Spam protection

How SiteBackend keeps spam out - honeypot, content filter, rate limiting, and optional Cloudflare Turnstile, hCaptcha or reCAPTCHA.

2 minUpdated

Every form has several layers of spam protection. The first three are on by default.

LayerDefaultWhat happens when it triggers
Honeypot fieldOn (_gotcha)Stored in Spam; visitor sees a normal success.
Rate limitOn (5/min per visitor, per form)Rejected with 429.
Content filterOnStored in Spam; visitor sees a normal success.
CaptchaOffRejected with 400 Captcha verification failed.

How do I add a honeypot?

Add a hidden field named _gotcha. People never see it, but many bots fill in every field.

<input type="text" name="_gotcha" tabindex="-1" autocomplete="off" style="display:none" />

You can rename it in Form → Settings → Spam protection → Honeypot field. The name always starts with _, and SiteBackend adds it if you leave it out (website is saved as _website). Fields starting with _ are never stored with the submission.

What does the content filter look for?

It scores each submission on signals common in spam: many links, link markup such as [url= or <a href=, and well-known spam phrases. Submissions above the threshold go to the Spam folder instead of your inbox, and don't trigger notifications. Turn it off in Form → Settings → Spam protection if it catches real messages.

How do I add a captcha?

SiteBackend verifies Cloudflare Turnstile, hCaptcha and Google reCAPTCHA tokens.

Add the widget to your form

Follow your provider's instructions to add their widget inside your <form>. Each widget adds a hidden token field automatically: cf-turnstile-response, h-captcha-response or g-recaptcha-response.

Add your secret key in SiteBackend

In Form → Settings → Spam protection, choose the provider under Captcha and paste your secret key. It's stored encrypted and never shown again.

Test it

Submit the form. Without a valid token, the submission is rejected with Captcha verification failed.

Where does caught spam go?

Honeypot and content-filter catches are kept in the form's Spam folder, in case something real was caught. Mark it Not spam to move it to the inbox. Spam never counts toward your monthly limit and never sends notifications.

Are testimonials protected too?

Yes. The testimonial collect form has its own hidden honeypot field and accepts at most 3 testimonials a minute from the same visitor. It doesn't support captchas. Nothing reaches your website without your approval anyway, unless you turn on auto-approve. See collecting testimonials.