A contact form should bring enquiries, not casino links, fake applications and bot messages. Many small businesses add a visible captcha immediately – and then make the form harder for real customers. A better approach is layered protection that stays invisible where possible and only becomes stricter when needed.

Bots scan websites for forms and submit advertising text, links or fake enquiries. Even small local business websites can suddenly receive dozens of spam messages per day once their form is found.
The problem is not only annoyance. Spam hides real enquiries, wastes time and can harm email deliverability when automatic replies go to fake addresses.
A honeypot is usually the best first step. It is a field that real visitors do not see and leave empty, while many bots fill it in automatically. If the field is filled, the message can be blocked or marked as spam.
Time checks and plausibility rules also help. A form submitted in two seconds or a message with many links is suspicious. The rules should be careful, because a short message such as “Please call me” can still be a real enquiry.
A visible captcha can help during a strong attack, but it should not be the first solution. Every extra step can reduce real enquiries, especially on mobile devices.
External captcha tools also need a privacy check. Some solutions transmit IP addresses, device data or behavioural signals to third parties. For German websites this should be reflected in the legal basis, consent setup and privacy policy.
Bots can bypass browser-only checks. Important rules belong on the server: required fields, email format, text length, honeypot, timestamp and spam scoring.
Rate limits reduce mass submissions from the same IP address or session. Logs can help, but they should be limited and deleted regularly.
A contact form processes personal data such as name, email, phone number and message. The privacy policy should explain purpose, fields, recipients and retention.
Data minimisation is the easiest privacy measure. Ask only for what you need for the first response. Sensitive topics such as health, legal advice or applications require extra care.
For simple websites, spam protection is often part of normal maintenance: honeypot, server validation, spam rules and SMTP delivery. External services may add cost; Google reCAPTCHA currently lists a free tier up to 10,000 assessments per month, with fees above that.
In our managed website subscriptions, form technology is usually part of the setup: Starter from 79 € per month for simple contact paths, Business from 149 € for multiple forms and clearer enquiry processes, Premium from 299 € for broader support.
Start with analysis, not the hardest captcha. Check how much spam arrives, what patterns repeat and whether automatic replies are enabled.
Then add protection in stages: honeypot, time check, link limit, server validation, rate limit and authenticated SMTP. Add a captcha only if the quieter measures are not enough.
Custom web design, German hosting, maintenance and personal support in one monthly package.
Book a free consultation