Contact form spam, and a website that sends spam: stopping both
Two problems share the word spam. Your form fills your inbox with junk, or your server is sending junk to other people and your real email is bouncing. One is a nuisance, the other is a security incident. Here is how to tell them apart and fix each one.
“We have a spam problem” means one of two very different things. Either your contact form delivers fifty junk messages a day, or your website is sending spam to strangers and your own email has started bouncing. The first is annoying. The second means someone is inside your server. They need different fixes, so first tell them apart.
Which one do you have?
Your inbox is full of form submissions selling SEO services, crypto, or nothing at all: form spam. Your legitimate email is landing in recipients’ spam folders, bouncing, or your host has sent a notice about outgoing mail: your site is sending spam. If you are not sure, ask your host for the outgoing mail log, or check whether your domain is on a blacklist using any of the free blacklist checkers.
Stopping form spam
Form spam comes from bots that find every form on the internet and fill it in. The defences, in order of how much they annoy real people:
- A honeypot field. A hidden field that humans never see and bots fill in. Any submission with that field filled is discarded. Invisible to real visitors, stops most dumb bots. Every decent form plugin supports it.
- A time check. A human takes at least a few seconds to fill in a form. A submission that arrives one second after the page loaded is a bot.
- Server-side validation. Reject submissions with no real email, with a message that is only links, or that arrive at a rate no human could produce from one address. Our own contact form does exactly this: honeypot, validation, and a limit of a few submissions an hour from one address.
- A modern challenge like Cloudflare Turnstile, which verifies visitors without a puzzle. Use this before reCAPTCHA, which frustrates real people and is easily solved by services that exist for the purpose.
- A spam filtering service for the submissions themselves, such as Akismet or CleanTalk, as a last layer.
What not to do: a visible puzzle as the first line of defence. It costs you real enquiries, and the bots pay people to solve it.
Stopping a site that sends spam
This one is a compromise, not a configuration problem. Somewhere on the server is a script sending mail, and it got there through a hole. Treat it as a hacked site:
- Ask the host to stop outgoing mail from the account while you work, so the damage and the blacklisting stop growing.
- Snapshot the site.
- Find the mailer script. Look for recently modified PHP files, PHP in the uploads folder, and unknown plugins. Search the file system for scripts that call mail functions from places that should not.
- Find the door. Outdated software, a weak password, an old install in a subfolder. The mailer is the symptom.
- Clean by replacement, rotate every password and the secret keys, patch everything, and follow the full cleanup order.
- Get off the blacklists. Once the sending has stopped, request delisting from each blacklist that lists you. Most clear within a day or two once they see the spam has stopped.
- Fix your own mail. Set up SPF, DKIM and DMARC records for your domain if they are missing, and send your site’s mail through a proper service rather than the web server. This is what makes your legitimate email trusted again, and it also stops others from spoofing your domain.
The one thing both have in common
Neither should be handled by the person who notices it at nine on a Monday. Form spam is a configuration you set once. Outgoing spam is a monitored condition: a daily check for changed files and a watch on your domain’s blacklist status. Both are standard parts of looking after a site, and both are quick to put right if you would like a hand.
See where your own site stands.
The scanner checks the things this guide talks about, in about ten seconds, no signup.
More from the guides
Hacked WordPress: the cleanup order that holds
Most hacked sites get cleaned twice. The first time removes what you can see. Here is the full order we use so the second time is never needed: contain, find the door, clean, rotate, patch, watch.
Is my website hacked? Twelve signs, and a five-minute check
Most hacked sites look normal to their owners for weeks. The signs show up in Google, in your inbox and on other people's phones first. Here are the twelve we check, and a five-minute routine that catches most of them.
Deceptive site ahead: what it means and the fix order
Chrome is not warning about your design. Google Safe Browsing found phishing or malware on your domain. Here is what the red screen means, how to find the cause, and how to get the flag removed without it coming back.