Our spam filter combines two layers: an email filter that catches throwaway addresses and signup-evasion tricks, and a traffic filter that blocks requests from networks heavily associated with abuse — VPNs, proxies, Tor exits, datacenters, crawlers and more. Each layer can be tuned independently per site.
Spam Filter: Add-on for Procaptcha and Prosopo Protect
Spam Filter is a Procaptcha add-on — it runs inside every Procaptcha verification, not as a separate SDK or endpoint. It pairs an Email Filter (throwaway addresses, disposable-domain detection via DNS/CNAME/MX lookups, custom regex blocklist) with a Traffic Filter (eight independent network-class toggles: abusive networks, VPN, proxy, Tor, datacenter, crawler, mobile, satellite), each tunable per site.
Because it lives inside the verification path Procaptcha already runs, there's no extra endpoint to call and no separate integration to maintain. Enable the filters you want in the dashboard; every verification your captcha handles is evaluated against them; blocked requests come back with a distinct reason per filter so your application can show a tailored message.

How Spam Filter runs inside Procaptcha
Rule-based evaluation that happens during each Procaptcha verification, with a distinct reason for every block.
Email Filter (curated + custom)
Disposable-domain detection
Traffic Filter (eight independent toggles)
Tunable per site
Distinct reason per block
Why Spam Filter is worth turning on
Zero extra integration
Runs inside the Procaptcha verification you already have. Toggle a filter in the dashboard and the next captcha verification enforces it — no new endpoint, no new SDK, no code deploy.
Curated by our threat research team
Default email patterns and abusive-network signals are maintained centrally. New evasion tricks caught for one customer are blocked for everyone the moment the pattern lands in the default set.
Per-block reason codes
Every blocked request comes back with a distinct reason per filter — VPN, Tor, disposable domain, custom-regex match — so your application can show a tailored user message instead of a generic failure.
Independent per-site toggles
Eight traffic filters and the email filter each toggle independently per site key. Sensitive endpoints (signup, checkout) can run tight rules while low-risk endpoints (documentation, marketing pages) run permissive.
No user-facing widget
The evaluation happens server-side during the Procaptcha verify call. Real users see nothing different from a normal Procaptcha challenge; blocked requests fail before your form's success flow runs.
How Spam Filter fits into Procaptcha
Spam Filter is not a separate SDK, a separate <script> or a separate endpoint. It's a rule set that runs inside every Procaptcha verification — the same /verify call your backend already makes to Prosopo when a user submits a form or hits a protected endpoint. Enable the filters you want in the dashboard; the next verification enforces them. No new integration surface, no extra network hop, no code deploy.
Two rule layers evaluated per verification:
- Email Filter — matches on the email address the form submitted (or that your backend passed to
/verify). Curated patterns for throwaway addresses, optional normalisation, custom regex blocklist, disposable-domain detection via DNS. - Traffic Filter — matches on the network the request came from. Eight independent toggles for VPN, proxy, Tor, datacenter, crawler, mobile, satellite, and generic "abusive" networks scored by our upstream reputation feed.
Each layer can be toggled independently per site key, so the same Prosopo account can run tight rules on your signup endpoint and permissive rules on your comment form.
Why your forms keep getting spam
If your inbox is filling up with fake signups, your contact form is generating obvious junk, or your WordPress site keeps sending spam emails you didn't author, the cause is almost always the same: a bot is submitting your form directly, faster than any keyword filter or honeypot can keep up. The fix isn't a smarter inbox rule. It's stopping the submission before the form processes it.
Anti-spam measures that only run after submission (Akismet, server-side keyword filters, post-hoc email validation) treat the symptom. Prosopo's Spam Filter treats the cause — it evaluates during the Procaptcha verification, so an abusive request is rejected before your form's success flow runs.
Email Filter: stop signup spam
Most signup spam doesn't come from random email accounts. It comes from a small set of evasion techniques that turn a single mailbox into thousands of apparent addresses, or from networks of disposable inboxes that exist only to bypass verification.
The Email Filter catches both:
- Throwaway address normalisation. Throwaway variants from Gmail, iCloud, Yahoo and other major providers all resolve to the same mailbox. The filter optionally normalises addresses before applying your rules, so one rule catches every variant.
- Curated default patterns. A maintained ruleset that targets throwaway address tactics from the major providers used to bypass signup verification.
- Custom blocklist. Add your own patterns to block addresses unique to abuse you're seeing.
- Disposable-domain detection. Optionally rejects addresses from known throwaway providers — and follows the domain through redirects, CNAMEs and MX records so freshly-registered throwaway domains can't slip through by pointing at a known backend.
Traffic Filter: block abusive network sources
The Traffic Filter rejects requests by the type of network they came from. Each filter is an independent toggle, so you can build the exact policy your audience needs:
| Filter | What it blocks | Recommended for |
|---|---|---|
| Abusive networks | Networks with a strong abuse signal | Everyone — on by default for all accounts |
| VPN | Known consumer VPN services | Sites with high signup-fraud exposure |
| Proxy | HTTP, HTTPS and SOCKS proxies | API endpoints and high-value forms |
| Tor | Tor exit nodes | Most consumer-facing forms |
| Datacenter / Hosting | Cloud and hosting IP space | Sites whose users browse from residential networks |
| Crawler | Known automated bots | Most forms (excluding documentation/marketing pages) |
| Mobile | Cellular networks | Niche — only when fixed-line access is required |
| Satellite | Satellite internet | Niche — only when ground-based access is required |
Blocks are reported back to your application with a distinct reason for each filter, so you can show users a tailored message ("Please disconnect your VPN and try again", "This form isn't supported over Tor", and so on) rather than a generic failure.
What's on by default
- Free tier accounts get abusive-network blocking on by default. It's the single highest-signal traffic filter and is safe to leave on for any account. The remaining seven traffic filters and the Email Filter are opt-in per site.
- Professional and Enterprise include every filter, per-site tuning, custom regex patterns and Gmail-style address normalisation.
You need Procaptcha to use Spam Filter
Because Spam Filter runs inside the Procaptcha verification, you need Procaptcha (or Prosopo Protect) on the endpoint first — the widget on a form, or the server-side / edge Protect integration in front of an API. If you haven't yet, start with Procaptcha for a form-level integration or Prosopo Protect for a whole-site / API deployment; then turn Spam Filter on in the dashboard.
How Prosopo Spam Filter compares
| Capability | Prosopo Spam Filter | Akismet | reCAPTCHA / hCaptcha |
|---|---|---|---|
| Network-level blocking (VPN, Tor, datacenter) | ● | ● | ● |
| Email signup-evasion blocking | ● | ● | ● |
| Disposable-domain detection | ● | ● Limited | ● |
| Custom blocklists | ● | ● | ● |
| Per-block reason codes for tailored user messages | ● | ● Limited | ● |
| GDPR-compliant data handling | ● | ● Varies | ● |
Common use cases
- Spam bot protection — the broad use case: any form, any platform, any spam pattern.
- Stop credential stuffing — block disposable inboxes used to enumerate accounts.
- Prevent phishing campaigns — reject signups from networks tied to known abuse.
- Defend signup forms — catch throwaway address tricks used to bypass per-email rate limits.
Platform-specific guides
If you're trying to stop spam on a specific form plugin or platform, jump to the install guide:
- Contact Form 7 spam protection
- Gravity Forms spam protection
- WPForms spam protection
- Ninja Forms, Fluent Forms, Formidable Forms and more WordPress plugins
Configuration reference
Full details of the Email Filter rules, the eight Traffic Filter toggles and their block reasons are in the docs:
Request a Demo of Prosopo Spam Filter
Our Spam Filter technology is available as both a standalone product and part of our Enterprise suite. Contact our sales team for pricing options.
Trusted by companies of all sizes.
Our customers love us.
Hundreds of businesses have made the switch from reCAPTCHA and hCaptcha to Prosopo. Here's what they have to say.
Frequently Asked Questions
How does the spam filter work?
Will legitimate messages be blocked?
Defaults are tuned to minimise false positives — the curated email patterns target known evasion tricks rather than legitimate names, and the only traffic filter enabled by default targets networks with a strong abuse signal. Every filter is independently toggleable, so you can dial sensitivity to your audience.
Can the spam filter be integrated with our existing systems?
Yes, our spam filter offers flexible integration options including REST API, JavaScript snippets, server-side modules, and pre-built plugins for popular platforms. Our technical team can assist with custom integrations for proprietary systems.
Does the spam filter work for non-English content?
Yes. The email and traffic filters are language-agnostic — they look at addresses, domains and network properties rather than message text — so they work the same for content in any language.
Can you stop throwaway Gmail, iCloud and Yahoo addresses?
Yes. The Email Filter ships with a curated default ruleset that catches the throwaway address patterns used by Gmail, iCloud, Yahoo and other major providers — where a single mailbox can pose as dozens of distinct signups. You can also opt in to address normalisation, which resolves provider-specific variants to a single canonical address before evaluating your custom regex blocklist, so one rule catches every variant of the same mailbox.
Can I block submissions coming from VPNs, proxies, or Tor?
Yes. The Traffic Filter provides independent toggles for blocking VPN, proxy, Tor, datacenter, crawler, mobile and satellite traffic. Each block returns a distinct reason so your application can show the user a tailored message — for example asking VPN users to reconnect, or telling Tor users the form isn't supported on that network.
Are abusive networks blocked automatically?
Yes. Traffic from networks flagged for abuse is blocked by default for every account, including free tier. Paid-tier accounts can adjust this setting, but it is recommended to keep it enabled.
What traffic types can I filter?
The Traffic Filter supports eight independent filters: VPN, proxy, Tor, abusive ASNs, datacenter/hosting IPs, crawlers, mobile networks, and satellite connections. Each can be toggled on or off per site. Traffic filtering is a paid feature, except for abusive network blocking which is enabled for all accounts.
What else can Prosopo protect for you?
No matter the threat, we have a solution to keep your business safe.
Accessible CAPTCHA: verification that does not lock people out
An accessible CAPTCHA alternative. Invisible for most users, proof of work rather than an image challenge as the first escalation, image challenges disableable per site, keyboard and screen reader support.
Learn more
Prosopo Protect — Site-Wide and API Bot Protection
Site-wide and API bot protection from Prosopo — deploy at the edge (Cloudflare Workers, AWS Lambda@Edge) or as a server-side integration (nginx, Caddy, custom reverse proxies). Access Rules on every request, allow/block/challenge verdicts, branded interstitials on HTML pages, clean HTTP status + header on JSON APIs.
Learn more
Residential proxy detection
How Prosopo detects residential proxies — TCP fingerprint interrogation, IP intelligence, and a self-maintained proxy-vendor catalogue. Available on the Enterprise plan.
Learn more
Access Control — the Customer-Authored Layer
Access Control is the customer-authored rules layer of the Prosopo platform — layered on top of the named-detector library that catches the bulk of bots by default.
Learn more
Enterprise Bot Protection — the Prosopo Platform
Enterprise bot protection from Prosopo. One detection engine, delivered as a widget (Procaptcha) or at the edge (Prosopo Protect), same dashboard for both. Every block comes with a reason, in plain words, rather than a black-box score.
Learn more
Invisible CAPTCHA
Prosopo's Invisible CAPTCHA is the invisible-first mode of Procaptcha — real users see nothing, and every block on a suspected bot comes with a reason you can read.
Learn more
Procaptcha: the GDPR-compliant CAPTCHA widget
Procaptcha is Prosopo's CAPTCHA widget — a drop-in reCAPTCHA and hCaptcha replacement, cookieless by default, GDPR-compliant, free for the first 10,000 verifications per month.
Learn more
Spam Filter: Add-on for Procaptcha and Prosopo Protect
Spam Filter is a Procaptcha add-on that blocks fake signups, throwaway emails and abusive-network traffic during each verification — without you writing any extra integration code.
Learn more