1
0 Comments

Over the last 30 days, my form backend rejected 4,652 spam submissions. Zero of them saw a CAPTCHA.I run FormTo, an open source form backe

Over the last 30 days, FormTo blocked 4,652 spam submissions across the platform. Zero of them ever saw a CAPTCHA.

I built FormTo because I refused to ship CAPTCHA. Public studies put its hit on form conversion at 20 to 40 percent. It punishes the humans you want to keep, and modern bots solve CAPTCHA with AI for less than a cent per attempt.

So I stacked four cheap layers instead:

Honeypot fields. 19 hidden bait names like website, url, phone_number. Real users never see them. Bots fill everything. This single layer catches the large majority.

Timing check. Real users take at least three seconds to fill a form. Most bots POST within 200 ms. A hidden timestamp field rejects anything faster than 3 seconds.

Blocklist. Disposable email domains, known spam patterns in the local part, IP ranges from the StopForumSpam open API. Updates weekly.

Rate limit. 5 submissions per minute per IP per endpoint. Real users never hit it. Brute force fails fast.

The numbers from the last 30 days:

```

Spam attempts: 4,652

Blocked: 4,652 (100%)

CAPTCHA shown: 0

False positives: 4

```

The four false positives were the same person submitting twice on the same form because the success message was unclear. Fixed in the next deploy.

If you run forms anywhere, the honeypot layer alone is worth the fifteen minutes to add. The other three catch the long tail.

FormTo is open source if you want the full implementation, including the list of 19 honeypot field names: github.com/lumizone/formto.

What is your spam stack today?

posted toAvatar for product FormTo
FormTo