# Spam protection

> How SiteBackend keeps spam out - honeypot, content filter, rate limiting, and optional Cloudflare Turnstile, hCaptcha or reCAPTCHA.

Source: https://sitebackend.com/docs/forms/spam-protection · Updated: 2026-10-03

Every form has several layers of spam protection. The first three are on by default.

| Layer          | Default                          | What happens when it triggers                      |
| -------------- | -------------------------------- | -------------------------------------------------- |
| Honeypot field | On (`_gotcha`)                   | Stored in **Spam**; visitor sees a normal success. |
| Rate limit     | On (5/min per visitor, per form) | Rejected with `429`.                               |
| Content filter | On                               | Stored in **Spam**; visitor sees a normal success. |
| Captcha        | Off                              | Rejected with `400 Captcha verification failed`.   |

## How do I add a honeypot?

Add a hidden field named `_gotcha`. People never see it, but many bots fill in every field.

```html
<input type="text" name="_gotcha" tabindex="-1" autocomplete="off" style="display:none" />
```

You can rename it in **Form → Settings → Spam protection → Honeypot field**. The name always starts with `_`, and SiteBackend adds it if you leave it out (`website` is saved as `_website`). Fields starting with `_` are never stored with the submission.

## What does the content filter look for?

It scores each submission on signals common in spam: many links, link markup such as `[url=` or `<a href=`, and well-known spam phrases. Submissions above the threshold go to the **Spam** folder instead of your inbox, and don't trigger notifications. Turn it off in **Form → Settings → Spam protection** if it catches real messages.

## How do I add a captcha?

SiteBackend verifies Cloudflare Turnstile, hCaptcha and Google reCAPTCHA tokens.

### Add the widget to your form

Follow your provider's instructions to add their widget inside your `<form>`. Each widget adds a hidden token field automatically: `cf-turnstile-response`, `h-captcha-response` or `g-recaptcha-response`.

### Add your secret key in SiteBackend

In **Form → Settings → Spam protection**, choose the provider under **Captcha** and paste your **secret key**. It's stored encrypted and never shown again.

### Test it

Submit the form. Without a valid token, the submission is rejected with `Captcha verification failed`.

## Where does caught spam go?

Honeypot and content-filter catches are kept in the form's **Spam** folder, in case something real was caught. Mark it **Not spam** to move it to the inbox. Spam never counts toward your monthly limit and never sends notifications.

## Are testimonials protected too?

Yes. The testimonial collect form has its own hidden honeypot field and accepts at most 3 testimonials a minute from the same visitor. It doesn't support captchas. Nothing reaches your website without your approval anyway, unless you turn on auto-approve. See [collecting testimonials](https://sitebackend.com/docs/testimonials/collecting).
