Bot and fraud prevention tools
ShortStack protects your campaigns at four points — when the page loads, when an entry is submitted, when a vote is cast, and after entries arrive in your list. This article lists every anti-fraud tool, what it blocks, where to find it and which plan includes it. No single tool blocks every bad actor, so the strongest setups combine several.
Quick reference
Each tool links to its own article with the setup steps. Compare what's included at every tier on the pricing page.
| Tool | What it blocks | Where to configure | Plan |
|---|---|---|---|
| Cloudflare Turnstile | Bots loading the campaign page | Campaign Settings → Security | Scale |
| Google reCAPTCHA | Bots submitting entries and votes | Campaign Settings → Security | Scale |
| Rate Limiting | High-volume submissions from one IP | Campaign Settings → Security | All plans |
| Referrer Blacklist | Traffic from giveaway/aggregator sites | Campaign Settings → Security | Max |
| Embedding Whitelist | Unauthorized embedding of your campaign | Campaign Settings → Security | All plans |
| Country-Based Visibility | Traffic from outside your target regions | Widget → Visibility | Max |
| Fraud Filter | Entries matching known spam patterns | Form Container → Fraud Filters | Scale |
| Entry Restrictions | Repeat entries from the same person | Form Container → Entry Restrictions | All plans |
| Email Login (entries) | Entries without a verified email address | Form Container + Login Field | Max |
| Vote Restrictions | Repeat votes from the same visitor | Entry Display Widget → Voting | All plans |
| Email Login (voting) | Votes without a verified email address | Campaign Settings → Email Login | Max |
| Disposable Email Blocking | Throwaway email addresses | Automatic — no setup | All plans |
| Manual Approval | Spam entries reaching a public gallery | Form Container → Approvals/Alerts | All plans |
| Two-Factor Authentication | Unauthorized access to your account | Preferences → Username & Password | All plans |
Page-level protection
Screens visitors before they can interact with your campaign.
Cloudflare Turnstile
Available on Scale plan and higher.
A CAPTCHA alternative that verifies visitors are human when the page loads, with no visual puzzle to solve. Three modes: Invisible (default, best for embeds), Visible (may show a checkbox, best for landing pages), and Disable (not recommended).
Active on all landing pages by default and off for embeds — check Enable if my campaign is embedded to turn it on. Verification adds a small delay to page load.
See Cloudflare Turnstile.
Rate limiting
Caps entries accepted from one IP address per minute. Default is 20. Lower it for high-value prizes; raise it if legitimate entrants share an IP, as happens at offices, schools, and events.
See Campaign Settings.
Referrer blacklist
Available on Max plan.
Blocks visitors arriving from domains you specify. Most often used against sweepstakes aggregator sites, which drive high volumes of low-intent entries.
See Campaign Settings.
Embedding whitelist
Restricts which sites can embed your campaign. Enter root domains only, separated by spaces. If an embed stops displaying, check this first.
See Campaign Settings.
Country-based visibility
Available on Max plan.
Shows or hides individual widgets by the visitor's country, based on IP address. Limiting your form to eligible regions reduces spam and improves lead quality.
See Widget Visibility.
Entry-level protection
Screens the submission itself.
Google reCAPTCHA
Available on Scale plan and higher.
Validates the visitor at submission and returns a risk score from 0.0 (likely bot) to 1.0 (likely legitimate). Available on the Form Container Widget and Entry Display Widget. Turnstile screens page loads; reCAPTCHA screens submissions.
- You supply your own keys. Google provides 10,000 free calls per month, which covers most campaigns. Usage above that is billed by Google directly to you. See How to Create Google reCAPTCHA Keys.
- Sensitivity Level sets the minimum score required for acceptance. A second slider sets the minimum score for Instant Win eligibility, so you can accept borderline entries as leads without letting them win prizes.
Manage saved keys in the Entry Profiles Manager.
See Restricting Entries Using reCAPTCHA.
Fraud Filter
Available on Scale plan and higher.
Catches entries matching patterns you define — specific email addresses, IP addresses, street addresses — using ? for a single character and * for any number of characters. Searches Address, Email Address, and Phone fields, plus IP address automatically. Custom fields aren't searchable.
Actions available on a match: Reject Entry (discarded silently — the submitter still sees a confirmation), Label Entry, Force Instant Win Loss, and Do Not Auto Approve Entry.
See Prohibit Fraudulent and Spam Entries with Fraud Filter Feature.
Entry restrictions
Limits how often one person can enter, by Email Address or Login, with a custom error message for anyone over the limit. Also caps total entries across every Form Container connected to the same list.
See Entry Restrictions.
Email login for entries
Available on Max plan.
The most secure entry restriction. Entrants confirm a code sent to their email address, so entries require a working inbox and bots can't retrieve the code. Set up using a Login Field in the Field Widget.
See Entry Restrictions.
Disposable email blocking
Throwaway and temporary email domains are blocked automatically. No setting to configure.
Vote-level protection
Configured separately from entry restrictions, in the Entry Display Widget under Voting.
Vote restrictions
Four options: No Restrictions, Anonymous Fingerprint (anonymized browser and IP data, all plans), Anonymous IP (stricter, IP only), and Email Address (Max plan).
See How to Set Up Voting.
Frequency limits
Set how often a visitor can vote, scoped by entry, category, or list, in days, hours, minutes, or seconds.
Email login for voting
Available on Max plan.
The most secure vote restriction. Voters receive a 6-digit code that expires after 15 minutes and can't be reused. Dialog text, error messages, and verification frequency are all customizable.
Email addresses are used only to verify the voter, not for promotional use. To collect voter data for marketing, see How to Collect Voter Data.
See Setting Up Email Login for Voting.
reCAPTCHA on votes
Available on Scale plan and higher.
Uses the same key profile and Sensitivity Level slider as entry reCAPTCHA.
Additional safeguards
Use Start with Vote Button Hidden plus an Action Widget to require a form submission before voting; this sharply reduces fraudulent votes and captures leads. You can also set a wait time before the vote button reappears, and schedule the voting window.
Reviewing entries after submission
Even a well-protected campaign benefits from a review pass before winners are announced.
- Manual approval — Uncheck Automatically approve entries in the Form Container Widget, and enable Hide Unapproved Entries in the Entry Display Widget to keep unreviewed entries out of a public gallery. Email Alerts can notify you on each submission.
- Filter by reCAPTCHA score — In the Entries Manager, open the Other filter section and set a score range.
- Exclude labeled entries — Enter your fraud labels in the Exclude Labels field to hide them from view.
- Exclude entries when picking winners — Enter fraud labels in the Exclude Entries field to remove them from the drawing pool. See How to Select Winners.
Account and integration security
- Two-Factor Authentication — Adds a second credential beyond your password, using an authenticator app. See Setting Up Two-Factor Authentication.
- Webhook security — Add a Secret Key to your webhook integration; ShortStack signs each request in the
X-Ss-Signatureheader for your server to verify. You can also restrict your endpoint to ShortStack's IP address. See Securing Webhook Form Integrations.
Recommended combinations
Low-value prize — Turnstile on Invisible, entry restriction by email address, Rate Limiting at default.
High-value prize or public voting — Turnstile plus reCAPTCHA, Email Login, Fraud Filter patterns, Country-Based Visibility, Referrer Blacklist, and manual approval with a review pass before picking winners.
Embedded campaign — Check Enable if my campaign is embedded, confirm your root domain is in the Embedding Whitelist, and add your ShortStack publishing domain to your reCAPTCHA key rather than your website's domain.
Before you launch, run through Testing Your Campaign and Campaign Best Practices.
Limitations
No bot prevention method is completely effective. Determined bad actors adapt, and CAPTCHA services are third-party products whose detection logic ShortStack does not control. These tools reduce fraudulent traffic substantially; they do not eliminate it.
Combine several layers, and set contest rules that reserve your right to disqualify entries at your sole discretion. See the Sweepstakes and Contest Rules Guide.
ShortStack engineers continue to develop and improve bot prevention.
Related resources
How to Select Winners (Help Doc)
Setting up Email Login for Voting (Help Doc)
FAQs
Do I need both Cloudflare Turnstile and Google reCAPTCHA?
They cover different moments — Turnstile at page load, reCAPTCHA at submission. For high-value campaigns, use both.
Do I have to supply my own reCAPTCHA keys?
Yes, for new campaigns. Google introduced API fees for reCAPTCHA, and rather than raise plan prices, ShortStack now requires your own keys. Existing published campaigns already using reCAPTCHA continue to work unchanged.
Does any of this cost extra?
Not from ShortStack. Google includes 10,000 free reCAPTCHA calls per month; usage above that is billed by Google directly to you.
What's the single most effective tool?
Email Login (Max plan). A verified email address blocks bots and makes duplicate entries and votes substantially harder.
Why does my campaign load more slowly with Turnstile enabled?
Turnstile verifies each visitor before the campaign renders. If the delay is a problem, change the mode in Campaign Settings → Security.
Was this helpful?
Thanks — that helps us decide what to fix next.
Sorry this missed. Tell us what you needed and we'll get you an answer — and fix the page.