Bots Submitting Forms on Your Website: Where Fake Leads Come From and How to Stop Them

When bots submit forms on your site, three things suffer at once: sales reps call into the void, the stats lie, and the ad platform learns from junk conversions. Here is where spam leads come from and how to protect your form in several layers.

Bots and Fraud10 min read
Bots Submitting Forms on Your Website: Where Fake Leads Come From and How to Stop Them
Contents
  1. Why bots submit forms: where fake leads come from
  2. Signs that bots are submitting your forms
  3. Form spam protection: the layers
  4. Duplicate leads: a separate problem
  5. Why fake leads must not go to the ad account
  6. How ArtisanClo shows and stops this
  7. Summary

Morning, twenty new leads in the CRM, and half of them are "aaaa", "test", a phone number of all sevens and an email on a disposable domain. A familiar picture: bots are submitting forms on your site. Sometimes it is harmless spam, sometimes it is fraud that eats into payouts and corrupts the campaign stats.

In short: spam form submissions and fake leads appear when the form accepts any data without checks and the page lets everyone in. Protection is built in several layers: keep bots off the page, validate submissions on the server, rate-limit, filter out duplicates and do not pass junk further on to the network and the ad account.

Why bots submit forms: where fake leads come from

Spam leads have different causes, and the cause determines which layer of protection will work.

Spam bots that hit every form

The most widespread type. A script finds <form> tags on pages, fills in every field and submits. It does not care whether it is a landing page or a blog: it advertises something in the "comment" field or just checks whether the form accepts a link. These bots are primitive and stopped by simple measures.

Fraud in ad traffic

Here the leads are the goal, not a side effect. The motive may belong to a dishonest traffic source (show a "conversion" so it does not get blocked), a publisher on a pay-per-action placement, or a competitor who wants to confuse your optimization. These bots run JavaScript, enter plausible names and numbers and go through proxies. Motives and signs are covered in detail in click fraud.

Testing stolen data

A bot runs a contact database through forms to find out which entries are still "alive". To you it looks like real names and phone numbers of people who never left you anything and will be very surprised by a call.

Real but "incentivized" people

Not everything that looks fake is a bot. Incentivized traffic (people paid for an action) and accidental taps in apps produce leads from real people with no real interest. Technical protection will not stop them; only judging the source and the approval rate helps. More in traffic quality.

Signs that bots are submitting your forms

Sign What you see How reliable
Junk in fields Random letters, "test", links in the name High for simple bots
Unreal contacts Phone in the wrong format or country, disposable email Medium
Speed Form submitted a second after the page opened High
Network Hosting, cloud or proxy address Medium: people use proxies too
Repeats Several leads from one device or address with different details High
Timing A batch of leads deep in the night for the geo, even intervals Medium
Approval The network rejects leads en masse or flags them as fraud High, but delayed

No single sign proves a bot on its own. A reliable conclusion comes from two or three matching. For a broader look at automation signals, see signs of bot traffic.

Form spam protection: the layers

Good form protection does not rely on a single trick. Each layer catches its own share of junk, and together they barely get in real people's way.

Layer 1. Keep bots off the page

The best bot lead is one it could not submit because it never saw the form. If the landing page gets ad traffic, a filter at the entrance stops visits from data centers, programs posing as browsers, headless browsers and known bot addresses before the page is shown. How that filtering works is covered in how to filter bot traffic, and the techniques for spotting automated browsers in headless browsers and fingerprinting.

But this layer has an honest limitation: a bot that knows the form handler's address can post data straight to it, bypassing the page. So the second layer is mandatory.

Layer 2. Server-side validation

Anything checked only in the browser can be bypassed by a bot. The form handler must check for itself:

  1. Field format. Phone: digits of the right length and country code; email: a valid domain; name: no links or special characters.
  2. Honeypot. A hidden field people do not see. If it is filled in, quietly discard the lead with no error message.
  3. Time to complete. The server issues a timestamp when the form is shown; a submission faster than a few seconds is suspicious.
  4. Form token. A one-time token issued with the page. A submission without it, or with someone else's token, means the form was not filled in on your page.
  5. Visit source. If the lead has no click ID that arrived with the visitor from the ad, it is either a direct visit or a submission that bypassed the page.
// Minimal check in the form handler
if (!empty($_POST['website'])) {        // honeypot: field hidden from people
    http_response_code(200); exit;      // pretend everything is fine
}
if (time() - (int)($_POST['ts'] ?? 0) < 3) {
    http_response_code(200); exit;      // filled in faster than a human
}

This is an illustration, not a finished solution: in a real handler the timestamp must be signed so a bot cannot forge it.

Layer 3. Rate limits

Limit the number of submissions from one address and one device per hour and per day. A real person rarely leaves more than one or two leads; a bot testing a database leaves dozens. A rate limit works especially well against fraud where one machine tries to pass itself off as many people.

Layer 4. CAPTCHA, with caveats

A CAPTCHA seems the obvious answer, but it has two costs. The first is conversion: every extra step in a form loses some real people, especially on mobile. The second is a false sense of security: human-powered solving services crack CAPTCHAs for a fraction of a cent. A sensible compromise is an invisible check that shows a challenge only on a suspicious submission, with a CAPTCHA as the last layer rather than the first. How different kinds of bot protection compare is covered in anti-bot protection for websites.

Tip. Do not let a bot know it has been caught. Answering "thank you, your request was received" to a discarded submission keeps the script's author from figuring out which check fired and adapting to it.

Duplicate leads: a separate problem

A duplicate is a repeat lead from the same visitor. It can be honest (the person did not wait for a call and submitted again) or dishonest (fraud where one device enters different details). Either way you must not count a duplicate as a new conversion:

  • you inflate CR and decide to scale on false numbers;
  • the network will not pay for a duplicate anyway, and the approval rate drops;
  • the ad account receives an extra conversion and starts looking for "more like it".

As a rule, duplicates are identified by a "visitor + time window" pair: if the same person (by address, or by address and browser) submits again within a set period, the second lead is marked as a duplicate and does not replace the first. How duplicates affect statuses and payouts is covered in conversion statuses.

Why fake leads must not go to the ad account

Modern ad platforms optimize delivery by the conversions you send them — via pixel, Conversions API or postback. If that data contains junk, the algorithm learns to find visitors who resemble bots. A week later the share of fake leads grows, while you see "cheap leads" and raise the budget.

So the rule is simple: only statuses you are sure of go to the ad account — an approved lead or a sale — while duplicates and rejected leads stay with you. How to set up that kind of sending is covered in sending conversions back to ad platforms.

How ArtisanClo shows and stops this

ArtisanClo works at the entrance: it decides on every visit from an ad link whether to let it through to the page with the form. The form handler itself stays on your site, so the server-side checks from layer two are still needed. What the service does:

Stops bots before the form. Programs posing as browsers, obvious headless browsers, ad review services and addresses where bots have already been confidently caught get the White Page instead of the form page immediately. Data centers, VPNs, proxies, missing JavaScript and other signals add up to a trust score: if too much looks suspicious, the visitor never sees the form. From the Professional plan there is a limit on clicks from one IP per day, and the live interaction check looks at how the mouse and finger move. Every decision is explained by a reason in the click log.

Ties the lead to the click. The Conversions setup section offers, for your own site, PHP code for the form handler, a script for the thank-you page or a pixel. The lead arrives together with the click ID, so you can see which visit, source and creative it came from. The postback log also shows outcomes such as click not found or no click_id, so a lead without a real click stands out immediately.

Handles duplicates. Flow settings have a Unique visitor block: a window from one hour to 30 days, with recognition by IP or by IP and browser. In modes with the tracker, a repeat lead from the same visitor via another click within the window is recorded as Trash marked "duplicate" and does not replace the first.

Maps network statuses. If the affiliate network sends a fraud status, the lead becomes Trash; an unknown status is also recorded as Trash with zero revenue. A repeat message with the same transaction ID updates the record — that is how the network approves or reverses a lead.

Shows where the junk is. The click log can be filtered by whether there is a lead, and the click card shows the network, checks and conversions. In Conversions you can filter for the Trash status. From Professional, Extra guard learns from your account's history — who paid and who turned out to be a bot — and sends similar visits to the White Page.

A postback to the source is sent once per conversion and status, and you can choose which statuses to report to the platform. From Professional, conversions are sent directly to Meta, TikTok and Google Ads using your own keys. More on the features page, and which features come with which plan on the pricing page.

Summary

When bots submit forms on your site, no single measure saves you. Keep bots off the page, validate every submission on the server (format, honeypot, timing, token), rate-limit, and keep the CAPTCHA as the last layer. Mark duplicate leads and do not count them as new conversions, and send the ad account only what you are sure of. Then fake leads stop distorting your stats, and the platform stops learning from junk.

Frequently asked questions

01

Why do bots submit forms on my site if there is nothing to steal?

Most bots do not need your form specifically. Some spam every form they find, others inflate conversions in ad networks, others test stolen contact details. To them your form is just an open input field that submits without checks.

02

Will a CAPTCHA stop spam leads?

A CAPTCHA blocks simple scripts but does not solve the whole problem: human-powered solving services get around it, while real visitors get stuck on it and conversion drops. It makes sense as a last layer or only for suspicious submissions, not for everyone.

03

How can I tell a fake lead from a real one?

Look at a combination of signs: an invalid or disposable phone number, a meaningless name, a submission one second after the page opened, a data center address, several leads from one device with different details. One sign proves nothing; several together almost certainly mean a bot.

04

What is a honeypot field in a form?

It is a hidden field a person does not see or fill in, but a simple bot fills in because it fills everything. The server receives a lead with the hidden field filled and quietly discards it. The method is free and does not bother people, but smarter bots recognize it.

05

Should I send fake leads to the ad platform?

No. If the platform receives junk conversions, its algorithm starts looking for similar visitors, which means even more junk. Send only confirmed statuses to the ad account, or at least filter out obvious duplicates and leads flagged as fraud.

Read next

See your traffic for real

Connect ArtisanClo to your site, see who actually arrives from your ads, and why every click got its decision.