← Back to Blog
WordPressContact Form 7SpamBot Protection

Reducing spam in Contact Form 7 the targeted way

Marc Wagner·October 5, 2026·6 min read

Which problem do you have?

Three cases look alike but have different causes:

  • Spam arrives. Your inbox fills up with ads, links or meaningless text. The form lets bots through.
  • The form reports an error. Visitors see “There was an error trying to send your message. Please try again later.” (translated on sites in other languages). That can be spam protection or a problem with sending mail.
  • Genuine enquiries are missing. Nobody complains, but nothing arrives either. Then protection may be rejecting people, or the mails do not reach your inbox.

Identify the case first, before you add protection. How to do that is described in the section “Mail delivery or bot protection?”.

What Contact Form 7 brings itself

Contact Form 7 has several measures against spam built in (checked on version 6.1.7):

  • Disallowed list. CF7 checks every submission against the list under “Settings → Discussion” (“Disallowed Comment Keys”). A match counts as spam. This helps against recurring words and domains, not against new texts.
  • Quiz field. With the tag [quiz] the form asks a question you define yourself. Bots that fill in any form fail; bots that target your site specifically do not.
  • Akismet. With the Akismet plugin and an Akismet key, CF7 checks name, email address and text through the Akismet service.
  • reCAPTCHA v3. CF7 loads the script from Google and rejects submissions below a score threshold.
  • Cloudflare Turnstile. CF7 integrates Turnstile; the script comes from Cloudflare.

The disallowed list and the quiz work without an outside service. Akismet, reCAPTCHA and Turnstile send your visitors' data to the respective provider, and that belongs in your privacy policy.

When additional bot protection makes sense

Dedicated bot protection is worth it if

  • spam keeps arriving despite the disallowed list and the quiz,
  • you do not want to load scripts from Google or Cloudflare,
  • you want to see for every rejected submission why it was rejected.

If the quiz is enough for your form, you need nothing more. Protection nobody needs is just one more source of errors.

Setting up SilentShield for Contact Form 7

The official plugin “SilentShield – Captcha & Anti-Spam” protects Contact Form 7 without code of your own. We have tested it with Contact Form 7 6.1.7 and WordPress 7.0.

  1. Install and activate the plugin from the WordPress directory.
  2. Under “SilentShield → API / SilentShield”, enter your key, click “Validate”, switch on “Activate API” and save.
  3. Under “SilentShield → Forms”, switch on Contact Form 7.

The site must run over https, otherwise the form cannot be submitted. All steps and the tested form plugins are in the WordPress guide. Every submission counts towards the quota, see prices and quotas.

Testing genuine submissions and failed attempts

A genuine submission: Open the page in a private window, fill in the form by hand and submit it. Expect CF7's confirmation with a green border.

A failed attempt: Send the same form without a browser to the CF7 interface. You find the form ID and the value for _wpcf7_unit_tag in the page source, in the form's hidden fields.

curl -X POST "https://example.com/?rest_route=/contact-form-7/v1/contact-forms/123/feedback" \
  -F "_wpcf7=123" -F "_wpcf7_unit_tag=wpcf7-f123-p45-o1" -F "_wpcf7_container_post=45" \
  -F "your-name=Test" -F "[email protected]" -F "your-message=Test"

Expect a response with "status":"spam". With SilentShield the message reads “Behavior check”.

Mail delivery or bot protection?

In Contact Form 7, “spam” and “the mail could not be sent” have the same default text. You can tell them apart in two places:

  • Border colour of the message: orange means spam, red means sending the mail failed, as long as your theme does not override CF7's colours.
  • Response in the browser: In the developer tools (Network tab) the response to feedback contains the status, either spam or mail_failed.

If it is mail_failed, the bot protection let the submission through; the problem lies with WordPress sending mail. Then check the mail settings, for example with an SMTP plugin. If it is spam, a protection measure rejected it. With SilentShield the message names the reason, such as “Behavior check”.

Limits

  • No protection keeps out spam that a person writes by hand.
  • Without JavaScript in the browser, a submission to a protected form is rejected.
  • SilentShield protects forms against bots. It does not replace a web application firewall or DDoS protection.

Set up form protection

Related pages

Ready to ditch CAPTCHA?

Start protecting your forms — invisibly. No credit card required.