Spam protection
Every form gets a honeypot and rate limits. Add a CAPTCHA to stop the bots that get past them.
SimplyForms Shield
SimplyForms Shield is our built-in CAPTCHA. Before a form submits, the visitor's browser solves a small computing puzzle in the background, typically in well under a second. People rarely notice it; bots sending thousands of submissions pay for every one.
- Nothing to set up. No account with another company, no keys to paste.
- Private. No cookies, no tracking, and nothing is sent to a third party: the puzzle comes from SimplyForms and is checked by SimplyForms.
- Accessible. No images to pick out; the widget is keyboard and screen-reader friendly.
- Works on hosted forms and on custom domains, as well as on your own site.
Turn it on
In your form's Security tab, choose SimplyForms Shield and save. Hosted forms show it straight away. For your own site, add the widget inside your form and load its script once on the page. The code on your form's Design/API tab already includes both:
<form action="https://api.simplyforms.dev/v1/forms/YOUR_FORM_ID/submissions" method="POST"> <input type="email" name="email" required /> <textarea name="message" required></textarea> <simplyforms-captcha form-id="YOUR_FORM_ID" autoreset></simplyforms-captcha> <button type="submit">Send</button> </form> <script type="module" src="https://simplyforms.dev/captcha/v1/widget.js"></script>
The widget adds a hidden sf-captcha-response field to your form, so a normal HTML post carries it. It starts solving as soon as the visitor clicks into the form, and fetches a fresh puzzle by itself if the page is left open for a long time.
Forms sent with JavaScript (AJAX, React, Next.js)
Build your request from the form element (new FormData(form)) so the hidden field is included. Each token works once, so keep the autoreset attribute: after a send, the widget solves a new puzzle as soon as the visitor touches the form again. The token stays in place until then, so your submit handler can read it whenever it is ready. In React, render <simplyforms-captcha form-id="YOUR_FORM_ID" autoreset="" /> and load the script once in your page or root layout. TypeScript projects can declare the element in a .d.ts file:
declare namespace JSX {
interface IntrinsicElements {
'simplyforms-captcha': React.DetailedHTMLProps<React.HTMLAttributes<HTMLElement>, HTMLElement> & {
'form-id': string;
autoreset?: string;
};
}
}Content Security Policy
If your site sends a Content-Security-Policy header, allow SimplyForms to load the script and the puzzle, and allow the widget's background workers:
script-src 'self' https://simplyforms.dev; connect-src 'self' https://simplyforms.dev; worker-src blob:; style-src 'self' 'unsafe-inline';
Without style-src 'unsafe-inline' the widget still works but appears unstyled. The page must be served over HTTPS (or be localhost).
What it does and does not stop
A puzzle makes every automated submission cost computing time, which stops the cheap, high-volume spam most forms receive. A determined attacker willing to pay for that time can still get through, so SimplyForms keeps its other layers on: the honeypot, per-address rate limits, domain restriction (Pro and above) and custom spam rules (Business). For forms that attract targeted abuse, a third-party CAPTCHA with behavioural scoring (below) is the stronger choice.
SimplyForms Shield is built on the open-source ALTCHA widget (MIT License, © 2023–2026 Daniel Regeci, BAU Software s.r.o.). We host it ourselves and show it as SimplyForms Shield; ALTCHA receives nothing from your visitors.
Bring your own CAPTCHA
You can use Cloudflare Turnstile, Google reCAPTCHA v2, hCaptcha or Friendly Captcha with your own keys. Create a site in the provider's dashboard, then paste its secret (and optionally its site key) in the form's Security tab. The Design/API tab shows the matching widget and script. Your provider receives the CAPTCHA token and, except for Friendly Captcha, the visitor's IP address; it never receives your form's fields.
Hosted forms support SimplyForms Shield and Cloudflare Turnstile. reCAPTCHA, hCaptcha and Friendly Captcha work on forms embedded on your own site.
Honeypot
Every snippet includes a hidden field that people never see but many bots fill in. A submission with it filled in is accepted silently and discarded:
<input type="text" name="_honey" style="display:none" />
Troubleshooting
- "Spam verification is required." The submission had no token. Make sure the widget is inside the
<form>, its script loads (check the browser console), and the visitor waited for the tick before sending. - "Spam verification expired. Please try again." The puzzle was solved more than 20 minutes before sending. The widget normally refreshes it by itself; reloading the page fixes it.
- The widget never appears. Usually a Content Security Policy blocking the script or its workers (see above), or a page served over plain HTTP.
- Posting from a server or script. There is no browser to solve the puzzle. For server-to-server submissions set spam protection to None and use domain restriction or the REST API instead.