Spammers using Contact Us

Katrina

Projects Admin & Graphics Team Member
Administrator
Graphics Team
Joined
Feb 10, 2019
Messages
20,453
Reaction score
10,852
FP$
2,593
Ever since Christianity Haven converted to XenForo we've been getting a ton of spammers using Contact Us. What tricks do I have to curb this behavior? Some are posting as Guest.
 
@Lammchen I wanted to recommend OzzModz add-on the Spaminator if you haven't got it yet. While it's practically impossible to prevent anyone from using the contact form it's blocked well over 100 bots from signing up on my site in only 1 week that I've had it installed. Not a single bot has signed up since I installed it and I was getting hit hard before I had the add-on. There's tons of 5 star reviews on it. The add-on is $24 but is well worth it in my opinion. Now I can focus on legitimate registrations instead of having to worry that bots are signing up on my site.

Wasn't trying to divert that thread as I assume your speaking of real people spamming, just felt the need to suggest the add-on. As for ordinary spammers, there's nothing you can really do but unless you could somehow get their ip address. Then you could see if they had a matching account and ban their ip address. If emails are being sent to your administrative account and not an external provider, I believe it may be possible to get the ip address. Though you'd have to check around.
 
at least that only you and your staff get to see it, just remove it each time and don't reply. They will get so bored and stop
 
at least that only you and your staff get to see it, just remove it each time and don't reply. They will get so bored and stop

The Russians don't get bored. They don't even post in English LOL
 
True but you always got to play their game. YOu can block ips or even block the country 😛

I'm afraid of blocking too many IPs and then causing problems with real members wanting to join later. Has anyone experienced that?
 
Blocking countries is easy. But that is an old trick. Spammers have gone smart. They know how to mask their IPs. These are mostly work of the bots.
 
I'm afraid of blocking too many IPs and then causing problems with real members wanting to join later. Has anyone experienced that?
In a way I have, I had so much bad fake traffic about a year ago that came out of nowhere and turns out that all the traffic was coming from China. Doesn't matter what I do it continues on. So I blocked the country and fixed the issue and months later I think I removed the blocked (I think) 😛
 
It surely works as long as spammers do not hire people to do their job from some other country.
 
Blocking countries is easy. But that is an old trick. Spammers have gone smart. They know how to mask their IPs. These are mostly work of the bots.
True, but you still need to be proactive in banning accounts. To be fair, some users (including myself) complained about the Contact Us spam to xenForo, and they said that one of the patch updates - it's got spam mitigation working in the background - derived from the normal account mitigation. All you need to do is get API's for StopForumSpam, Honeypot, etc. and put in the ACP side of xenForo. I thought we went over this in another thread, @Lämmchen? Get to work, my friend.
 
IPB all the way as they have spam defiance built into the system
 
reCAPTCHA filtering is not available ?
reCAPTCHA v3 is not available on xenForo 2... yet. But, the spam mitigation does the job quite well...
xenForoSpamMitigation.png
See that? Green is IP Address, Orange is e-mail address. You can click the green button to check the IP address of the user. It tells you exactly why the user was put into moderation queue. StopForumSpam is a database of spammers with e-mail addresses. If that account accrues enough spam, it wills show you "blacklist" that means it's a known spammer. You can do whatever you want here, but you will run into false positives, so check the IP before doing anything.

This shows how powerful the spam mitigation is, really. The contact us form uses this system now, since xenForo updated the software to use this exact panel. I have not gotten any more spam from this section since that particular update.

That alone won't work, though, you need to go through your email, and blacklist any spam you see until you're comfortable. If you have cpanel, you can set spam mitigation, there, too.

You have to be proactive until they stop. It won't completely stop, but it will get smaller, and smaller, and smaller. Enough that you'll just lay in your bed, brushing away the spam like you're just sleeping well that night.
 
Last edited:
Nice that it works for you. I had some wrong flag issues with SFS and Project Honeypot in the past.
 
Back
Top Bottom