What Percentage of Form Submissions Are Spam? (2026 Data)
The LeadShield.ai Team · 01 September 2026
Search for "what percentage of form submissions are spam" and you will find confident numbers everywhere and sources almost nowhere. The honest answer is that nobody publishes an authoritative figure for form spam specifically. What does exist is verified data on automated traffic as a whole: the 2026 Thales Bad Bot Report found that automated traffic accounted for 53 per cent of all observed web traffic in 2025, and 40 per cent of all traffic was malicious bots. Your own form's share depends on exposure, not on an average. Here is what the data actually says, and how to measure your own number in about a minute.
What percentage of form submissions are spam?
No authoritative statistic exists for form spam rates, and any site quoting one is usually misquoting traffic-level research. The most-cited source, the Thales (formerly Imperva) Bad Bot Report, measures internet traffic, not form submissions. Its 2026 edition contains no form-spam percentage at all. What it does show is the environment your forms sit in: automated traffic is now the majority of everything on the web, and the malicious share is growing. A contact form on a quiet brochure site and a lead form fed by paid ads in a competitive niche will see wildly different junk rates, which is why the number worth having is your own.
What does the 2026 bot data actually say?
The 2026 Bad Bot Report, the 13th annual edition published in April 2026, reports that "automated traffic accounted for 53 percent of all observed web traffic in 2025." Of that, bad bots generated 40 per cent of all traffic, up from 37 per cent the year before. Benign automation, including search engine crawlers, made up the other 13 per cent. Human traffic fell to 47 per cent. Thales says it blocked 17.2 trillion bad bot requests during 2025, and that the average number of AI-driven bot attacks it mitigated rose more than tenfold, "bringing the daily average of attacks blocked to 25 million."
Two honest caveats belong next to those figures. First, they describe traffic across the internet, not submissions through your form; the report itself never claims otherwise. Second, "bad bot" covers credential stuffing, scraping, denial of service and ad fraud, not only form abuse. The numbers set the scene. They do not answer the question on their own, which is precisely why measuring your own rate matters more than quoting an average.
Why does your form spam rate differ from the average?
Form spam concentrates where the incentives are, so your rate depends on exposure. Four factors move it most. Paid traffic: forms reached through Google or Meta ads sit in the same ecosystem as click fraud and get probed by scripts chasing converting traffic. Niche: legal, finance, home services and solar attract more junk because the payouts for a genuine lead are high. Visibility: a form on a high-traffic public page gets crawled and submitted to more than one buried behind a login. Protection: a naked form with no checks will collect everything a bot pushes at it, while layered validation quietly removes most of it.
This is also why quoted averages mislead. A vendor serving small e-commerce sites might report single-digit spam rates. An agency running lead-gen campaigns in a spam-heavy vertical could see a quarter or more of its clients' submissions flagged. Both numbers are real. Neither predicts yours.
What counts as a spam submission?
A spam submission is any form entry that was not sent by a real person with genuine interest. Three kinds dominate. Classic bot fills, scripted and often garbled, with disposable or malformed email addresses and nonsense in the message field. Human solver spam, paid humans or farms pushing through CAPTCHAs for SEO link placement or lead-resale schemes. AI-written enquiries, the newest and slipperiest kind: coherent, personalised-seeming messages generated by language models that read like a real prospect until you look closely. Deterministic checks, the format, domain and mailbox tests, catch the first kind reliably. The third kind is harder, because nothing about the email address is wrong. That gap between format validity and genuine intent is exactly where a raw spam-rate number needs interpretation, and where live contextual analysis on Professional and Enterprise plans does work a CSV export cannot.
How do you measure your own form spam rate?
You measure it from your own data, and it takes about a minute. No installation, no waiting for traffic, no guessing.
- Export last month's submissions or leads from your CRM, including email, phone, name, message and timestamp where available.
- Run the export through a deterministic list check. LeadShield's free lead audit screens up to 250 rows per upload with no account, no card and no snippet; paid plans handle 1,000 or 5,000 rows.
- Read the verdicts. Every row comes back valid, suspicious, invalid or duplicate, with plain-English reasons.
- Divide flagged rows by total rows and multiply by 100. That is your spam rate for that export.
- Re-run monthly and after any campaign change, and compare against the leads your sales team manually disqualified. The gap between the two is usually instructive.
⚠️ A worked illustration: an export of 250 rows returns 61 flagged (invalid, suspicious or duplicate). 61 ÷ 250 × 100 = 24.4 per cent. That figure describes one hypothetical list, not a benchmark; your export will say something only about your traffic.
One limit worth stating plainly: bulk CSV cleaning runs deterministic layers only. A CSV row has no browser session and no IP address, so behavioural and contextual signals cannot apply to it. Treat a file audit as a floor, not a ceiling. Live protection at the form sees more, because it sees the submission as it happens.
What do the ad platforms do about invalid traffic?
Google defines invalid traffic as "any activity that doesn't come from a real user with genuine interest," which can include "accidental clicks... fraudulent clicking by competing advertisers, advertising botnets and more." Its filters "catch it before it's ever charged to the advertiser," and when invalid activity slips through, "that money is credited back to the advertisers." On the click side, the platforms run their own defences, and a repeated GCLID is charged at most once.
The part Google cannot fix for you is the conversion. A bot that submits your form creates a conversion signal the ad algorithm reads as success, and the campaign optimises towards more of whatever produced it. Google's own advertiser guidance tells you to record the IP address, GCLID, referrer URL and user agent for form submissions and watch for suspicious patterns, which is an admission that the form itself is your responsibility. We covered the feedback loop in detail in how junk leads train ad platform optimisation.
How do you lower your form spam rate?
Layer the checks rather than relying on one. Start with deterministic validation at the point of submission: email format, disposable domains, dead mailboxes, phone plausibility. Add a honeypot field and fill-time checks, which catch scripts without adding friction for people. Keep a CAPTCHA if you have one, but know its limits; we tested what reCAPTCHA does and does not stop in does reCAPTCHA stop fake leads? On Professional and Enterprise plans, behavioural and AI contextual analysis score the submission itself, and those plans add exclusion exports, IP lists and hashed suppression files for Google Customer Match and Meta Custom Audiences, so the junk you catch stops feeding the platforms that sent it.
LeadShield does this as a 60-second JavaScript install, and you can see it score an email before you commit to anything at the live demo.
Frequently asked questions
Is there an average form spam rate I can quote internally? No reputable publisher produces one. Traffic-level data from the 2026 Thales report shows bots at 53 per cent of all traffic, but no form-level statistic exists. Measure your own export instead; it takes about a minute and survives scrutiny.
Do CAPTCHAs stop spam submissions? They reduce scripted bot fills, which is worth having. Paid human solvers and AI-written enquiries pass through them, because those submissions look human. Use CAPTCHA as one layer, never the whole defence.
Does Google charge me for bot form fills? Not in the way you might fear, and not in the way that matters most. Google filters invalid clicks and credits advertisers when it finds them. The real cost of a bot fill is the false conversion signal, which teaches the algorithm to find more of the same.
What is the difference between a bot fill and an AI-written enquiry? A bot fill is a script, usually detectable from format signals alone. An AI-written enquiry is coherent and personalised-seeming, with nothing wrong at the format level, which is why contextual analysis exists on Professional and Enterprise plans rather than in a CSV check.
Can I check my spam rate without installing anything? Yes. The free lead audit at leadshield.ai/audit screens a 250-row export with no account, no card and no snippet, returning a verdict and reasons for every row on deterministic checks.
Ready to put a number on your own list instead of quoting someone else's? Run your export through the free 250-row lead audit and see exactly what is sitting in your CRM.
Fake leads draining your budget?
LeadShield blocks bots, disposable emails and AI spam at the form. 60-second install.
Start free 14-day trial