If your WordPress website is being bombarded by spam comments or form submissions, we understand how frustrating and overwhelming that can be. Fortunately, there are several steps you can take to reduce or eliminate spam effectively, helping you regain control over your site and keep your focus on what matters most. Follow these tips to get started.
1. Disable Comments Entirely (Recommended if You Don’t Need Them)
If your site doesn’t need a comment section — such as for a brochure site, landing page, or online store — disable comments completely:
- Go to Settings → Discussion
- Uncheck “Allow people to post comments on new articles”
- Use the Disable Comments plugin to remove comment functionality site-wide
To disable comments on existing content:
- Use Quick Edit to turn off comments for individual posts
- Use the Bulk Actions menu from Posts → All Posts to apply this across multiple entries
This is the simplest and most effective way to shut down spam entirely.
2. Activate a Spam Filter Plugin
If you need comments, install a trusted anti-spam plugin:
- Antispam Bee – Free and GDPR-compliant
- Akismet – Free for personal use, paid for business sites
- Zero Spam for WordPress by Highfivery – Blocks bots without using CAPTCHAs
These tools catch spam automatically before it reaches your moderation queue.
3. Harden Your Comment Settings
Go to:
WordPress Dashboard → Settings → Discussion
Recommended settings:
- Enable “Comment author must have a previously approved comment”
- Disable “Anyone can post a comment”
- Enable “Comment must be manually approved”
- Enable “Users must be registered and logged in to comment” (optional but highly effective)
- Use the Disallowed Comment Keys field to block common spam keywords like
casino,viagra, or shortened URLs likeis.gd
To populate this list with known spam terms:
- Use the WordPress Comment Blacklist by splorp
- Extend and manage blocklists easily with:
- Block List Updater by Pluginkollektiv
- Comment Blacklist Manager by Andrew Norcross
- Comment Blacklist Updater by Apasionados
4. Automatically Close Comments on Older Posts
Still in Settings → Discussion:
- Enable “Automatically close comments on articles older than”
- Set to 14 days or another suitable duration
This reduces comment spam on outdated or archived content.
5. Require CAPTCHA for Comment Submission
CAPTCHA helps block automated spam:
You can also consider all-in-one plugins that add comment protection:
- Shield Security by Shield Security
- WP Toolbelt by Ben Gillbanks
6. Remove Existing Spam Comments
To clean up spam already in your database:
- Go to Comments → Spam and click “Empty Spam”
- Go to Comments → Pending and click “Trash All”
- For large volumes or automation, use WP Bulk Delete
7. Filter Spam Emails with Ecenica Mail
If you’re receiving spam through comment notifications or contact forms, Ecenica‘s built-in mail filtering tools can help block them before they reach your inbox.
a) Enable Spam Filters in cPanel
- Log in to Ecenica Dashboard.
- Navigate to your plan and click Login to cPanel.
- Go to Email → Spam Filters.
- Enable SpamAssassin (on by default).
- Set a spam threshold score — the default of 5 is recommended for balance, but you can lower it to 4 for stricter filtering.
- Enable Auto-Delete Spam or move spam to the Junk folder to keep your inbox clean.
b) Create Email Filters
- In cPanel, go to Email → Email Filters.
- Create custom rules to filter incoming mail based on:
- Subject line keywords (e.g., “casino”, “loan”, “viagra”)
- From address patterns (e.g., unknown domains or fake addresses)
- Body content (e.g., common spam phrases)
This is especially helpful for filtering spam from WordPress contact forms or comments that generate email notifications.
Note: If you’re not hosting your email with Ecenica, reach out to your email provider for guidance on configuring their spam filters. Most providers offer tools or rules to block unwanted messages, especially those generated by WordPress comment notifications or form submissions.