Jotform gives you captchas, email validation, submission limits per IP or cookie, unique field limits and free-domain blocking. Configured together they stop most automated submissions. None of them catches spam typed by a person, and none of them tells you where a submission came from.
What Jotform provides
Verify exact menu locations in the product, since Jotform’s interface changes. The capabilities themselves are documented.
| Option | What it does | Worth using? |
|---|---|---|
| reCAPTCHA or hCaptcha field | Challenge before submission | Yes, as a later layer |
| Email Validator | Sends a verification code to the address | Strong, adds friction |
| Clearout integration | Validates addresses via API | Useful, may use credits |
| Unique Submission Limit | One submission per IP or cookie | Good against repeats |
| Unique Field Limit | One submission per email address | Good against repeats |
| Disallow free email domains | Rejects Gmail, Outlook and similar | Careful, see below |
| Password-protect form | Locks the form entirely | Only for private forms |
Source: Jotform’s own documentation, checked September 2026.
A sensible order
Start with the limits. Unique Submission Limit and Unique Field Limit cost your visitor nothing and stop the repetitive submissions that make up a large share of the volume.
Then add a captcha. hCaptcha or reCAPTCHA as a form field. It will catch the straightforward automated traffic. Expect it to do nothing about anything else.
Consider email verification carefully. It works, and it adds a step between a customer deciding to enquire and the enquiry existing. On a quote request form that is a real conversion cost. On a newsletter signup it is fine.
Be careful with free-domain blocking. If your customers are businesses, switch it on. If your customers are consumers, and for a plumber, HVAC company or pest control business they are, it will reject real jobs. A blocked submission leaves no trace anywhere, so you will never see what it cost. The longer version.
What none of it catches
Two things, and they are the two that matter most.
Spam typed by a person. A web design pitch written by a human passes every captcha, satisfies every email validator, and arrives from a unique address and IP. Every option in the table above is looking for automation, not what sent it. Why that is structural rather than a configuration problem is covered in reCAPTCHA not stopping spam.
Where the submission came from. Jotform records what someone typed. It does not record which ad, search or referral brought them, or what they read before deciding to enquire. That matters more than it sounds, because the junk that does get through still gets counted as a lead somewhere, and whichever channel is carrying it ends up looking like your best performer. What spam leads do to your marketing numbers works that through.
Running Jotform with Lead Source
Lead Source does not stop spam arriving through your Jotform. The form is Jotform’s and the submission is created on Jotform’s servers; Lead Source receives a copy of it afterwards and does not modify it. Nothing added after the fact can prevent a submission that already exists.
What it does add on a Jotform is the part nothing in the table above records: the real source, the landing page and the page journey behind every submission, on the individual lead record.
So the two problems have different answers. If your attribution is the gap, add Lead Source and keep your form. If the spam is the gap, the fix is switching the form rather than adding a layer in front of it, because prevention has to happen where the form is built. Jotform lead tracking covers the setup, and form spam protection covers what a Lead Source form does about spam.