Nextdeal

    New Spam Detection in Web Forms: An Additional Layer of Protection to Keep Your Zoho CRM Clean and Secure

    April 7, 2026, 6:23 PM By Nextdeal Srl

    New Spam Detection in Web Forms: An Additional Layer of Protection to Keep Your Zoho CRM Clean and Secure 

    One of the most anticipated features—spam detection in web forms—is finally here!

    Web forms are an essential tool for generating records, but they are also vulnerable to submissions from unauthenticated or malicious sources, which can lead to the collection of spam records, clogging up CRM systems and reducing data quality.

    Zoho CRM's new spam detection feature provides an additional layer of security and reduces reliance on basic measures such as CAPTCHA and double opt-in, thereby improving the quality of data collected from web forms. Users no longer need to manually check for potential spam records.

    Let's see how spam detection filters out suspicious records from web forms and helps keep the CRM clean and organized.


    What does spam detection do?

    It offers the following benefits:

    • Simplifies the manual review of potential spam in web forms.
    • Detect suspicious emails by identifying invalid or suspicious email addresses and assigning a spam likelihood score.
    • It retains these records for manual approval.
    • It automatically blocks spam records, preventing them from entering the CRM.

    What happens to web form submissions?

    All submissions are evaluated according to predefined criteria and scanned for spam.

    • Valid, non-suspicious records (from verified IP addresses) are entered into the Leads module.
    • Suspicious submissions are flagged as potential spam and placed in the " Awaiting Leads " page (formerly "Approve Leads") pending approval.

    These records are assigned a Spam Possibility Score.

    • The " Record Source " column displays details such as IP address, web form name, and URL.
    • The " Spam Possibility " column shows the probability of spam as a percentage.

    If you hover your mouse over the info icon, you can see the main reasons for the score.


    Factors that contribute to the spam score

    Here are a few examples:

    • Sent by a bot/crawler
    • Invalid phone numbers (incorrect, toll-free, or suspicious)
    • Invalid email addresses (unauthorized, temporary, or known spam domains)

    A New Level of Security: Honeypot Field

    It is a mechanism that detects bots using hidden fields in forms.
    If these fields are filled out, the system flags the entry as spam.


    Spam probability levels

    • 🢢 Green: 1%–20%
    • 🟠 Orange: 21% – 70%
    • 🔴 Red: 71% – 100%

    Management of pending records

    Previously, records were only:

    • approved
    • together
    • resolved
    • eliminated

    Administrators can now also:

    • block the IP addresses of records with high spam scores

    The " Block IP " button is available alongside "Merge," "Approve," and "Resolve."

    Blocked IP addresses:

    • end up in the " Blocked" category
    • are also automatically blocked by the system if they appear on the Zoho blacklist

    Note: Locked records are deleted after 60 days.


    How to enable spam detection

    When configuring a web form:

    • The Spam Detection section is available
    • You can set the threshold using a slider

    By default:

    • threshold: 90% – 100%

    It can be changed at any time.

    Note:
    Only records within the selected range are placed on hold.
    Example: If you set the range to 80–100%, only those within that range will be considered spam.


    Revised Approval Page

    • “Approved Leads” → “Pending Leads”
    • Improved interface for navigating between categories
    • Keep track to avoid forgetting

    New filters available:

    • By Source (web form or import)
    • Based on spam probability
    • By fields (creation date, owner)
    • By IP (web form) → distinguishes between manual and automatic blocks


    Need more help? Request a quote

    Nextdeal Srl