RevOps/No. 30/6 min read
Bots are half your web traffic. Your CRM still treats a form fill as a person.
Form spam isn’t a deliverability annoyance. It’s unvalidated data walking straight into your lifecycle stages, your scoring model, and the conversion feed you send back to the ad platforms.
There is a gap between “form submitted” and “contact exists” where validation is supposed to happen. In most portals we open, nothing lives there. The submission fires, the contact gets created, the lifecycle stage moves, the score calculates, and the conversion pixel reports back to Google. All of it in about two seconds, on data nobody checked.
That was survivable when bots filled forms with asdfasdf. It isn’t now. Thales and Imperva’s 2026 Bad Bot Report found that bots made up more than 53% of all web traffic in 2025, with 40% of that traffic classified as malicious, and AI-driven bot attacks up 12.5x year over year. The generative-AI era didn’t just make bots more numerous. It made them write like people. A submission with a plausible first name, a real-looking title, and a corporate-sounding domain no longer proves a human was there.
Your CRM doesn’t know that. It was never asked to.
The problem isn’t spam in your inbox. It’s spam in your model.
Teams treat form spam as a nuisance: delete the junk contacts, move on. That framing is why it never gets fixed properly. Bad submissions aren’t sitting inert in a list. They’re actively training four systems at once.
Your scoring model. Behavioral scoring rewards form fills. A bot that submits three gated assets in an hour looks like your most engaged contact of the week. If your score already blends fit and engagement into one number, that bot outranks a real VP who read two pages and left. Reps then learn to ignore the score, which is the actual damage. A scoring model nobody trusts is worse than no scoring model, because you paid for it and built routing on top of it.
Your ad platforms. Smart bidding learns from the conversions you report. If you’re sending form fills back as the conversion event, you are paying an algorithm to find more of whatever filled out that form. When a share of those are bots, you’re not just wasting spend. You’re teaching the platform to buy the traffic that produced them.
Your funnel math. MQL counts inflate. Lead-to-opportunity conversion rate drops, because the denominator grew with records that were never going to convert. The board sees a conversion-rate problem and asks sales why they aren’t working the leads.
Your sending reputation. Every unvalidated address that enters a nurture is a bounce or a spam trap waiting to fire, and the worst sender in your stack sets the ceiling for everyone else on the domain.
Validate before you create, not after
The fix is structural, and it’s smaller than it sounds. You need a gate between submission and record creation, and the gate needs to write its reasoning to properties you can report on.
1. Make validation a property, not a delete
Start with two custom properties on the contact: lead_validation_status (picklist: passed, suspect, failed, unchecked) and lead_validation_reason (picklist, not free text: disposable_domain, mx_unreachable, role_address, honeypot_tripped, submit_velocity, geo_mismatch, gibberish).
Governed picklists matter here for the same reason they matter in self-reported attribution. A free-text reason field gives you a column nobody can group by. A closed set of seven values gives you a report that tells you which vector is actually hitting you, which is the only way to know what to tighten next month.
2. Run three passes, in cost order
Syntax first, because it’s free. Deliverability second: check the MX record and reject disposable domains. Identity third, and only for submissions that passed the first two, because enrichment lookups cost money and you shouldn’t spend it on qwerty@mailinator.com.
Platform-native controls handle a real share of this before you build anything. HubSpot’s form spam documentation covers invisible reCAPTCHA v2, AI gibberish detection on text fields, blocking free and disposable email providers, and marking submissions from excluded IPs and referrers as spam. Turn those on first. They route spam to a separate submissions index instead of creating contacts, which is exactly the behavior you want. Then build your own layer for what they can’t see: submit velocity from one IP, a honeypot field, a time-on-form threshold, geography that contradicts the stated company.
3. Quarantine, don’t delete
Deleting is tempting and it destroys your evidence. A failed submission should still land somewhere you can query, because the pattern in your rejects is a report: which form, which campaign, which source, which hour. We have seen a single paid campaign account for most of a quarter’s junk, which is a media-buying decision, not a forms problem. You cannot make that call from an empty trash can.
Set lead_validation_status to failed and hold the record out of lifecycle, nurture, and routing. Keep it visible to reporting.
4. Gate lifecycle and the conversion feed on the same flag
This is the step that makes the rest matter. Lifecycle stage should not advance past subscriber until lead_validation_status equals passed. Scoring workflows should be enrolled on the same condition. Offline conversion uploads should filter on it too, so the ad platform only ever learns from records a human plausibly created.
One flag, four consumers. That’s the whole build.
What it costs to leave the gate open
Nothing visibly breaks, which is why this sits unfixed. The numbers just drift. Your MQL volume looks fine and your conversion rate quietly erodes. Your paid campaigns optimize toward cheaper, worse traffic. Your reps stop opening marketing-sourced records. Six months later someone proposes buying a new scoring tool, which will read the same unvalidated data and produce the same result.
It’s the same pattern as every other reporting problem that’s actually a data problem. The report isn’t wrong. The records underneath it are.
Fixed, the interesting number changes. Instead of counting leads, you can count validated leads, and you can see the delta. That delta is the size of the problem you’ve been reporting to your board.
Where to start
Run one query this week: contacts created in the last 90 days, grouped by original source, where the email domain is free, disposable, or role-based (info@, sales@, admin@). Then pull form submission counts by hour and look for the spikes that don’t match human working patterns.
You’ll get a percentage. If it’s under 2%, turn on the native controls and move on. If it’s in double digits, you don’t have a lead quality problem. You have an ungated data entry point, and every system reading from it is compromised until you close it.
This is object-model and workflow work, which is where every Marketing Operations & CRM engagement we run starts. Validation is not a plugin. It’s a property, a gate, and four systems agreeing to respect it.
Not sure how much of your inbound is real? That’s one of the things we map in the free 30-minute audit. We look at where submissions enter, what validates them before they become contacts, and what your scoring and conversion feeds are reading. Then we hand you the prioritized list. Whether we work together or not.