5 Ways to Protect Your Super Forms From Spam

Super Forms

You can protect Super Forms from spam in five ways: add an anti-spam plugin such as OOPSpam, enable Google reCAPTCHA v2 or v3, block duplicate entries, add a custom PHP blocklist, or block countries at Cloudflare. Layering two or three of these works best, since each catches a different type of spam. The steps for each method are below.

Method 1: Add Google reCAPTCHA v2 or v3

Super Forms includes a Google reCAPTCHA element that verifies visitors are human.

Method 1: Add Google reCAPTCHA v2 or v3

  1. Create a v2 (checkbox) or v3 key pair in the Google reCAPTCHA admin console. Add your exact domain.
  2. In WordPress, go to Super Forms > Settings, search for “captcha”, and paste your Site Key and Secret Key.
  3. Save, then add the reCAPTCHA element to your form.

v2 and v3 keys are not interchangeable. reCAPTCHA stops most bots, but it does not reliably stop a human who fills in the form by hand. 

Method 2: Block Duplicate Entries

Duplicate blocking limits repeat submissions from the same email address.

Method 2: Block Duplicate Entries

  1. Edit your form and open Form Settings.
  2. Set Save data to Save as Contact Entry.
  3. Check Enable custom entry titles and enter {email} as the value.
  4. Enable Prevent submitting form when entry title already exists.

This stops repeats from one address. It does not stop a spammer who rotates addresses.

Method 3: Install the OOPSpam Anti-Spam Plugin

OOPSpam hooks into the Super Forms submission process and filters spam automatically. Visitors never see a puzzle or checkbox.

How to set it up

In WordPress, go to Plugins > Add New, search for OOPSpam Anti-Spam, then install and activate it.

OOPSpam Anti-Spam

Create a free account at oopspam.com and copy your API key from the dashboard.

Copy your API key from the dashboard

Go to Settings > OOPSpam, paste your API key, and save.

Go to Settings > OOPSpam, paste your API key, and save.

Find the Super Forms section and check Activate Spam Protection.

Find the Super Forms section and check Activate Spam Protection.

Super Forms Spam Message

What OOPSpam can filter

OOPSpam also keeps a submission log, so you can review blocked entries and adjust settings if a real visitor gets caught.

OOPSpam submission log

Method 4: Add a Custom PHP Blocklist

Super Forms documents a super_before_processing_data hook that compares submitted values against a list you define. When a value matches, it shows the bot a fake “Thank you” message and discards the submission. The bot never learns it was blocked. See the Super Forms code example. Use this for known bad emails or phone numbers. You must maintain the list yourself.

Method 5: Block Countries at Cloudflare

If your spam comes from regions where you have no customers, block them before requests reach WordPress.

Method 5: Block Countries at Cloudflare

  1. Log into Cloudflare and select your site.
  2. Go to Security > Security rules and click Create rule.
  3. Set the field to Country, the operator to is in, and select the countries.
  4. Set the action to Block and deploy.

This is a blunt tool. Use it only when the pattern is clear and real visitors won’t be locked out.

Final thoughts

Layer your defenses. Start with OOPSpam for automatic filtering, add reCAPTCHA for bot verification, and use duplicate blocking, custom rules, or Cloudflare for specific patterns. Keep Super Forms updated to 6.3.314 or later, which patched a critical file upload vulnerability.

Spam Protection for WordPress, Zapier, Make and more.

Since our launch in 2017 we’ve been perfecting our API to be the trusted option for small businesses to enterprise— and continue to stick to our values of being the accessibility and privacy-friendly option. Give us a shot!

Try OOPSpam for free → Try our WordPress plugin for free →

✓ No credit card required ✓ Cancel anytime

Enjoy Reading This Article?

Here are some more articles you might like to read next: