Spam protection

Public forms attract bots. AcquisitionSuite includes several layers of protection that need no setup and no third-party service.

Honeypot field

Every form includes a hidden field that real visitors never see or fill in. Bots tend to fill in every field they find; a submission with the hidden field filled in is rejected.

Rate limiting

Each IP address is limited to 5 submissions per 10 minutes. Beyond that, further attempts are refused until the window passes. The limit uses the connection’s real address, not forwarded headers, so it cannot be bypassed by spoofing headers. If several genuine visitors share one network (an office or a school), they share the limit too.

Nonces and validation

Every submission carries a security nonce and is validated on the server. Required fields, including required checkboxes and radio groups, are re-checked server-side, so skipping the browser form does not skip the rules.

Single-use, expiring downloads

Even if spam gets through, it cannot harvest your files: the download link is single-use and expires. See Download links and expiry.

Double opt-in

To keep fake addresses off your mailing list, turn on double opt-in for Mailchimp, Brevo or MailWizz so a subscriber must confirm their address first. See Email integrations.

If real people are blocked

A visitor who tests a form many times in a few minutes will hit the rate limit and see an error. Wait ten minutes and try again. Also make sure page caching does not serve a stale security nonce; see Caching and CDNs.

Still stuck?Our support team replies by email. Contact support

Share with