Five mistakes teams make with form spam
The gap between knowing this and actually doing it is where most teams lose ground. These are the ones we run into repeatedly when we audit form spam.
The realistic threat for most small businesses is automated and opportunistic, not targeted. The version that survives contact with a real deadline is the simple one.
Where it usually goes wrong
- Treating it as a launch task rather than an ongoing one
- Assuming someone else already owns it
- Honeypots stop most bots without troubling humans
- CAPTCHAs cost real conversions
- Never checking whether the fix actually worked
Rate limiting handles the rest. The cost of getting this wrong is rarely visible on the day it happens. It is the sort of thing that looks like polish right up until it costs you an enquiry.
What to do next
What this looks like day to day
Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about form spam before you move on:
- Someone can say what the current setup is without going to look
- CAPTCHAs cost real conversions — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Pick the one that would hurt most if it failed, and start there.