How do I stop spam on Webflow forms?
Turn on Webflow spam filtering and bot blocking, then add reCAPTCHA or a honeypot without breaking real form submits.
Spam means Webflow received a submission you do not want. Start in Site settings, Apps and Integrations, Cloudflare Turnstile spam protection. Turn on spam filtering and bot blocking, then publish so bot blocking applies to every form. Add a reCAPTCHA element to every form before you turn reCAPTCHA validation on, because forms without it stop submitting. A hidden honeypot field can catch bots that fill every input.
Spam arrived. A failed form did not.
Open Site settings, then Forms, and look at the latest rows. If you see messages you did not ask for, with junk links or copied pitches, the form did submit and the problem is spam. If a real visitor reports an error and your test never appears in Forms, fix the submit path before you add filters. Filters will not repair a form that never sends.
Label the next test so you can find it, for example "spam check October 4". Send it from the published page. An unfinished canvas is not the same check.
Turn on filtering and bot blocking
Webflow documents four approaches: a CAPTCHA, bot blocking, spam filtering, and a honeypot. Start with the two site-level switches.
Go to Site settings, Apps and Integrations, Cloudflare Turnstile spam protection.
- Turn on spam filtering. It checks form data on the site and applies to every form.
- Turn on bot blocking, then publish. Bot blocking applies to every form. Webflow describes it as using signals such as mouse movement and inputs to separate bots from people, and it blocks those bot submissions.
You can use both switches together with reCAPTCHA. While bot protection is loading, submit buttons are disabled. If the button looks inactive for a moment, that can be the loading state. You can style the disabled state in the Style panel.
Example: the contact form at /contact starts receiving overnight notes that say "We ranked your site" and include a URL. Those rows are in Forms, so the form works. Turn on spam filtering and bot blocking, publish, and watch whether new junk of that shape slows down. Keep an eye on ordinary customer messages too, so you notice if real notes stop arriving.
Add reCAPTCHA without silencing real forms
reCAPTCHA v2's checkbox asks the visitor to confirm they are human. Add the element from the Add panel, Elements, Forms, and place it inside the form. It does not show on the published site until you enable reCAPTCHA validation.
Before you flip that switch, put the element on every form, including a footer newsletter and any form on a CMS template. Validation applies to the whole site. Any form without the element fails to submit. That change starts as soon as you save, even if you have not republished.
Then open Site settings, Apps and Integrations, reCAPTCHA validation. Paste the reCAPTCHA v2 site key and secret key, turn validation on, save, and publish. In Google, choose the Challenge (v2) checkbox type and register the live domain. Include the webflow.io subdomain if you test there. Registration can take up to 30 minutes. Keys are case sensitive. An invalid domain error means the host you opened is not on the key.
If the form uses a custom action, Get or Post, and submissions are collected outside Webflow, the native reCAPTCHA integration does not run. Exported sites are the same: the native integration does not run there.
Send the labeled test again. You want that test in Forms, and you want the junk pattern to drop. If the newsletter form now errors, it is missing the element. Add it and publish. That failure is the main way a spam project breaks a working form.
Add a honeypot when you want less friction
A honeypot is a field people never fill and many bots do. When the hidden field has a value, you treat the submit as spam.
Webflow's honeypot guide uses a quiet setup:
- Add a div inside the form. Name the class without the word hidden.
- Put an input in that div and give it a believable label, such as Company fax.
- Hide it with position, opacity, or display none. Bots learn, so you may need to change the hide method later.
- Set tabindex to -1 on the input so visitors do not land on it with the keyboard.
- Set aria-hidden to true on the label so screen readers skip it.
- Add a short script on that page that disables the submit button when the honeypot field contains text.
Do not rely on the honeypot alone if the form is getting heavy automated spam. Pair it with spam filtering and bot blocking. After you publish, submit the form yourself with the honeypot empty and confirm the row appears. Then fill the hidden field in a private test and confirm that path does not go through.
Review Forms after a busy day. Spam controls reduce new junk. They do not delete old rows, and they do not promise a mailbox with zero unwanted mail.
Questions & answers
Should I turn on reCAPTCHA before I add the element?
No. Add the reCAPTCHA element to every form first. Turning validation on applies to the whole site, and forms without the element fail as soon as you save.
Does bot blocking cover one form only?
No. Bot blocking applies to every form on the site. Publish after you turn it on. Submit buttons stay disabled while the protection loads.
Will spam filtering delete old junk submissions?
No. Spam filtering checks new form data. It does not remove submissions already listed in Site settings, Forms.
What if visitors can see the honeypot field?
Hide it, set tabindex to -1, and mark the label aria-hidden. If people can see or tab to a field such as Company fax, they may fill it and get blocked.
Sources & further reading
Need a hand with your Webflow site?
View membership
View membership