Your customer list is valuable because the people on it have actually visited your website. Online forms and checkout pages are the two main entry points where visitors leave their contact information, and they are also the most common targets for spam bots. Some bots don't even load the page; they simply blast the site with form submissions or leave fake emails on the checkout page.
Kanorio has built-in multi-layered checks for both of these entry points. This article explains how these checks work, what you and your visitors will see, and what situations still require your manual attention.
Think of these as security checkpoints before entering a building. None of them require any setup on your part—they start working as soon as your site is published.
Checkpoint 1: Network Edge. All Kanorio websites are served via the global Cloudflare network. Requests identified as clear bot traffic rather than a browser are challenged before they ever reach your site. This layer also handles DDoS protection and firewalls; see Website Security Protection for details.
Checkpoint 2: On-page checkpoints. Forms and checkout pages contain multiple checkpoints that a human filling out the form normally would never trigger. Bots, which don't render the page and simply fill in fields, are likely to trigger these. Any submission that triggers these is immediately discarded.
Checkpoint 3: One-time pass. When a visitor opens a page, the system issues a pass for that specific submission. It is valid only for that form (or that checkout session), expires after one use, and times out if left idle for too long. Copying the pass to another form or submitting the same one twice will not be accepted.
Checkpoint 4: Submission rate limits. Each source is limited in how many submissions they can make in a short period, and each form has a daily cap on how many entries it can receive. Even if the previous layers are bypassed, large-scale spamming is prevented.
Online forms have one extra layer compared to checkout pages: Before clicking submit, the visitor's device must complete a short computation. This is the brief human verification you see on the form. For a human, it takes less than a second; for a bot trying to send thousands of submissions, the computational cost per entry makes it unprofitable.
Only submissions that pass all checks will create a contact and send you a notification. Submissions that fail are never saved.
| Entry Point | Visitor Experience |
|---|---|
| Checkout Page | Nothing. All checks happen in the background with no extra steps or verification screens. |
| Online Form | Before clicking submit, visitors will see a "I'm not a robot" checkbox that completes in under a second. It is provided by the platform, follows your site's brand colors and border radius, displays text in your site's language, and cannot be disabled. |
We don't use human verification on checkout pages because adding an extra step to the checkout process causes drop-offs. Forms are where visitors proactively leave contact information, so a brief confirmation is an acceptable trade-off.
No third-party verification scripts. Many websites embed services like Google reCAPTCHA. While effective, it means that every time a visitor fills out a form, their data is sent to a third party, potentially introducing tracking cookies. Kanorio's checks are handled entirely by our own servers, so visitor data is never sent elsewhere. This aligns with our Visitor Privacy and Data Handling principles.
The human verification on forms uses the open-source ALTCHA (MIT licensed, code is public and auditable, and used by German, French, and UK government sites as well as the US SEC). It works on the principle of "Proof of Work": the visitor's device completes a small computation to prove it isn't a bulk-spamming bot. The entire process happens on the device; the challenge is generated by Kanorio's server, and the answer is returned only to Kanorio. It does not connect to any external services, set cookies, or perform fingerprinting. You won't see third-party logos or links on your form, and you don't need to add anything to your privacy policy.
Custom domains are treated equally. Checks are not tied to a specific URL. Whether a visitor arrives via yourbrand.kanorio.com or a custom domain, the protection is identical. You don't need to apply or configure anything for each domain.
No keys, quotas, or billing to manage. Some platforms require site owners to apply for API keys from a verification provider and paste them into the dashboard, and charge extra for high usage. Kanorio includes this in all plans with no extra steps.
Blocked content simply doesn't exist. It isn't dumped into a "spam folder" for you to clean up, nor does it count against your form's "entry limit."
The platform learns from all sites. Any device identified as a spam source on one Kanorio site will have its submissions to other sites automatically classified as spam for a short period. This judgment comes only from Kanorio's own network, is not shared with third parties, and does not permanently remember anyone. It clears automatically after a while, or when you unmark a submission as spam.
It blocks bot spam, not everything you might not want to receive. The following may still get through:
For this type of content, forms have an additional Content Check: submissions using disposable email addresses, messages filled with links, or the same text appearing repeatedly across multiple sites in a short time are automatically moved to the form's "Spam" category. These will not create a contact, notify you, or send any messages to the sender.
For information on checking spam, correcting misclassifications, marking as spam, and using "Pause submissions," "Entry limits," or "Limit to one per person" to block bulk spam, see Online Forms.
Checkout pages do not have free-text fields and only perform a check for disposable emails: checkout data submitted with a disposable email will not be recorded.
Submissions that don't pass the checks are not saved, and we intentionally do not store them. The effectiveness of this protection is reflected in the absence of fake contacts in your list, rather than a number.
No. Protection for forms and checkout pages is built-in, and there is no toggle in the dashboard. There are no extra steps during checkout; for online forms, you will see a brief human verification before submitting.
No. It is a key layer for blocking bulk spam, and disabling it would significantly reduce the effectiveness of the other layers. It takes less than a second for a human.
No one. It uses the open-source ALTCHA technology, where the computation is completed on the visitor's device. The challenge and answer only travel between your site and Kanorio; there is no third-party involvement and no cookies are set. This is why you won't see Google or other provider logos on your form.
Adding an extra step to the checkout process causes drop-offs, so checkout page checks are handled in the background. Forms are where visitors proactively leave contact information, so a brief confirmation is a reasonable trade-off. Both are handled by the platform, and no setup is required.
Yes. Checks are not tied to a specific URL. Protection is identical for custom domains and Kanorio URLs, with no extra application or configuration needed.
First, go to "Customers › Online Forms" and enter the responses page for that form. Filter the status by "Spam"; most sales pitches should already be there and won't bother you. For those appearing in the normal list, click "Mark as Spam." If the volume is high, you can enable "Pause submissions" or set an "Entry limit." If you suspect it's bot spam that wasn't blocked, please contact us following Security Troubleshooting and include a few examples.
Content checks are rule-based and may occasionally misclassify messages with many links or those using disposable emails. Simply click "Unmark as Spam" to create the contact. If the person opted into a subscription at the time, their consent will also be restored.