How to Block Countries in Super Forms?

Super Forms does not list a built-in country blocking setting in its documentation. To block form submissions by country, use the OOPSpam Anti-Spam plugin, which filters Super Forms entries by country from your WordPress dashboard. To block visitors from your entire site, add a Cloudflare security rule. Combine both for layered protection. Neither method is fully accurate, because VPNs and proxies can hide a visitor’s real location.

Method 1: Use OOPSpam for Form-Level Country Filtering

OOPSpam checks each Super Forms submission and rejects it if it comes from a country you block. Your site stays visible to visitors worldwide. Only form submissions are filtered.

How to set it up

In WordPress, go to Plugins > Add New, search for OOPSpam Anti-Spam, then install and activate it.

OOPSpam Anti-Spam

Create a free account at oopspam.com and copy your API key from the dashboard.

Create a free account at oopspam.com and copy your API key from the dashboard.

Open the OOPSpam settings in WordPress, paste your API key in the General tab, and save.

Open the OOPSpam settings in WordPress, paste your API key in the General tab, and save.

Find the Super Forms section and check Activate Spam Protection.

Find the Super Forms section and check Activate Spam Protection.

Set up Country Filtering and choose one approach:

Set up Country Filtering and choose one approach

Optional: edit Super Forms Spam Message to explain the block, for example “We’re unable to process submissions from your region. Please contact [email protected].”

Super Forms Spam Message

Save your settings.

Test the form in an Incognito window. Then check the OOPSpam spam and ham logs to confirm what was blocked.

OOPSpam spam and ham logs

Which country setting should you use?

Setting Use it when
Country Blocklist Spam comes from a few known regions and you accept everyone else
Country Allowlist Your customers are in a few countries and you want a strict rule
Trusted Countries You want your home market to bypass all checks

Add more filters

Method 2: Block Countries at the Edge With Cloudflare

Cloudflare blocks requests by country before they reach WordPress. This blocks visitors from the whole site, not just the form. Use it for region-limited businesses or high-volume attacks.

Method 2: Block Countries at the Edge With Cloudflare

  1. Log into your Cloudflare dashboard and select your site.
  2. Go to Security > Security rules.
  3. Click Create rule and name it “Block Countries.”
  4. Set the field to Country, the operator to is in, and select the countries.
  5. Set the action to Block and save.

What to Know Before You Block

Final thoughts

Super Forms has no native country filter, so use an external tool. OOPSpam is the most direct option because it filters at the form level and leaves your site open. Add Cloudflare if you need a hard block across the whole site.

Spam Protection for WordPress, Zapier, Make and more.

Since our launch in 2017 we’ve been perfecting our API to be the trusted option for small businesses to enterprise— and continue to stick to our values of being the accessibility and privacy-friendly option. Give us a shot!

Try OOPSpam for free → Try our WordPress plugin for free →

✓ No credit card required ✓ Cancel anytime

Enjoy Reading This Article?

Here are some more articles you might like to read next: