A no-CAPTCHA contact form that still blocks 99% of spam
CAPTCHAs exist because most forms only have one layer of protection. Add four more layers and you don't need the CAPTCHA. That's exactly what SecureSMTP does — honeypot fields, time-to-submit checks, signed render-time nonces, and an AI classifier read the content of borderline submissions. Real visitors fill in your form and click Send. Bots get silently filtered. No challenges, no friction, no "I'm not a robot" tax on your conversion rate.
Free forever for 100 submissions / month · no credit card.
Why CAPTCHAs are the wrong fix
- Every CAPTCHA you show is a tiny conversion hit — multiplied across every form on every page
- They're an accessibility nightmare for screen-reader users, low-vision users, and users on slow connections
- Modern bots beat image CAPTCHAs cheaper than humans solve them ($0.50 per 1,000 solves)
- Most "invisible" CAPTCHAs (reCAPTCHA v3) actually track every visitor in exchange for working at all
One click to submit
No checkbox. No puzzle. No challenge. Real visitors fill in your form and click Send — done.
Five layers of bot blocking
Each layer catches a different class of bot. Stack them and 99%+ never reach your inbox.
No third-party tracking
No Google. No Cloudflare account required (Turnstile is optional). Privacy-friendly by default.
Questions, answered
How is this different from invisible reCAPTCHA?
Invisible reCAPTCHA still tracks every visitor and sends their session fingerprint to Google. SecureSMTP uses only client-side honeypots and server-side checks — no third-party scoring service.
What stops a determined spammer?
Custom-built spammers do occasionally get through any system. For those, our AI classifier reads the submission content and flags it as spam — you'll see it pre-filtered in the dashboard rather than your inbox.
Will real visitors with old browsers get blocked?
No. All our checks fail safely — a missing JavaScript token, a too-old browser, or a slow connection don't cause a real visitor to be rejected. False positives are aggressively minimised.
Do I have to disable my existing CAPTCHA?
You can run both for a transition period if you're cautious. After a week of zero spam (typical), most users disable their CAPTCHA entirely.
Related
A reCAPTCHA alternative that blocks bots without making your visitors prove they aren't one
reCAPTCHA hurts conversion, frustrates users, and leaks data to Google. SecureSMTP blocks bots invisibly with 5 protection layers — no CAPTCHAs, no challenges, no Google. Free forever for 100 submissions/month.
How to remove reCAPTCHA from WordPress without opening the spam floodgates
Step-by-step: how to remove reCAPTCHA from your WordPress site without losing spam protection. Replace it with SecureSMTP — 5 invisible protection layers. Free forever for 100/month.
A WPForms alternative that doesn't paywall the features you actually need
Looking for a WPForms alternative that's free, doesn't paywall basic features, and has spam protection built in? SecureSMTP ships everything you need from day one. 100 submissions/month free forever.
Ready in five minutes.
Free forever for 100 submissions / month. No credit card, no trial expiry.