It was only when we were getting the first of our 2022 websites live earlier this week that I thought it might be a good idea to share what we do to help hold back the spam tide for our website projects.
You need emails and forms on your website otherwise how are your potential customers going to get in touch? Especially all those millenials and Gen Z's who prefer quick, non verbal communication. They don't like to waste time calling on the phone do they?
By the way did you know there's now a generation called Generation Alpha? Or mini millenials as its also been termed. This will be the generation born from 2010 up to 2024. It will be interesting how the world of marketing and sales changes for them, won't it?
I'm getting slightly off topic....
The digital world feels like it's brimming over with spam bots or sometimes actual real people trying to have a nosey and get access to your website and data. Sometimes this can be a flurry of emails from someone who needs a bank account TODAY to deposit 10 million dollars as the executor of someone's estate and then reward you with a million dollars for your trouble. Or a Nigerian prince needs your help as he has too much cash and he needs to stash it with you NOW! Yep, we've all had those emails over the years haven't we?
Spam can also mean an onslaught of 100's or 1000's of attempts on your forms that can end up overwhelming the server your hosting is on and mean your website could go down. Let's hope only temporarily. Fingers crossed.
Because the big G is forever priding itself on ridding the web of it's digital flotsam it's made this particular tool free and accessible. It's not new but there have been a couple of versions of it. We usually implement the latest version for our client's websites. It's called the invisible version, V3 and has been around since 2018. We've been adding it for almost 2 years now as standard. The version we implement means it does its work in the background and only deploys its API when a user is deemed as a risk. So not a 100% fraud proof but like any sort of prevention it's off putting enough for the bots or humans to try elsewhere. Somewhere more 'inviting' that has no fraud prevention in place.
You might have seen it's image in the bottom right hand corner of websites. Some websites have it on every page but it only needs to be on the pages that actually have the web forms.
Image of Google reCAPTCHA on our website

If you'd like to find more out about it then Wiki is as good a place as any to brush up on your Google reCAPTCHA knowledge.
To get set up you need to create a Google account or sign in. Once there, navigate to the reCAPTCHA page. From there navigate to the V3 Admin Console you'll see in the header.

There's a simple form to fill in that asks for your domain and email address. You can also add in emails for team members. We ask business owners to add our email in so we can quickly access if we need to. The only thing that has changed in the last couple of months is even though it's still a free service up to 1 million assessments per month they now need a payment card registered to the Google account. 1 million is a lot of assessments but there is an enterprise level too for very large sites.
Once you've completed the form you will be taken to a page like the image below that shows you your secret keys. All very Harry Potter sounding isn't it? We need these keys to implement the reCAPTCHA onto the website. If you're doing it yourself or want to ask your developer to implement it for you then there is a developer's guide to reCAPTCHA.
There it is! You have your spam protection in place to protect your web forms.
There's also a reCAPTCHA plugin that makes it easy to add to protect most Wordpress sites. If you subscribe to one of our Wordpress support packages this is the type of job we'd do to look after your website.
If you have any questions about implementing this on your website then don't hesitate to get in touch.
We're happy to help.