# Add Captcha to Subscriber Form

**URL:** <https://forum.ghost.org/t/add-captcha-to-subscriber-form/27>\
**Category:** Ideas\
**Tags:** 🚢-shipped\
**Created:** [March 29, 2018, 7:42pm UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27 "2018-03-29T19:42:46Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sarah](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/sarah/32/21755_2.png) [@Sarah](https://forum.ghost.org/u/Sarah)\
**Post date:** [March 29, 2018, 7:42pm UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27/1 "2018-03-29T19:42:46Z")

</div>

Enable option to include captcha to prevent spammy emails from being added to a subscriber list.

---

<div class="post-metadata">

**Author:** ![HauntedThemes](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/hauntedthemes/32/15301_2.png) [@HauntedThemes](https://forum.ghost.org/u/HauntedThemes)\
**Post date:** [April 1, 2018, 8:22pm UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27/2 "2018-04-01T20:22:12Z")

</div>

This is indeed a problem with the current subscription form. I get like 10 spam subscriptions every day on each blog.

The subscription is still in beta so it will be improved in the future. Until then check these simple solutions:

An option for those who get spams is to enable Zapier integration and send subscribers to MailChimp with double op-in enabled.  
Another option is for those who are self-hosted.

Connect to your database.  
Do a backup for your subscribers table in case of something goes wrong.  
Do a select: SELECT \* FROM subscribers WHERE subscribed\_url != ‘’;

This should select all those who are not spams.  
subscribed\_referrer might be empty sometimes but subscribed\_url seems to always be filled.

So you could simply delete all those that have subscribed\_url empty. Do a backup first just to be sure.  
DELETE \* FROM subscribers WHERE subscribed\_url = ‘’;

---

<div class="post-metadata">

**Author:** ![John](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/john/32/29288_2.png) [@John](https://forum.ghost.org/u/John)\
**Post date:** [April 2, 2018, 9:32am UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27/3 "2018-04-02T09:32:01Z")

</div>

I feel like step one here should be to just make the signup form smarter. If `subscribed_url` is always empty for spammers, then maybe we should not write to the database at all when that’s detected.

---

<div class="post-metadata">

**Author:** ![HauntedThemes](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/hauntedthemes/32/15301_2.png) [@HauntedThemes](https://forum.ghost.org/u/HauntedThemes)\
**Post date:** [April 2, 2018, 10:24am UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27/4 "2018-04-02T10:24:58Z")

</div>

I need to test another option here. If it is manually completed by the user, `subscribed_url` is never empty. But I’m not sure what happens if a Zap is created and a New Mailchimp Subscriber is set to Create a Subscriber in Ghost. I will test and come back with an answer.

EDIT: It is empty.

---

<div class="post-metadata">

**Author:** ![Kevin](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/kevin/32/32_2.png) [@Kevin](https://forum.ghost.org/u/Kevin)\
**Post date:** [April 2, 2018, 10:31am UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27/5 "2018-04-02T10:31:29Z")

</div>

> But I’m not sure what happens if a Zap is created and a New Mailchimp Subscriber is set to Create a Subscriber in Ghost

In that case the `subscribed_url` will not be set. However Zapier integrations use the private API whereas signup’s from the blog itself go via a public subscribe endpoint so there can be different levels of protection for each.

---

<div class="post-metadata">

**Author:** ![Trey](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/trey/32/123_2.png) [@Trey](https://forum.ghost.org/u/Trey)\
**Post date:** [April 5, 2018, 7:05am UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27/6 "2018-04-05T07:05:43Z")

</div>

Just a humble suggestion to add to this. Is it possible or wise to add captcha at the ghost sign ins to prevent running bruteforce tools or scripts on it?

---

<div class="post-metadata">

**Author:** ![amaitu](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/amaitu/32/7865_2.png) [@amaitu](https://forum.ghost.org/u/amaitu)\
**Post date:** [April 5, 2018, 10:32am UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27/7 "2018-04-05T10:32:37Z")

</div>

Another workaround if you’re self hosted is to implement a wider spam detection system at the DNS level - you can use the Cloudflare free plan to automatically show captchas to users that appear automated. You can also set custom rules for particular endpoints.

---

<div class="post-metadata">

**Author:** ![Kevin](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/kevin/32/32_2.png) [@Kevin](https://forum.ghost.org/u/Kevin)\
**Post date:** [April 5, 2018, 11:15am UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27/8 "2018-04-05T11:15:24Z")

</div>

> [@Trey](#):
>
> at the ghost sign ins to prevent running bruteforce tools or scripts on it

Ghost already has built-in brute force protection for signin and password reset

---

<div class="post-metadata">

**Author:** ![Trey](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/trey/32/123_2.png) [@Trey](https://forum.ghost.org/u/Trey)\
**Post date:** [April 5, 2018, 1:01pm UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27/9 "2018-04-05T13:01:35Z")

</div>

Oh my bad. Wasn’t aware that bruteforce protection is already there. I don’t use cloudflare because of the known complications which occurs when setup by a newbie 😂 i don’t want to get locked out of my own home(page).

---

<div class="post-metadata">

**Author:** ![svikashk](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/svikashk/32/580_2.png) [@svikashk](https://forum.ghost.org/u/svikashk)\
**Post date:** [May 11, 2018, 11:12am UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27/10 "2018-05-11T11:12:43Z")

</div>

I was wondering what’s a good way for a newbie like me to block these spams? I’m self-hosted and I get about 20 subscriber error mails from Zapier.

---

<div class="post-metadata">

**Author:** ![HauntedThemes](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/hauntedthemes/32/15301_2.png) [@HauntedThemes](https://forum.ghost.org/u/HauntedThemes)\
**Post date:** [May 11, 2018, 12:48pm UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27/11 "2018-05-11T12:48:22Z")

</div>

The easiest way would be to replace the subscription form with a Mailchimp form. Until Ghost’s Subscription gets out of beta I recommend this option. This way you will also be GDPR compliant, if you want. Mailchimp has the option to do this.

---

<div class="post-metadata">

**Author:** ![ernie](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/ernie/32/674_2.png) [@ernie](https://forum.ghost.org/u/ernie)\
**Post date:** [May 27, 2018, 7:01pm UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27/12 "2018-05-27T19:01:11Z")

</div>

I think this discussion could benefit from the suggestion of making a third-party service like Akismet available. I get probably 50-100 spam signups a week because I have a list around 10k, and while a Captcha is one solution, something like Akismet or [Cleantalk](https://cleantalk.org/) also brings knowledge of low-rep senders in general, which could do a lot to nip the problem in the bud.

---

<div class="post-metadata">

**Author:** ![HauntedThemes](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/hauntedthemes/32/15301_2.png) [@HauntedThemes](https://forum.ghost.org/u/HauntedThemes)\
**Post date:** [May 28, 2018, 10:29pm UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27/13 "2018-05-28T22:29:15Z")

</div>

I’ve released a small tutorial on **[How to Stop Spam Emails in Ghost using Zapier and MailChimp](https://www.hauntedthemes.com/how-to-stop-spam-emails-in-ghost-using-zapier-and-mailchimp/)**. If you are interested you can give it a shot. It is more like a filter to find what emails are spam. Long story short, I’m creating a MailChimp list with a Subscribed Url field, mandatory. Then I create a Zap that says “When a New Ghost Subscribed is inserted, add it to MailChimp list, only if the Subscribed Url field in not empty”.

---

<div class="post-metadata">

**Author:** ![John](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/john/32/29288_2.png) [@John](https://forum.ghost.org/u/John)\
**Post date:** [June 10, 2020, 3:52pm UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27/15 "2020-06-10T15:52:04Z")

</div>



---

<div class="post-metadata">

**Author:** ![John](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/john/32/29288_2.png) [@John](https://forum.ghost.org/u/John)\
**Post date:** [June 10, 2020, 3:52pm UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27/16 "2020-06-10T15:52:08Z")

</div>



---

<div class="post-metadata">

**Author:** ![John](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/john/32/29288_2.png) [@John](https://forum.ghost.org/u/John)\
**Post date:** [August 1, 2025, 1:01am UTC](https://forum.ghost.org/t/add-captcha-to-subscriber-form/27/17 "2025-08-01T01:01:22Z")

</div>


