Table of contents
An unprotected Contact Form 7 form will eventually become a spam faucet — CF7's markup is the most recognized form pattern on the web. The durable answer is layers, cheapest first. Shot on CF7 under WordPress 7.0, August 2026.
- Start free and invisible: CF7's quiz tag or a honeypot add-on.
- Add reCAPTCHA v3 via Contact → Integration for volume spam.
- Akismet filters what sneaks through into a spam pile instead of your inbox.
- Never delete suspicious mail unseen — false positives are real leads.
Edit your form and add one line to the Form tab:
[quiz quiz-1 "What is two plus three? (digit)|5"]
Humans answer once; bots fail silently. On low-traffic sites this alone often ends the problem. Manage your forms under Contact → Contact Forms:

Contact → Integration is where CF7 connects external services:

Click Setup integration under reCAPTCHA, create v3 keys at Google's reCAPTCHA admin console for your domain, and paste the site and secret keys. Protection applies to all your CF7 forms at once — no per-form tags needed.
CF7 integrates with Akismet (the same service that guards comments). With
Akismet active and an API key set, add akismet:author, akismet:author_email
flags to your name/email fields, and suspicious submissions get flagged as
spam instead of delivered.
Submit the form normally and confirm it still works — every anti-spam layer is also a chance to block real people. If you use reCAPTCHA, watch the first week for legitimate messages that stopped arriving (privacy browsers can score poorly) and loosen if needed.
If spam continues with all layers on, it's likely humans (cheap manual spam) or a bot targeting WordPress comments instead — different doors, different locks. Check where it's actually entering before adding more form plugins.
Keep learning
- Contact Form 7 basics
- What is SMTP and why your site needs it
- WordPress contact forms — the ultimate guide



Leave a comment