Skip to content

Prevent and filter spam in form submissions

Last updated: July 20, 2026

Available with any of the following subscriptions, except where noted:

If you're receiving spam in form submissions, use spam prevention methods, such as reCAPTCHA or gibberish detection, to help reduce and filter unwanted submissions. These methods help protect the quality of your CRM data.

When spam is detected, affected submissions are listed on the spam submissions index page, where you can review and manage spam without affecting your contacts. Learn more about what happens when form submissions are marked as spam and how to manage spam submissions.

Permissions required Edit forms permissions are required to create and edit forms or edit form submission settings. 

Prevent different types of spam

Each spam prevention method protects against specific behaviors and spam types. Use the table below to identify which method to use based on the type of spam you're receiving.

Spam you're receiving Recommended method Outcome
Form settings
High volumes of automated bot submissions. reCAPTCHA Visitors who don't complete or pass the CAPTCHA can't submit the form.
Spam from free email providers (e.g., Gmail or Yahoo), disposable email addresses, or specific email domains. Block email domains or free email providers Visitors using a blocked email address or domain can't submit the form.
Account settings
Submissions containing random characters or nonsensical text. Gibberish detection Form submissions that contain gibberish may be marked as spam, depending on your form submission settings.
High volumes of known bot traffic. Bot filtering Known bot submissions are excluded from form analytics and may be marked as spam, depending on your form submission settings.
Repeated spam from known IP addresses or websites. Exclude known IP addresses or referrers Submissions from excluded IP addresses or referrers are excluded from form analytics and may be marked as spam, depending on your form submission settings.

Verify form submissions with CAPTCHA

Turn on CAPTCHA to add a verification step that helps ensure submissions are made by people, not bots. HubSpot forms use Google’s invisible reCAPTCHA v2. If Google considers a visitor suspicious, the visitor must solve a CAPTCHA challenge before submitting the form.

Please note: if CAPTCHA has been turned on in the form, form submissions from the Submit data for a form API or other form integrations will not be accepted. 

Turn on CAPTCHA in the updated form editor

  1. In your HubSpot account, click More, then navigate to Marketing > Forms. If More doesn't appear in your account, navigate to Marketing > Forms directly.

  2. Create a new form or hover over an existing form and click Edit.

  3. In the top left, click the + add icon.

  4. In the left panel, click Other.

  5. Under the Security & Privacy section, click and drag reCAPTCHA onto the form preview on the right to include this element on your form.

  6. In the top right, click Review and update.

Turn on CAPTCHA in the legacy form editor

  1. In your HubSpot account, click More, then navigate to Marketing > Forms. If More doesn't appear in your account, navigate to Marketing > Forms directly.
  2. Hover over a form and click Edit
  3. In the left panel, on the Existing properties tab, click to expand the Other form elements section.
  4. Toggle the CAPTCHA (spam prevention) switch on.
  5. In the top right, click Update or Publish

Mark form submissions from excluded traffic sources as spam

If you exclude specific IP addresses or referrer domains in your site analytics, any form submissions that come from those sources are excluded from your form analytics by default. In your form submission settings, set whether the form submissions are also marked as spam. 

To manage this setting across your forms: 

  1. In your HubSpot account, click the settings icon in the top navigation bar.

  2. In the left sidebar menu, navigate to Marketing > Forms.
  3. Click the Submissions Settings tab.
  4. Toggle the Mark form submissions from excluded IP/referrers as spam switch on or off. This setting is turned on by default. 
    • When this setting is turned on, form submissions from excluded IP addresses or referrer domains are marked as spam with the type Excluded source. New contacts aren't created from these spam submissions.
    • When this setting is turned off, form submissions from excluded IP addresses or referrer domains are captured as regular form submissions. However, these submissions are excluded from traffic analytics and workflow enrollment. 

Mark form submissions containing gibberish as spam

Subscription required A Marketing Hub or Content Hub Professional or Enterprise subscription is required to use gibberish detection in forms. 

Use AI-powered gibberish detection to identify form submissions containing random characters or nonsensical text. If gibberish is detected in a form submission's text fields, the submission is marked as spam. Sensitive Data fields are not included in gibberish detection. 

To manage gibberish detection across your forms: 

  1. In your HubSpot account, click the settings icon in the top navigation bar.

  2. In the left sidebar menu, navigate to Marketing > Forms.
  3. Click the Submissions Settings tab.
  4. Toggle the Gibberish detection switch on or off. 
    • Once this setting is turned on, new form submissions are analyzed for gibberish.
    • Existing form submissions aren't retroactively analyzed.

Manage gibberish detection for custom properties

Permissions required Edit property settings permissions are required to create or edit properties.

By default, single-line and multi-line text properties are included in gibberish detection, except for Sensitive Data properties. If you’re using custom properties in your form, you can choose whether the property is included in gibberish detection.

To manage gibberish detection for a custom property:

  1. In your HubSpot account, click the settings icon in the top navigation bar.
  2. In the left sidebar menu, under Data Management, navigate to Properties.
  3. Click the Select an object dropdown menu, then select [Object] properties to edit a property for that object.
  4. Click the name of the custom property you want to edit.
  5. In the left sidebar menu, click the Rules tab.
  6. In the Visibility options section, select or clear the Include property in Gibberish detection for form submissions checkbox.
    • Once this setting is turned on, any new form submissions using this property are analyzed for gibberish.
    • Existing form submissions aren't retroactively analyzed.
  7. In the top right, click Save.

Block specific email domains or free email providers 

Subscription required A Marketing Hub or Content Hub Starter, Professional, or Enterprise subscription is required to block specific email domains or free email providers.

Block specific email domains or free email providers to help prevent submissions from personal or disposable email addresses. These settings are configured on an individual form level. Learn more about blocking email domains in your form.

Was this article helpful?
This form is used for documentation feedback only. Learn how to get help with HubSpot.