Contact form protection for agencies and freelancers
When a client's inbox fills with spam, the call goes to whoever built the website. Protecting forms properly once, on every site, saves agencies and freelancers hours of support.
The short answer
Agencies and freelancers should give every client website the same baseline: invisible server-side checks (trap field, time check, one-time token, rate limit), a spam log the client can check, email sent from the client's domain, and a short handover note. This removes most spam complaints and "I didn't get the message" calls.
A standard for every client site
- Protection on every form, including pop-ups and landing pages.
- No CAPTCHA puzzles unless the client's spam log shows they are needed.
- Email through an authenticated service from the client's own domain, with SPF, DKIM and DMARC.
- A spam log the client (or you) can check.
- A privacy policy that mentions what the form collects.
- A test submission from phone and desktop before handover.
Turn it into part of your service
Clients notice spam more than almost anything else on their website. "Spam-protected forms, tested and documented" is an easy line to add to a proposal, and it cuts support time after launch.
Work with us
If you'd rather not build this for every project, we install protection on client websites (WordPress and custom PHP) under your agency's arrangement with the client. Tell us about your projects and we'll suggest how to work together.
Common questions
Can you install protection on my clients' websites?
Yes. We work with agencies and freelancers on WordPress and custom PHP websites, with the client's permission and access.
Will it change my design?
No. The protection works behind your existing forms, or we build the form in your design.
Who owns the setup?
The client. Everything is installed on their server, with no subscription to us.