---
title: "Spam protection - Workflow Forms"
description: "How Workflow Forms filters spam: an invisible trap field, a minimum fill time, a limit per visitor and blocked email domains."
canonical: "https://docs.workflow-forms.app/spam-protection"
---

# Spam protection

Every form comes with spam checks that need no setup. They stop most automated submissions, but no filter catches everything: treat spam protection as best effort.

## What is built in

- **An invisible trap field.** Every form has a field visitors do not see. A bot that fills in every input fills this one too and gives itself away.
- **A minimum fill time.** A submission sent faster than 2 seconds after the form loaded is refused. The time is signed by our server, so it cannot be faked by the page.
- **A limit per visitor.** One visitor can only send the same form a few times in a short period. After that they see "Too many attempts. Please wait a moment and try again."
- **Server-side checks.** Every submission is validated on our server, not in the browser: required fields, formats, lengths, patterns and conditions. Nothing the browser claims is trusted.

A submission caught by the trap field or the fill time gets the same answer as a successful one, so a bot learns nothing. It is not stored, does not count toward your plan and does not start the Form submitted trigger.

## Blocked email domains

Open **Settings**, tab **Spam protection**, and enter the domains you do not accept under **Blocked email domains**:

- One domain per line, for example `mailinator.com`. Subdomains are blocked too.
- Up to 500 domains.
- The visitor sees that the address cannot be used ("This email address cannot be used here.") and can enter another one.

The list applies to every form of your shop.

## See what is refused

Refused submissions are not stored. They start the **Form submission rejected** trigger in Shopify Flow, at most once per form and reason every 5 minutes, with the reason (`validation`, `spam`, `rate_limit` or `quota`) and no submitted values. Build a workflow on it if you want to be told when a form is under attack. See [Shopify Flow triggers](https://docs.workflow-forms.app/shopify-flow-triggers.md).

## What it does not do

- There is no CAPTCHA.
- A person who fills in the form by hand with nonsense is not stopped by these checks. Blocked email domains and required fields with validation help there.
- Visitors who fill in a very short form in under 2 seconds (for example with a password manager) can be treated as a bot. This is rare for forms with more than one field.

## Spam that got through

Delete it in **Submissions**, one by one or with a bulk action. If it keeps coming from the same email domain, block the domain. If one of your workflows sends email on every submission, consider adding a condition there too.

## Next steps

- [The submissions inbox](https://docs.workflow-forms.app/submissions-inbox.md) - delete and archive submissions.
- [Shopify Flow triggers](https://docs.workflow-forms.app/shopify-flow-triggers.md) - the Form submission rejected trigger.
