Making the Call

Spam form submissions are skewing more than your inbox

Summarize with AI

Are spam form submissions making your conversion numbers wrong? If your analytics or your ad account counts a form submission as a conversion, and nothing checks the submission first, then yes. And the wrong number is the smallest of the three problems. The same spam can teach Google Ads to buy more of whatever produced it, and it can bury the one real quote request that arrived the same week.

This is written for whoever owns the numbers and the inbox, not whoever wires up the form. You don't need to know how any of the fixes are built. You need to know what each one stops, what it can break, and what to ask for.

How do spam form submissions get into an RFQ form?

Three different ways, and they need different fixes.

Scripts that post straight to the form. They never load the page. They find the address the form sends to and submit to it directly, hundreds of times if nothing stops them. Because the page never loads, your analytics usually never sees them. Your inbox does.

Bots that drive a real browser. They load the page, fill the fields and press submit like a person would. These show up in the inbox and in the analytics, which is the worst case for your numbers.

People. Somebody selling SEO, offshore development or a list of trade show attendees, typing into your quote form by hand because it's the only way in. No bot check stops a human, and to a bot check they are one.

That split explains something most companies notice and can't account for: the inbox and the analytics report rarely agree. Spam from the first group inflates the inbox and not the report. Spam from the second inflates both. So the report and the inbox disagree, and neither one is a count of real enquiries. The report can look healthy while bots pad it, and on its own it can't tell you by how much.

What does spam do to Google Ads bidding?

Google describes Smart Bidding as bidding strategies that use its AI to optimize for conversions in every auction. It learns from whatever you tell it a conversion is. If a form fill counts as a conversion the campaign bids toward, every spam submission it counts becomes a small lesson that says: find more people like this one.

That's how an account ends up spending more on the traffic producing junk while reporting a healthy cost per conversion. Nothing in the account looks broken. The report shows conversions going up. The sales team sees an inbox of pitches and nonsense and stops believing the report. They're both right about what they're looking at.

It's the tracking problem covered in where leads leak in Google Ads for manufacturers, and spam is the quickest route into it: the account counts something that isn't a quote request, and the bidding goes looking for more of it.

How do real enquiries get missed?

Two ways, and the second is harder to notice.

They get buried. An estimator opens the RFQ inbox to twenty-five messages and two are real. After a few weeks of that, they skim. The RFQ from a new buyer, who sent the same drawing to two other suppliers that morning, gets read on Thursday. On how buyers run the RFQ process, the first credible reply often frames the whole comparison. Thursday isn't first.

They get filtered. A filter that deletes whatever it judges to be spam will, sooner or later, delete a real buyer. It usually goes unnoticed, because a rejected buyer doesn't leave a trace. They just send the drawing to someone else.

The fix for both is the same, and it isn't a better spam tool. Suspicious submissions go to a quarantine folder that one named person skims every working day, instead of being deleted. Real ones get logged where the whole team can see them and who is answering, not left in whichever inbox the form happens to email, which is the case made in what to connect first in a CRM integration. A filter you can look inside will occasionally catch a real enquiry, and you'll find it there.

Which spam protection works, and what does each one break?

There's no single fix. OWASP's guidance on bots says it plainly: a single control is brittle. Each method below stops some of the three groups and misses the others, and several can cost you a real buyer if they're set up carelessly.

Honeypot field. A hidden field that only bots fill in. It stops simple scripts that fill every field they find. It misses bots that read the page like a browser, and every human pitch. What it can break: very little if it's built properly. Built carelessly, a real person can end up in the hidden field, which is why the standard pattern hides it from screen readers, keyboard navigation and the browser's autofill too.

Cloudflare Turnstile. It checks each visitor in the background and flags the ones it judges automated, with no puzzle to solve. It misses humans typing pitches. What it can break: a visitor it judges risky gets a checkbox. A buyer whose ad blocker, VPN or company proxy stops it loading can't pass at all, so a failed check should send the submission to quarantine, not show an error. It only protects anything if your server checks the result: Cloudflare says the widget alone does not protect your forms.

Google reCAPTCHA v3. It scores automated traffic silently in the background. It misses humans typing pitches. What it can break: it returns a score from 1.0 (likely human) to 0.0 (likely bot) and you choose the cut-off. Reject low scores outright and any real buyer who scores low goes with them, unseen. Its tokens expire after two minutes, so if it runs when the page loads, a buyer who takes longer over a detailed RFQ can be rejected.

Server-side validation. Your server checks every field, whatever the page did. It stops scripts that post straight to the form and skip the page's own checks, and junk like links pasted into a phone field. It misses anything that looks like valid input. What it can break: rules set too strictly reject real input, like an overseas phone number or a part number full of symbols.

Email or domain checks. They stop made-up addresses and, with a confirmation email, anyone who doesn't control the mailbox. They miss real addresses used for pitches. What they can break: a confirmation step sits between the buyer and your team, and a buyer who doesn't click never reaches you. Blocking personal addresses (Gmail and the like) turns away the smaller customer who uses one.

Rate limiting. Caps on submissions from one source. It stops one source hammering the form hundreds of times. It misses bots spread across many addresses, which is how serious ones run. What it can break: set too tight, several people at one company sharing an office connection can trip it.

For a typical RFQ form, the combination that stops most of it without turning buyers away is a honeypot, server-side validation, one invisible check (such as Turnstile or reCAPTCHA v3) verified on the server, and a quarantine folder instead of deletion. Use email checks to flag, not to block. None of it stops the human pitches, which is fine: they're easy for a person to spot once they're not buried in bot traffic.

How do you keep spam out of GA4 and Google Ads?

This is the half most anti-spam advice skips, and it's the half that decides what your ad budget buys.

Count a conversion only after the server accepts the submission. Send accepted submissions to a thank-you page and count arrivals there, which is the approach in the website KPIs worth tracking. A submission the server rejected never reaches that page, so it never counts. A suspicious one sent to quarantine should still get a thank-you message, just not on the page you count. GA4's automatic form tracking fires when a form is submitted in the browser; it doesn't know whether your server accepted it or whether a person sent it.

Use Google's current terms, because they now mean different things. In GA4, an action that matters to the business is a key event. Google renamed these: what Analytics used to call conversions are now key events, and "conversion" means an action used to measure ad campaigns and optimize bidding. Mark the accepted RFQ as a key event.

Work toward bidding on qualified leads, not raw form fills. The aim is for the bidding to learn from leads your team has confirmed, not from every form that got through. Google has two ways to send that back from your CRM: offline conversion import, which matches on the click ID Google attaches to each ad click, and enhanced conversions for leads, which Google calls its upgraded version and which also matches on details like the email address from the form, captured by your site when the form is sent. Either way, your team marks a lead qualified, and that becomes what the bidding can learn from.

Switch only when confirmed leads can carry it. Bidding needs enough examples to learn from. Google's lead-generation guidance says the conversion action you choose for bidding should have at least 15 conversions in the last 30 days, counted across the account, and a company that gets a handful of qualified leads a month isn't there yet. Until it is, keep the accepted form submission as what the campaign bids toward; the spam checks above are what keep that number honest. If even accepted submissions fall short of Google's guidance, whoever runs the account should bring it up before choosing a bid strategy. When confirmed leads do come in often enough, Google publishes the steps for moving bidding to them, written for campaigns on Target CPA. Follow those, or have whoever runs the account follow them, rather than switching overnight. Expect the cost per conversion to rise once you switch, because each conversion is now a confirmed lead rather than a form fill. That isn't the ads getting worse. Keep importing won deals as well. Closed business is where the bidding should end up, but a won deal can take months, and Google's same guidance prefers an action that happens within seven days of the ad interaction. So won deals take over only once there are enough of them, arriving soon enough, to carry it.

If you can't get a clear answer on whether your account bids on raw form fills or on leads someone checked, that's the first question to settle. It's also why the plan for paid search sometimes has to start with the tracking rather than the ads.

Common questions

Are spam form submissions making our website conversion numbers wrong?

Very likely, if a form submission counts as a conversion and nothing checks it first. Spam that posts straight to the form reaches the inbox but often not the analytics, and spam from bots using a real browser reaches both. So neither the analytics number nor the inbox count is the number of real enquiries. Count a conversion only after your server accepts the submission and it passes your spam checks.

Why do bots spam contact forms?

Because trying costs a script almost nothing. Most aren't aimed at your company; they work through every form they can find, and the few that reach a person occasionally sell something. Some of what looks like bot spam is people selling services, typing by hand, which no bot check stops.

How to prevent bots from filling out forms?

Layer a few methods rather than relying on one: a hidden honeypot field, validation on your server, and one invisible check such as Cloudflare Turnstile or reCAPTCHA v3, verified on the server. Send suspicious submissions to a folder someone reviews instead of deleting them, so a real buyer caught by mistake can still be found.

Can spam leads hurt our Google Ads performance?

Yes, if a form submission counts as a conversion the campaign bids toward. Spam counted as a conversion teaches the bidding to find more of the traffic that produced it. Count only submissions your server accepts and your spam checks pass, so spam never reaches the numbers the bidding learns from, and bid toward those until confirmed leads come in often enough for Google to learn from. Google's lead-generation guidance says the conversion action you choose for bidding should have at least 15 conversions in the last 30 days, counted across the account. When confirmed leads get there, follow Google's published steps for moving bidding to them rather than switching overnight, and expect the cost per conversion to rise. Closed deals are where the bidding should end up, once there are enough of them to carry it.

Should we block personal email addresses on our quote form?

Usually not. Some real buyers, especially at smaller companies, use a personal address. Flag those submissions for a quick look instead of rejecting them, and let the person reviewing the queue decide.

We get so many spam form submissions that real enquiries get missed. What should we do?

Cut the volume with a honeypot, server-side validation and one invisible check, then change where submissions go. Suspicious ones go to a quarantine folder one named person skims every working day, and real ones become a record with an owner instead of an email in a shared inbox.

RFQ pageWebsite conversion rateSEO (search engine optimization)
Share

Let's build something together.

A 30-minute call. We'll listen, dig into the details, and tell you honestly whether we're the right partner, or point you to someone who is.

Book Intro Call ↗