The fastest way to stop bot submissions on a contact form is Google reCAPTCHA. Get a free site key and secret key from google.com/recaptcha/admin, then drop them into your form plugin's settings. No code required for most setups. Contact Form 7, WPForms, and Gravity Forms all have a built-in reCAPTCHA integration field you enable per form.
reCAPTCHA comes in two flavors that behave very differently, and picking the wrong one is a common mistake.
v2 vs v3: which to use
reCAPTCHA v2 is the "I'm not a robot" checkbox, or the image-grid challenge if Google's risk score is uncertain. It's visible and it interrupts the user, but it's simple to set up and gives a clear pass/fail. Good default if you want obvious spam blocking with no tuning.
reCAPTCHA v3 runs invisibly in the background and returns a score from 0.0 to 1.0 instead of a checkbox. You set a threshold (commonly 0.5) below which the submission is rejected or flagged. There's no user friction, but it needs a bit more configuration. If your threshold is too strict you'll start blocking real visitors with no explanation on the form. If you go this route, log scores somewhere for the first few weeks so you can see what real traffic looks like before you tighten the threshold.
For most small business contact forms, v2 checkbox is the practical choice. It's visible enough to deter casual bots, doesn't require score tuning, and if it's blocking a real person they at least see why.
Setup in Contact Form 7
- Install the separate reCAPTCHA integration under Contact → Integration in wp-admin (CF7 doesn't bundle it in the core plugin).
- Paste your site key and secret key there.
- CF7 applies reCAPTCHA automatically to all forms once the keys are saved. You don't add a shortcode manually in most versions.
Setup in WPForms or Gravity Forms
Both plugins have a dedicated reCAPTCHA settings page (WPForms → Settings → CAPTCHA; Gravity Forms → Settings → reCAPTCHA). Enter the site key and secret key, choose v2 or v3, then add the CAPTCHA field to the specific form from the form editor. Unlike CF7, these plugins apply it per-form, not site-wide. Double check you've actually added the field if submissions are still coming from bots after setup.
If you're not using a form plugin
Custom PHP forms need to call reCAPTCHA manually. Load the client-side script:
<script src="https://www.google.com/recaptcha/api.js" async defer></script> <div class="g-recaptcha" data-sitekey="YOUR_SITE_KEY"></div>
Then on form submit, verify the token server-side before processing the mail:
$response = wp_remote_post('https://www.google.com/recaptcha/api/siteverify', [
'body' => [
'secret' => 'YOUR_SECRET_KEY',
'response' => $_POST['g-recaptcha-response'],
],
]);
$result = json_decode(wp_remote_retrieve_body($response), true);
if (empty($result['success'])) {
// reject the submission
}
Never trust the token client-side only. The checkbox rendering in the browser proves nothing by itself. The siteverify call is what actually confirms the submission with Google.
If the form still isn't reaching you after adding reCAPTCHA
reCAPTCHA only stops the submission from being accepted as spam. It doesn't fix delivery. If real submissions pass the CAPTCHA but the email never lands in your inbox, that's a separate mail delivery problem, usually WordPress's default wp_mail() getting filtered by the receiving server. See Contact form emails not arriving (WordPress SMTP fix) for the authenticated SMTP fix.
When to contact support
reCAPTCHA setup itself is on the WordPress and plugin side. If you're not sure whether a delivery issue is a reCAPTCHA misconfiguration or a server-side mail problem, open a ticket from the portal (Support → New ticket) and a real person can help you narrow it down.