Skip to main content

Overview

The Honeypot Field is a simple way to reduce spam without adding friction (such as CAPTCHAs) to your form. When enabled, your form includes a hidden input that human users will leave empty — but bots often complete. Any submission where the honeypot contains a value is treated as spam according to your form’s configuration.

Enabling the Honeypot Field

You can enable Honeypot protection in the Crunchforms dashboard:
  1. Navigate to your dashboard
  2. Open the form’s settings by selecting Edit Form Settings from the menu next to the form, or from the same menu inside the form’s submission view.
  3. Go to the Spam protection section.
  4. Enter the name of the honeypot field you would like to use (e.g., hp_username, website), or press the button to generate a random one. It must match the name attribute of the hidden field in your form.
  5. Save your changes.
Once a name is set, the settings page shows you the exact hidden input to paste into your page, and the code snippet in the left-hand panel includes it automatically.
Crunchforms checks the saved field name. If you change the name, save before updating your page — otherwise the two no longer match and the trap catches nothing.

Adding the Honeypot Field to your Form

If you are building a custom frontend and POSTing to Crunchforms, include a hidden honeypot field in your HTML:
honeypot-form.html
  • Do not use display:none — bots often ignore fully hidden fields.
  • Push the field off-screen using positioning, not visibility:hidden.
  • Use a natural-sounding field name (e.g., website, username, hp_name).
  • Add tabindex="-1" to avoid keyboard focus.
  • Set autocomplete to a non-standard value (e.g., "nope") to prevent browser autofill.

API Usage

If you are submitting JSON data, include the honeypot field like any other field:

Example Valid Submission

Example Spam Submission

This submission would be rejected as spam because the honeypot field is filled:

Limitations

  • Honeypot fields work best against low-complexity bots.
  • Advanced bots may detect hidden fields. For stronger protection, consider other methods like Cloudflare Turnstile or reCAPTCHA.

Next steps

Explore advanced configurations and features:

Set up a Honeypot Field

Get easy protection against simple bots using a hidden field

Set up Cloudflare Turnstile

Advanced bot protection using Cloudflare Turnstile

Set up Google Recaptcha

Advanced bot protection using Google reCaptcha v3

Add additional email addresses

Add and verify additional email addresses to receive form submission notifications

Need Help?

Get Support

Send us a note