Submissions and FlowSpam protection

Spam protection

Copy page

How Workflow Forms filters spam: an invisible trap field, a minimum fill time, a limit per visitor and blocked email domains.

Every form comes with spam checks that need no setup. They stop most automated submissions, but no filter catches everything: treat spam protection as best effort.

What is built in

  • An invisible trap field. Every form has a field visitors do not see. A bot that fills in every input fills this one too and gives itself away.
  • A minimum fill time. A submission sent faster than 2 seconds after the form loaded is refused. The time is signed by our server, so it cannot be faked by the page.
  • A limit per visitor. One visitor can only send the same form a few times in a short period. After that they see "Too many attempts. Please wait a moment and try again."
  • Server-side checks. Every submission is validated on our server, not in the browser: required fields, formats, lengths, patterns and conditions. Nothing the browser claims is trusted.

A submission caught by the trap field or the fill time gets the same answer as a successful one, so a bot learns nothing. It is not stored, does not count toward your plan and does not start the Form submitted trigger.

Blocked email domains

Open Settings, tab Spam protection, and enter the domains you do not accept under Blocked email domains:

  • One domain per line, for example mailinator.com. Subdomains are blocked too.
  • Up to 500 domains.
  • The visitor sees that the address cannot be used ("This email address cannot be used here.") and can enter another one.

The list applies to every form of your shop.

See what is refused

Refused submissions are not stored. They start the Form submission rejected trigger in Shopify Flow, at most once per form and reason every 5 minutes, with the reason (validation, spam, rate_limit or quota) and no submitted values. Build a workflow on it if you want to be told when a form is under attack. See Shopify Flow triggers.

What it does not do

  • There is no CAPTCHA.
  • A person who fills in the form by hand with nonsense is not stopped by these checks. Blocked email domains and required fields with validation help there.
  • Visitors who fill in a very short form in under 2 seconds (for example with a password manager) can be treated as a bot. This is rare for forms with more than one field.

Spam that got through

Delete it in Submissions, one by one or with a bulk action. If it keeps coming from the same email domain, block the domain. If one of your workflows sends email on every submission, consider adding a condition there too.

Next steps