Stop Contact Form Spam With a Cloudflare Rule Instead of reCAPTCHA

Every week a client asks us what they can use instead of reCAPTCHA. Our answer is usually not another captcha at all. It is a single Cloudflare firewall rule that sends visitors from outside your home country through an automatic browser check before they ever reach your contact form. In this short video we show the rule we use, and below are the steps to copy it into your own Cloudflare account.

Video transcript: How To Reduce Contact Form Spam With Cloudflare

0:00Why We Avoid CAPTCHAs for Contact Form Spam

This is Brendan from WP Speed Fix here, and I thought I would make a very short video because we've had a few clients asking about it this week for reCAPTCHA alternatives, or CAPTCHA alternatives. We don't like CAPTCHAs. They are slow, they are heavy, they add one or two seconds at least to your page load speed, which is not good. Some plugins, like Contact Form 7, even add the reCAPTCHA site-wide regardless of whether there is a contact form on the page. So basically you've slowed down all the pages by one or two seconds. Not good.

From a speed optimization perspective we don't want to use CAPTCHAs or reCAPTCHAs. That's great for speed, not so good for spam. So let me explain a simple Cloudflare firewall rule that we add to filter traffic and stop spam.

0:49Creating the Cloudflare Firewall Rule

I've just got a Cloudflare account open here. In the free Cloudflare account you can add five firewall rules. This is a paid one, so we have 20. If you go here under Security and WAF, Web Application Firewall, you can add a new rule, so you can create a firewall rule. I'm going to show you this rule here, and in the post linked from this video I will give you the code so you can just copy and paste the code in. If I hit this tool icon here, this is the rule that I have.

What we're basically doing is capturing all the traffic, or sending all the visitors, outside Australia. This is an Australian site, so it's not targeting visitors outside Australia. Anyone who's outside Australia that visits the site gets basically an automated Cloudflare challenge. You've probably seen it from time to time when you go to a website and it comes up with a security warning, checking to make sure you're a real user. That's probably Cloudflare, and that's what this rule does.

1:35Protecting Google and Bing From the Rule

In this case we have people who are outside Australia, so they're not in Australia, and they're not a known bot. We want to be careful with these rules. We don't want to block Google. That's a problem. If we block Google and Bing and other important search crawlers, then we're going to screw up SEO and not rank in the search results. So these two conditions here are what you want by default, and I'll include the string that creates this rule.

You want to edit this so it's your own country, or the country or countries you're targeting. I think you can also do continent. You can do continent as well, so if you're in Europe you can use that, or North America I think as well. That will give you broader coverage. The rule still works, but it'll cover more countries and it's a bit more broad. You want these two conditions at a minimum.

2:21Allowing SEO Tools and Other Bots Through

This rule has some extra bits and pieces in it because we're using some tools on this website. This is a website that our SEO agency is doing work on, so these are some of the tools we use: Optmyzr, TrueClicks, Siteliner, Screaming Frog and Surfer SEO. What this does is stop blocking those bots or user agents as well. They're not in the known bots list at Cloudflare. I think Cloudflare only has like 15 known bots. I'll link you up to their post that lists them all. Google and Bing are definitely in it, Ahrefs I think is another, and there are several others.

Anyway, we added these in as extra rules so we're not blocking them either, because adding this rule will break automated tools that are hitting your website. You might want to add those in, but that's pretty much how to do it. That's how to filter traffic outside your home country.

3:33Choosing the JS Challenge Over a CAPTCHA

It won't really hurt real users if you have, say, three percent of your traffic still outside your home country. All it does is send them through a Cloudflare automated security check. That's what JS Challenge is, and it's what you want to use. There's also Managed Challenge as another option. You don't really want to use that, or the legacy CAPTCHA. You want to avoid those, because then your users are going to have to select the boats or select the airplanes or whatever it is, the really annoying CAPTCHA that takes you five goes to get because the image is so blurry or doesn't look clear at all. So you want to use JS Challenge. That's the automated check.

Anyway, that's it. Nice short video, very simple. As I said, I'll link you up to the post where you can just copy and paste this expression.

4:20Copying the Rule Into Your Own Cloudflare Account

Before we finish I'll show you here. I'll just copy that and go back. If you want to create your own rule, just click Create Firewall Rule, then click Edit Expression and just copy in the text I give you. Save it as draft. Oops, I'll just give it a name, "test rule". If you save it as draft, oops, it's erroring out because it's a duplicate. Let me just change that to say UK. It saves the draft and you'll see there it has added the rule. We'll go back and edit it just by copying and pasting, so we just select our country, say UK or whatever it is there.

Anyway, that's it. I hope you found that useful. Let me know if you have any questions, post in the comments. If you want some help with your site speed, head over to wpspeedfix.com where you can request a free site speed audit, where we'll have a look at your site and tell you how we can help. There's also a free speed test tool there that will give you detailed speed optimization insights and recommendations in about 90 seconds, totally for free, no opt-ins or any of that jazz. Anyway, leave it to Cheers.

Why we take reCAPTCHA off sites

Captchas are heavy. Google reCAPTCHA loads a chunk of JavaScript that adds at least a second or two to page load, and some form plugins make it worse. Contact Form 7, for example, loads reCAPTCHA on every page of the site whether or not that page has a form on it, so the whole site pays the speed cost for one contact page.

Removing the captcha makes the site faster, but spam climbs quickly once it is gone. The Cloudflare rule is how we get the speed back without drowning in junk submissions.

What the rule does

The rule matches two conditions together: the visitor is not in your country, and the visitor is not a known bot. Anyone who matches gets a JS Challenge, which is the automatic “checking your browser” screen you have probably seen on other sites. A real person waits a moment and carries on. Most spam scripts never get past it.

The “not a known bot” part is the piece you must not leave out. Cloudflare keeps a list of verified crawlers, including Google and Bing. If you challenge those, you stop search engines from crawling the site and your rankings will suffer. Keep both conditions in every version of this rule.

The rule expressions

This is the simple version for an Australian site. Swap AU for your own country code:

(not ip.geoip.country in {"AU"} and not cf.client.bot)

If you target more than one country, list them inside the braces separated by spaces, for example {"AU" "NZ"}. You can also match on continent instead of country, which gives broader coverage if you sell across Europe or North America. The rule works the same way, it just lets more traffic through unchallenged.

On the site in the video we also use several SEO tools that are not on Cloudflare’s known bots list, so the rule has extra exclusions for their user agents. Our more advanced version looks like this:

(not ip.geoip.country in {"AU"} and not cf.client.bot and not http.user_agent contains "opteo" and not http.user_agent contains "truclicks" and not http.user_agent contains "siteliner" and not http.user_agent contains "screaming" and not http.user_agent contains "surfer")

Replace those names with whatever tools hit your own site. User agent matching in Cloudflare is case-sensitive, so check how each tool actually identifies itself in your security events log and copy that spelling exactly.

Adding the rule in Cloudflare, step by step

  1. Log in to Cloudflare and select the domain.
  2. Open Security, then WAF. In the video this screen is labelled Firewall rules; newer dashboards call them Custom rules. Click the button to create a new rule.
  3. Give the rule a clear name, such as “Challenge outside AU”.
  4. Click Edit expression to switch from the field builder to the text editor, then paste in one of the expressions above.
  5. Change the country code (or codes) to suit your market.
  6. Set the action to JS Challenge.
  7. Save it. You can save as a draft first if you want to check it before deploying. Cloudflare will not let two rules share the same name, so rename it if you get an error.

The free Cloudflare plan in the video allowed five firewall rules and the paid plan more, so one rule for spam fits comfortably even on a free account.

Pick the right challenge

Cloudflare offers several actions and they behave very differently for real visitors:

  • JS Challenge: automatic. The browser runs a quick check and the visitor continues without clicking anything. This is the one we use.
  • Managed Challenge: Cloudflare decides what to show, which can include an interactive check. We avoid it for this rule.
  • Legacy CAPTCHA: the “select all the boats” image puzzle that takes several attempts because the pictures are blurry. Avoid it. It puts back the friction you removed when you took reCAPTCHA off.

Will it hurt real customers?

For a business that serves one country, very little. If a few percent of your traffic comes from overseas, those visitors see a short automatic check and then the site as normal. Nobody is blocked outright.

The thing that does break is automation. Uptime monitors, rank trackers, site crawlers and other tools that fetch pages from data centres in other countries will hit the challenge. That is why we add the user agent exclusions. After you deploy the rule, keep an eye on your tools for a day or two and add an exclusion for anything legitimate that stops working.

Quick checklist

  • Keep not cf.client.bot in the expression so Google and Bing are never challenged.
  • Set the country or continent to match where your customers actually are.
  • Exclude the user agents of SEO and monitoring tools you rely on.
  • Use JS Challenge, not Managed Challenge or Legacy CAPTCHA.
  • Remove the reCAPTCHA plugin or setting once the rule is live, so you actually get the speed benefit.

If you want to know what else is slowing your site down, request a free site audit from the WP Speed Fix homepage.