Spam Protection for Your Forms
WP-ImmoMakler protects every form in the plugin from spam: the contact form in the property detail view, the property alert form, the withdrawal form, as well as the Propstack search profile form and the Propstack newsletter sign-up.
Protection is built up in tiers. You’ll find all the settings bundled together in your website’s backend (wp-admin) under WP-ImmoMakler → Settings → Spam Protection.
The principle: never lose a genuine enquiry
Section titled “The principle: never lose a genuine enquiry”No spam protection can reliably tell whether a submission comes from a human or a bot. That’s why WP-ImmoMakler follows this rule: when in doubt, deliver it.
The reasoning is a simple trade-off. A spam email landing in your inbox costs you a few seconds. A genuine enquiry that’s silently discarded may cost you a client – and you’d never even know. The defaults are chosen accordingly.
Level 1: Invisible checks
Section titled “Level 1: Invisible checks”Every form checks for typical bot characteristics in the background. There’s nothing for your visitors to see or operate.
Honeypot. Every form contains an extra input field that’s invisible to visitors. A human never sees this field and leaves it empty. A spam bot that parses the form mechanically, however, fills it in and gives itself away.
Origin. Every form receives a signed characteristic when it’s loaded. If it’s missing or the signature doesn’t match, the submission didn’t come from a regularly opened form on your website – typical of bots that send their data straight to your website’s address without ever opening the page.
Fill time. The same characteristic reveals how long filling in the form took. If a form is submitted in under three seconds, no human was at work.
This tier is always active and requires no configuration. You can, however, decide what happens with a suspicious submission:
Deliver and flag (default)
Section titled “Deliver and flag (default)”The enquiry is delivered to you as normal. The subject line additionally contains [Suspected Spam], and a short note at the top of the message explains why the submission looked suspicious. You decide for yourself whether it’s actually spam.
The advantage: no genuine enquiry is ever lost. This matters more than it might sound – even a human visitor can end up filling in the invisible field, for example when a password manager or browser extension auto-fills form fields.
For automated processing, every email flagged this way also carries the header X-ImmoMakler-Spam-Suspected. Its value names the cause: honeypot, origin, or speed. That lets you set up a rule in your email client that automatically sorts suspicious enquiries into their own folder instead of deleting them.
Enquiries that reach your CRM software directly
Section titled “Enquiries that reach your CRM software directly”Enquiries via the property contact form don’t always go to you as an email only – depending on your setup, they can also go straight into your CRM software. There too, a suspicious enquiry is flagged, as far as the respective transmission channel allows it:
- OpenImmo Feedback XML: If you’ve enabled the Attach XML option, the
anfragefield in the XML file starts with the spam suspicion note. That way, a CRM system that picks up the enquiry from the XML file sees it too. - ImmoScout24 message manager: The note appears at the start of the message that arrives in the message manager.
- CasaOne: The note appears at the start of the message transmitted to CasaOne.
- Publimmo: As described above, the enquiry email carries the
[Suspected Spam]subject prefix, the note, and theX-ImmoMakler-Spam-Suspectedheader.
Here too, the enquiry is transmitted in full. The note is simply prepended to it.
Reject the enquiry
Section titled “Reject the enquiry”The enquiry is not delivered. The sender instead receives a notice explaining that they were mistakenly flagged as a spam bot, along with a request to contact you by email or phone instead.
There’s nothing to flag on the property alert form – the only email it sends goes to the address in the form, not to you. So on a confident signal, no confirmation email is sent at all, regardless of this setting. The bot gets nothing; a visitor who was wrongly flagged can simply try again, since an unconfirmed property alert is discarded either way.
The same applies to the Propstack newsletter sign-up: on a confident signal, WP-ImmoMakler doesn’t create a contact in Propstack and doesn’t send a double opt-in email.
This setting keeps more spam out of your inbox. However, it can occasionally cost you a genuine enquiry – specifically when the invisible field gets filled in without the visitor’s intent. So only choose it once flagging alone still lets through too much spam.
Rejection only happens on unambiguous signals. A missing origin characteristic alone never leads to rejection, only to a flag: it can also result from your site being served from a cache that still predates the update. Your visitor isn’t at fault for that – and a genuine enquiry must never be lost because of it.
Level 2: CAPTCHA providers
Section titled “Level 2: CAPTCHA providers”In addition, a CAPTCHA checks whether a request came from a human. ALTCHA is enabled by default; you can also choose between seven externally hosted CAPTCHAs – captcha.eu, Cloudflare Turnstile, Friendly Captcha, hCaptcha, and Google reCAPTCHA (v3, v2 challenge, v2 invisible) – or “No CAPTCHA (Level 1 only)”. Only one CAPTCHA can be active at a time.
With ALTCHA, your visitor’s browser solves an automated computational task in the background, issued and verified by your own server – without any contact to a third party and without cookies. For a single visitor the effort is imperceptible; for a bot submitting forms en masse, it adds up to a real obstacle. Unlike the honeypot, a failed check is always rejected – it’s a far more reliable signal.
The other CAPTCHAs are third-party services and transmit your visitors’ data to their own servers for verification; see the third-party data protection notice below for details.
Note that all CAPTCHAs require JavaScript: visitors with JavaScript disabled or blocked will no longer be able to submit the form. If it matters to you that those visitors can submit your forms too, choose “No CAPTCHA (Level 1 only)”.
If a property alert fails the CAPTCHA, WP-ImmoMakler logs it in the spam log (immomakler-spam-…log in the import directory), together with the CAPTCHA provider and whether a solution was submitted at all. WP-ImmoMakler rejects a property alert without a solution without asking the provider. It therefore appears only in this log and not in your CAPTCHA provider’s statistics. Accepted property alerts show in the backend which check they passed (see Property Alerts).
Full setup details are in the ALTCHA documentation and under CAPTCHA Providers.
Rate limit on automatic reply emails
Section titled “Rate limit on automatic reply emails”Some forms send an email to the address entered in the form: the property alert confirmation, the contact form’s automatic acknowledgement, a withdrawal’s acknowledgement, and the double opt-in email for the Propstack newsletter sign-up. Without a limit, this could be abused to flood someone else’s inbox with such emails.
WP-ImmoMakler therefore limits how many such emails are sent from the same IP address within an hour. Normal visitors never reach these values.
For property alerts, set the value under WP-ImmoMakler → Settings → Spam Protection (default 5, 0 disables the limit). For the contact and withdrawal forms’ confirmation emails, the limit is 10 per hour and can be adjusted via the immomakler_contactform_confirmation_rate_limit and immomakler_widerruf_confirmation_rate_limit filters. The Propstack newsletter sign-up allows 5 sign-ups per hour; you can change the value via the immomakler_propstack_newsletter_rate_limit filter.
The same applies to the newsletter sign-up in the contact form: if someone ticks the box there to subscribe to the Propstack or Mailchimp newsletter, the newsletter service sends a confirmation email to the address entered. If the submission carries a confident signal, the sign-up is withheld as a result, regardless of the Level 1 setting. In addition, at most 5 sign-ups per hour and IP address are allowed, shared across all connected newsletter services; you can change the value via the immomakler_contactform_newsletter_rate_limit filter (0 disables the limit). Either way, the enquiry itself still reaches you – only the newsletter sign-up is skipped.
Third-party data protection notice
Section titled “Third-party data protection notice”With the default ALTCHA setting, as well as with “No CAPTCHA”, every tier of the spam protection runs exclusively on your own server. No data is transmitted to third parties, no cookies are set, and no behavioural data about your visitors is collected.
If you choose Cloudflare Turnstile, Friendly Captcha, hCaptcha, or Google reCAPTCHA instead, your website transmits your visitors’ data (including their IP address) to the respective provider’s server for verification. Please check whether you need to list the chosen provider in your privacy policy. With Google reCAPTCHA, this data is transferred to the United States. Since the US does not offer a level of data protection equivalent to that of the EU, this can create GDPR-related risks and potential liability issues without users’ explicit consent. Before choosing Google reCAPTCHA, check whether this is compatible with your privacy policy and adjust it if necessary.
captcha.eu, Cloudflare Turnstile, Friendly Captcha and hCaptcha all explicitly position themselves as more privacy-friendly alternatives to Google reCAPTCHA. The same applies here: check their current privacy policies yourself before deciding on a service. captcha.eu processes data exclusively in Austria, on every plan; for data protection reasons, WP-ImmoMakler deliberately connects to the service via the direct route to those servers, bypassing the CDN that captcha.eu places in front by default. With Friendly Captcha, WP-ImmoMakler serves the widget script from your own server rather than from a content delivery network (CDN), so no additional provider is added; and the “Friendly Captcha: Server Region” setting lets you restrict the service to EU servers (only available on certain Friendly Captcha plans). Details on all seven externally hosted CAPTCHAs can be found under CAPTCHA Providers.