reCAPTCHA and other form captchas are a poor trade: they load extra third-party script on the page, they put a puzzle in front of the people most likely to become customers, and they do not always stop the spam. The client in this video already had a captcha on their Contact Us form and was still getting a steady stream of junk through it. Instead of adding another layer to the form, we moved the filtering to Cloudflare, so suspicious visitors are challenged before the page even loads. Here is the rule, step by step.
Table of Contents
How the rule works
The rule only applies to one URL: the contact page. On that page it challenges any visitor who is outside your main markets and is not a known bot. Visitors from your core countries go straight through with no captcha at all. Search engine crawlers and the other verified bots on Cloudflare’s list are left alone. Everyone else gets a Cloudflare challenge, and automated spam tools that cannot pass it are stopped at Cloudflare without ever touching your form or your hosting.
This works on the free Cloudflare plan, which included five firewall rules when we recorded the video.
Building the rule in the Cloudflare dashboard
- Open your domain in Cloudflare and go to Security, then WAF. Create a new firewall rule (newer dashboards call these custom rules).
- Give it a name you will recognise later. We used “Contact us form spam filtering”.
- Add the first condition: URI Path equals your contact page path. In our example that is
/contact-us/. Check whether your site uses a trailing slash and match it exactly, because/contact-usand/contact-us/are different strings to the rule. - Add Country does not equal your home country. The client is in Australia, gets very little spam from Australia, and Australia is their biggest market, so we excluded it.
- Add Continent does not equal your second market. For this client that is North America.
- Add Known Bots equals off. This keeps Google, Bing and the other verified crawlers out of the rule.
- Set the action to JS Challenge. Cloudflare’s newer Managed Challenge option does the same job if you prefer it.
- Click Deploy. The rule takes effect immediately.
The quicker way: paste the expression
Rather than building the conditions one at a time, click Edit expression and paste the rule in directly, then name it, choose the challenge action and deploy:
(http.request.uri.path eq "/contact-us/" and ip.geoip.country ne "AU" and ip.geoip.continent ne "NA" and not cf.client.bot)
Before you deploy, change three things to suit your site:
- The path, so it matches your own contact page exactly.
- The country code, so it is your main market rather than Australia.
- The continent code. A European business might use
ip.geoip.continent ne "EU".
You can also delete the country and continent conditions altogether. The rule then challenges everyone on the contact page except known bots. We do not recommend that for most sites: a person on the contact page is probably close to buying, and putting a challenge in front of your best visitors defeats the point.
Do not remove the known bots condition
This is the one part to leave alone. Without not cf.client.bot, Googlebot gets challenged on the contact page, cannot crawl it, and the page can drop out of the index. Spam bots are not on Cloudflare’s verified list, so keeping this exception costs you nothing in protection.
Check the rule is earning its place
Come back an hour or a day later, depending on your traffic. Next to each rule Cloudflare shows how many challenges were issued and the CSR, the challenge solve rate. A high issued count with almost nothing solved means the rule is stopping automated traffic and real people are not being caught.
In the video we show a similar rule on the WordPress login page: 15 challenges issued in 24 hours and none solved, so none of those visitors were genuine. Expect a contact page rule to show the same pattern. If the solve rate is high, real people are being challenged, and you should widen the countries you exclude.
When this is not the right rule
This rule protects one page. If you have forms across the site, such as a footer opt-in or a quote form in the sidebar, a site-wide filter is a better fit, and we have a separate video on our channel covering that. For a single contact page, though, filtering at Cloudflare means the captcha on the form is no longer doing the heavy lifting, and your best visitors no longer have to solve a puzzle to reach you.
If spam, slow pages or broken forms are costing you leads, request a free site audit from the WP Speed Fix homepage.