Dabish Digital
Security

Form spam: the questions we get asked most

It comes up on almost every project, usually later than it should. The questions about form spam that come up most often on our calls.

The realistic threat for most small businesses is automated and opportunistic, not targeted. Assume whoever inherits this will have half your context and none of your patience.

Do we need to care about this?

Honeypots stop most bots without troubling humans. There is a version of this that is over-engineered, and it is worth avoiding. The version that survives contact with a real deadline is the simple one.

Can it wait until after launch?

Occasionally. More often the post-launch version costs several times the pre-launch one. The cost of getting this wrong is rarely visible on the day it happens.

How do we know it is working?

Rate limiting handles the rest. There is a version of this that is over-engineered, and it is worth avoiding. Check it against what you would want a competitor's site to get wrong.

In practice

Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about form spam before you move on:

  • Someone can say what the current setup is without going to look
  • Rate limiting handles the rest — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

If you want a second opinion on how yours is set up, ask.