Elementor form spam protection
Elementor Pro's form widget is quick to design with, and its forms are easy for bots to find. A few fields in the widget stop most of the spam.
The short answer
To protect Elementor forms from spam: add a Honeypot field to every form widget, add a reCAPTCHA (v3 is invisible) field with your keys set in Elementor's settings, use a content filter integration if your version offers one, and turn on submission saving so you can review blocked entries.
Step by step for Elementor forms
- Update Elementor and Elementor Pro.
- Add a Honeypot field. Edit the form widget, add a field and choose the Honeypot type. It is hidden from visitors automatically.
- Add reCAPTCHA. Enter your reCAPTCHA keys in Elementor's integrations settings, then add a reCAPTCHA field to the form. Version 3 is invisible.
- Check integrations. Depending on your version, Elementor offers integrations (such as Akismet) that filter by content.
- Save submissions. Elementor Pro can keep form submissions in the WordPress admin so you can check what arrived.
- Repeat for every form: pop-ups, footers and landing pages each have their own widget.
Common Elementor spam problems
- Pop-up forms without protection: each pop-up is a separate form.
- Templates copied before the honeypot was added.
- Human sales spam, which honeypots and reCAPTCHA pass. Use link and keyword rules.
If bots still get through, server-side protection in front of the form stops direct submissions. See WordPress form bot protection.
Common questions
Does Elementor have spam protection?
Elementor Pro's form widget includes a Honeypot field and reCAPTCHA fields. You add them to each form.
Why do my Elementor forms still get spam?
Usually a form without the fields (often a pop-up), or human spam. Check each widget and review saved submissions.
Can I use Turnstile with Elementor?
Not as a built-in field in every version; third-party add-ons provide it. Check what your version offers before adding plugins.