Where would AI save you the most time?Free workbook: find the tasks worth automating.
Get the workbook

Home/Articles

AIAutomation

How We Stopped Form Spam With Layered Filtering and AI (4,007 Submissions, $30 of AI)

By Al Bunch · · 6 min read

Contact forms attract spam the way porch lights attract moths, and the usual defenses (a CAPTCHA, a honeypot field, a keyword list) stop the lazy bots and miss the rest. We built a form-processing system, Form Pipeline, that we run for clients under their own branding. Here are its real numbers, how it decides what’s spam, and why the AI is the last layer instead of the only one.

The Numbers

Every client form, from December 23, 2025 to October 7, 2026:

Submissions processed4,007
Rejected as spam3,237 (81%)
…of which blocked by network reputation before any content check2,083
Approved as real761
Flagged for a person to review8
Submissions that needed the AI at all614 (about 15%)
Total AI cost$30.61 (about 5¢ per AI decision, under 1¢ per submission)

In the last 30 days alone: 1,393 submissions, 1,274 rejected as spam automatically, 112 approved automatically, 7 flagged for review.

Four out of five submissions were spam. If every one of those had reached an inbox, someone would be spending real time each week deleting junk, and real leads would be easier to miss.

Why the AI Comes Last

The obvious approach is to send every submission to an AI model and ask “is this spam?” It works. It’s also the expensive, slow way, and it means paying to analyze the same spammer for the hundredth time.

Instead, each submission goes through cheap checks first and only reaches the AI if nothing earlier could decide:

  1. Network reputation. Is this IP address, or the network it belongs to, a known spam source? Most repeat offenders stop here.
  2. Sender reputation and rules. Is this email address on the known-bad list? Does the submission fail basic checks?
  3. AI content analysis. For whatever’s left, a model reads the submission and returns a spam score in a fixed format.
  4. A decision, or a person. Clear results are approved or rejected automatically; borderline ones are flagged for review.

85% of submissions are decided before step 3. That’s why the AI bill for nine months is about the price of a lunch.

Layer 1: Network Reputation That Escalates

Spam doesn’t come from random places. It comes from the same hosting providers and networks over and over, rotating through IP addresses to dodge simple blocklists.

So the system blocks at two levels:

  • IP addresses that have sent spam are blocked, with the block decaying over time so a reassigned address isn’t punished forever.
  • Networks (ASNs). When spam keeps arriving from many different IPs in the same network, the block escalates from individual addresses to the whole network. One hosting network alone accounts for 118 blocked IP addresses in our data. Blocking them one at a time would be an endless game of whack-a-mole.

Those blocked submissions are shadowbanned, not rejected with an error. The sender sees the normal “thanks, we got your message” response. Nothing is delivered, and the spammer has no signal to change tactics. That’s how 2,083 submissions were stopped without the AI or a person ever looking at them.

Clients can whitelist their own networks, turn IP blocking off, or run the system as a plain pass-through. The layers are settings, not hard-coded assumptions.

Layer 2: Sender Reputation That Learns

The system keeps a list of known-bad email addresses: 1,628 today. 606 of them weren’t added by anyone. They were promoted to the list automatically, after the same addresses kept showing up in confirmed spam.

This is where the system improves on its own. Every confirmed spam submission makes the cheap layers smarter, which means fewer submissions reach the AI next month. The same reputation check is also available as an API: a SaaS platform we run calls it during signup to quietly turn away accounts from known spam sources.

Layer 3: AI for the Hard Cases

What reaches the AI is the spam that looks like a real person: a plausible name, a real-looking email, a message that’s almost about your business. “I came across your website and I’d love to help you rank on Google” passes every CAPTCHA. A person spots it in two seconds, and so does a language model.

The model doesn’t chat or improvise. It gets the submission, a description of what the form is for, and instructions to return a score in a fixed format. Our code, not the model, decides what happens next based on that score. That’s the pattern we use for every AI integration: the model makes one judgment call; ordinary software does everything else, predictably.

Layer 4: Borderline Goes to a Person

No spam filter is perfect, and we don’t claim this one is. Misclassifications are rare, but the bigger design decision is what happens when the system isn’t sure.

Borderline submissions aren’t guessed at. They’re flagged and held for a person to review, approve or reject. That’s happened 8 times out of 4,007 submissions: rare enough that reviewing them takes seconds, and it means a real lead is never thrown away because a model was 55% confident.

Every correction feeds back into the reputation lists, so the same mistake is less likely to happen twice.

What This Means for Your Forms

If spam is getting through your forms today, the lessons transfer to any setup:

  • A CAPTCHA isn’t enough. It checks browsers, not intent. Human-written and challenge-solving spam goes straight through.
  • Block networks, not just addresses. Spammers rotate IPs inside the same few networks.
  • Use AI for judgment, not for everything. Cheap rules for the obvious cases, AI for the ambiguous ones. Your costs stay in cents.
  • Never let the AI make uncertain calls alone. A review queue for borderline cases is what makes automation safe for real leads.
  • Don’t tell spammers they’ve been caught. A normal-looking response gives them nothing to adapt to.

And once spam is gone, the clean submissions can go straight into your CRM, with routing and follow-up, instead of an inbox someone has to watch. That’s the part most businesses actually care about.

Where would AI save your team the most time?Free workbook: score your manual tasks, check the AI fit and do the payback math.
Get the workbook

Want This on Your Forms?

We run Form Pipeline for clients as part of our integration work, under your brand, connected to your CRM, email marketing or team chat. It’s not a self-serve product; we set it up, tune it to your forms and keep it running. See AI automation services for how we build AI into business processes, or tell us about your forms.

FAQ

Frequently Asked Questions

Can AI stop contact form spam?

Yes, but it works best as the last layer, not the only one. In our system, network reputation and simple rules decide about 85% of submissions before the AI runs. The AI judges the rest, and anything borderline goes to a person instead of being guessed at.

Why doesn't reCAPTCHA stop all form spam?

reCAPTCHA checks whether a browser behaves like a human. A lot of form spam today is sent by people paid to fill in forms, or by bots that solve or bypass the challenge, so it passes. Judging the content of the message and the reputation of the sender catches what a challenge can't.

How much does AI spam filtering cost?

Very little when the AI only sees the hard cases. Across 4,007 submissions our total AI cost was $30.61: about 5 cents per AI decision and under 1 cent per submission, because most spam is rejected by cheaper rules first.

What happens to submissions the AI isn't sure about?

They're flagged for a person to review instead of being approved or rejected automatically. That keeps mistakes rare without letting the AI make uncertain calls on real leads. Of 4,007 submissions, 8 were flagged.

Free download

The AI Automation Workbook

Find the tasks worth handing to AI, estimate the payback, and plan a pilot you can measure.

Get the free PDF

Ready to Get Your Systems Connected?

Tell us what tools you're using and what's not working.