How to stop form spam without a CAPTCHA
This post is part of our How to series on getting more from your htmlhost site. Every feature it mentions is documented in the docs.
Put a form on the internet and bots will find it. The usual fix, a CAPTCHA, makes real visitors click traffic lights, and some of them give up. On htmlhost, every delivered form is protected without one.
What happens behind the scenes
- A honeypot. Each form carries a hidden field people never see but form-filling bots do. Anything that fills it in is quietly discarded.
- A fill-time check. A human takes a few seconds to fill in a form; a bot takes milliseconds. Submissions that arrive impossibly fast go to Spam, and nobody is emailed about them.
- Rate limits. Each visitor can send 5 messages per site every 10 minutes, and 20 per hour across all sites.
- Same-site only. Your form can only be sent from your own site, so spammers can't post to it from elsewhere.
Protection for your visitors, too
Forms that ask for passwords, card numbers or similar details are refused. This stops anyone from using a site hosted here to trick people into handing over sensitive information.
When something slips through
On your site's Messages tab, select the message and click Mark spam. The Spam filter keeps suspected spam out of your inbox, and it's cleared automatically after 30 days. If a real message ends up there, click Not spam.
If a burst of spam is flooding your email, switch Email notifications to Paused or Daily summary in the Forms tab while it passes. Messages are still saved.
Do I need to do anything?
No. Every form from the Library, forms the AI writes, and any form you connect with Send to my inbox gets this protection automatically. If you hand-code a form, the fill-time check and rate limits still apply, and the docs show the one hidden field to add for the honeypot.
Ready to try it yourself?
Paste HTML, get a link. Deploy your site in under 3 seconds — no config, no build step.
Start hosting