Contact Form Spam

Talon H. shared this question 20 days ago
Need Answer

I have someone calling themselves "Smith" using the contact form (which I believe has reCAPTCHA protection) to send in dozens of leads per day. What's strange is that there's no phone/email (which are required) but there's content in the "Event Notes" field like this:

field_00bdb88: 3

field_f5a9b22: 00:00

field_1a3a4bd: 3

field_e626fcb: 3

field_ef4bb40: 3

What can be done to stop them? I've blacklisted them, but of course that doesn't help the contact form.

Comments (2)

photo
1

We're taking a look on your behalf.

photo
1

So it looks like they were taking advantage of your party planner form. Elementor was registering the submissions as unsuccessful, but the after submit "actions" may have still been letting it through as a lead. I cleaned up the spam leads, traced their IP back to a hosting network (basically there were quite a few IP addresses getting blocked by your wordfence firewall) and so instead of just blocking the one that was sending spam, I blocked that networks entire range of IP addresses.


Let us know if more come in and we'll look into it more at that point.

photo
2

Thanks, Daniel! Much appreciated. Unfortunately, they just started up again last night around 3AM, and got a whole bunch overnight.

photo
1

No worries, we'll check it out and see if we can come up with a more comprehensive solution. :)

photo
2

As a follow up, I went through and deleted most of the leads but left 3 because I've escalated the issue as well. I added reCaptcha v3 and a honeypot to the form which will hopefully prevent this moving forward from the website side of things. If you wouldn't mind leaving the 3 Smith leads on your leads/events page for the time being so we can look into further preventing it on the IO side of things that would be appreciated!


Best,


Daniel

photo
1

You got it, I'll wait for you to remove those once you're finished with them. Thanks!

photo
Leave a Comment
 
Attach a file
Access denied