Dabish Digital
Security

What to ask your agency about form spam

We end up explaining this on discovery calls often enough that it deserved writing down. If you are briefing an agency or a freelancer on form spam, these questions are worth asking early.

The cheapest security work is the boring kind done on a schedule. The practical test is whether someone new to the project could tell, in a minute, that it had been handled.

Questions worth asking

  • Who will actually do this work, and have they done it before?
  • How will we know afterwards whether it worked?
  • What happens if it needs changing in a year?
  • What are you assuming that we have not confirmed?

What a good answer sounds like

Honeypots stop most bots without troubling humans. The cost of getting this wrong is rarely visible on the day it happens. If it only works because one person remembers to do something, it does not work yet.

Rate limiting handles the rest. Where this goes wrong is almost never a lack of knowledge. The version that survives contact with a real deadline is the simple one.

How to tell if yours is fine

The realistic threat for most small businesses is automated and opportunistic, not targeted. Three things worth confirming about form spam before you move on:

  • Someone can say what the current setup is without going to look
  • CAPTCHAs cost real conversions — and you know whether that is true here
  • There is a way to tell whether the last change to this helped

If you want a second opinion on how yours is set up, ask.