in and costing nothing
  • Nothing added at setup — no joining fee, ever
  • Upgrades apply to the account in place, with no move between plans
  • The renewal price printed on the tag matches the order price
  • WordPress Toolkit, with updates applied for you
  • One-click installs for WordPress and 400+ other applications
  • A domain free for year one when you order annually
  • A 99.9% uptime commitment, watched by monitoring day and night

Across the Counter

The questions we get asked most

Could this filtering turn away real customers?

Layered invisible checks — honeypot, timing, scoring — almost never do. The risk sits in aggressive content filters and hard puzzles. Stored entries are the safety net: even a wrongly filtered enquiry is sitting in the database waiting to be found.

Why did the spam go from none to hundreds overnight?

Your form's address landed on a target list. It is traffic, not a break-in. Layer the protections above and the flood drops back to a trickle within days, as the list-makers move on to easier forms elsewhere.

Does the price climb when the term is up?

No. What you pay to order is what you pay to renew, year after year. We do not run teaser rates, so there is no year-two ambush waiting in the calendar, and your bookkeeping can treat the hosting line as a fixed number.

Can I set the PHP version myself?

Yes — PHP versions are chosen per site from the control panel, so an old application and a current one can sit side by side on the same account. Extensions and per-site settings live in the same screen, and none of it needs a support ticket.

Is there a refund if it does not suit?

Yes — thirty days. Put the hosting through real work, and if it is not right, ask for the money back and you get it; there is no retention script to survive first. Domain registrations are the one carve-out, because registries take that fee the moment the name is placed.

Is the SSL certificate genuinely free?

On every plan, with nothing held back. The certificate is issued the moment your domain points here and reissues itself well before expiry. The encryption is the same as a paid DV certificate — paid tiers exist only for wildcard coverage or organisation validation, which most sites never need.

Can I bring a domain I already own?

Yes, and transfers in are routine. Unlock the name at your present registrar, collect the auth code, then start the transfer from your client area. Whatever registration time is left comes across with it, and DNS keeps answering the whole way through.

Packing up and moving host? Take our checklist.

A plain running order for a move nobody notices: what to copy first, how to carry email across without dropping a single message, when to point DNS, and the two slips behind nearly every hour of downtime we get called about.

One email carrying the checklist, then the odd note on running a site well. Step off the list whenever you like — our privacy policy spells out the rest.

Start on a plan with a plain price tag.

Free SSL, a free move in, renewals charged at the order price, and human support around the clock. That is the whole offer.

See the plans