Start with WordPress's built-in comment settings before installing anything. Go to Settings → Discussion and turn on comment moderation: require an admin to approve a commenter's first comment, hold comments with two or more links for review, and enable the disallowed words list. This alone stops most automated spam without adding a plugin. If it's not enough after a week or two of real traffic, add a dedicated anti-spam plugin like Akismet on top, not instead.
Configure discussion settings first
In Settings → Discussion, work through these in order:
- Before a comment appears: check "Comment must be manually approved" if your comment volume is low enough to review by hand, or "Comment author must have a previously approved comment" if you want first-timers held but repeat commenters posted instantly.
- Comment moderation: set a link threshold (2 is a reasonable default). Spam comments almost always carry multiple links to sell something; legitimate comments rarely do.
- Disallowed comment keys: a plain text list of words, IPs, or email domains. Any match sends the comment straight to trash instead of the moderation queue. Paste in known spam phrases as you spot them in your queue.
- Other comment settings: require name and email, and consider closing comments automatically on posts older than a set number of days. Old posts attract disproportionate spam because nobody's watching them.
These settings live in core WordPress, so they work regardless of theme or hosting.
Moderate from the block editor
Comments show up under Comments in the left admin sidebar, not inside the block editor itself, but you'll get there from the same admin screens you use to edit posts. Each comment has Approve, Reply, Edit, Spam, and Trash links. Marking a comment "Spam" instead of "Trash" matters: Spam teaches the built-in filter and (if installed) Akismet what to catch next time, while Trash deletes it without feeding the model. Check the comment queue a few times a week rather than letting it pile up. A large backlog is where legitimate comments get missed and buried in noise.
Add Akismet when built-in moderation isn't enough
If spam is still getting through after tightening Discussion settings, install the Akismet plugin from Plugins → Add New, search "Akismet Anti-Spam". It needs an API key (a free key is available for personal sites; commercial sites need a paid key), which you enter on its settings page after activation. Akismet checks every incoming comment against a spam database in real time and files matches into a separate Spam folder under Comments, keeping them out of your moderation queue entirely. It's a widely used solution for this specific problem, since it doesn't rely on link-counting or keyword-matching alone.
Before adding any anti-spam plugin, weigh it against what else is already running. If your site running WordPress is already feeling sluggish, work through My WordPress site is slow first. Comment-related plugins are rarely the bottleneck, but every active plugin adds some overhead.
Test changes on staging first
If you're changing comment behavior on a store or a high-traffic site, for example switching from open comments to manual approval, or installing a new anti-spam plugin, test it on a staging copy first. You want to confirm real comment forms still submit correctly and legitimate comments aren't getting caught by an overly aggressive link threshold. See Using WordPress staging for the safe workflow. This matters even more on a WooCommerce store, where product review comments are a form of customer feedback you don't want silently dropped.
If a bad change locks up comments
An overly strict disallowed-words list or a misconfigured plugin can occasionally block comments you actually want. If you need to roll back a change and don't remember exactly what you edited, restoring from a recent backup is often faster than hunting through settings.
When to contact support
If comment spam volume looks like an automated attack, hundreds of submissions in a short window rather than the usual trickle, or if Akismet itself seems to be misbehaving after an update, open a ticket from Support → New ticket in the portal.