Automated messages, promotional content and abusive submissions can quickly make an Elementor contact form difficult to manage. Adding a protection method is not only a matter of switching on a setting: the keys must belong to the correct domain, the relevant field must be added to the Form widget, and any Akismet mapping must use real field shortcodes.
Elementor documents two relevant integrations for its Form widget: Google reCAPTCHA v2 and v3, plus Akismet where the required Elementor Pro plan supports form integrations. This guide presents the setup as a layered, testable process. It explains how the two reCAPTCHA versions differ, how to connect Akismet, which fields can be scanned, and how to verify that legitimate visitors can still submit the form. Neither integration should be treated as a complete guarantee that every unwanted submission will be blocked.
Before You Configure Elementor Form Spam Protection
Start by confirming that you can edit the relevant page with Elementor and access the Elementor settings. You should also identify whether the site is production, staging or development. This matters because keys registered for another environment or domain may not work as expected. Google states that reCAPTCHA registrations apply to the domains entered and their subdomains, while domain changes may take up to 30 minutes to take effect.
Prepare the required accounts and credentials before editing the form. Keep secret credentials private throughout the process. They should not appear in screenshots, public documentation or client-facing code repositories.
Keys, domains and plan availability
- reCAPTCHA: register the intended site with Google and obtain a Site Key and Secret Key.
- Akismet: install the Akismet plugin, create or access an Akismet account and obtain an API key.
- Domain: register the correct production, staging or development domain and review it before troubleshooting.
- Plan: Elementor documents Akismet integration for Elementor Pro plans that support form integrations, identified in its documentation as the Advanced Pro Advanced plan and above.
- Credentials: provide secret keys only to trusted parties and use separate development and production keys where practical.
These preparations reduce avoidable errors, but they do not replace testing. reCAPTCHA and Akismet are screening or abuse-reduction mechanisms, not complete security controls.
How to Add reCAPTCHA to an Elementor Form
Elementor’s reCAPTCHA setup has two parts: a global integration in WordPress and a matching field inside the specific Form widget. First register the relevant site and reCAPTCHA version with Google. After registration, copy the Site Key and Secret Key. Do not publish the Secret Key in a screenshot or repository.
In WordPress, open Elementor > Settings > Integrations. Enter the Site Key and Secret Key in the appropriate reCAPTCHA settings, then save the configuration. For v3, Elementor also provides an optional score-threshold setting. This threshold should be treated as a site-specific tuning control rather than a universal value.
Configure the integration and form field
- Edit the page containing the form with Elementor.
- Select the Form widget or add one to the page.
- Add a form item and choose reCAPTCHA3 for reCAPTCHA v3 or reCAPTCHA for v2.
- For v2, configure the available presentation, such as the “I’m not a robot” checkbox or the invisible reCAPTCHA badge, together with the relevant badge position where available.
- Save or publish the page and test the form with a legitimate submission.
Entering keys in Elementor’s Integrations screen is not enough by itself. The corresponding reCAPTCHA field must also be present in the Form widget. Check that the field uses the intended version and that the form loads with the expected presentation or background behavior.
When a domain has recently been added or changed, allow for Google’s documented propagation period before treating the delay as an Elementor configuration failure. If the integration still does not work, compare the registered domain, environment and keys with the site on which the form is running.
reCAPTCHA v2 vs v3: Choosing the Form Experience
Elementor supports both reCAPTCHA v2 and v3, but they create different experiences. In Elementor’s Integrations screen, v2 is identified as “reCAPTCHA”, while v3 is separately identified. This distinction is useful when choosing keys and adding the field to the form.
reCAPTCHA v3 evaluates interactions in the background and produces a score. It does not require direct user input in the form, so it can provide a less intrusive experience. Elementor exposes an optional score threshold for v3. Changing that threshold can affect which submissions are treated as suspicious, so monitor legitimate form completion and possible false positives after an adjustment.
Match the version to the user experience
- Choose v3 when a background-based, low-friction interaction is preferred and the site owner is prepared to monitor the score-threshold behavior.
- Choose v2 when a visible “I’m not a robot” checkbox or an explicit challenge is preferred.
- Remember the v2 options: Elementor describes both a checkbox and an invisible badge configuration.
- Do not rank them universally: the choice depends on the form experience and the site’s testing results, not on an unsupported performance guarantee.
Elementor’s documented integration does not support Google’s Enterprise reCAPTCHA API. Confirm this limitation before creating or reusing credentials. Also review the site’s privacy notice, cookie configuration and consent-management approach because reCAPTCHA involves external requests and Google documents a necessary cookie for risk analysis. The legal and operational implications depend on the site’s configuration and jurisdiction.
How to Connect Akismet to an Elementor Form
Akismet requires more than installing a plugin. Install and activate the Akismet plugin, then create or access an Akismet account and obtain its API key. In WordPress, open Settings > Akismet Anti-spam and connect the key manually.
After connecting Akismet, edit the Elementor Form widget. Locate the Akismet Spam Protection section. Elementor warns that the prefilled dummy text in this section does not activate protection. The form needs the actual shortcodes of the fields that should be filtered.
Activate protection with real field shortcodes
- Open the form in Elementor and identify the fields whose content should be scanned.
- Open the Advanced tab of a selected field and copy that field’s shortcode.
- Paste the shortcode into the corresponding setting in the Akismet Spam Protection section.
- Repeat the process for each selected field, checking that every shortcode belongs to the intended field.
- Save or publish the page, then perform controlled and legitimate tests.
The presence of the Akismet section does not prove that the form is protected. Without replacing the dummy values with real shortcodes, the documented form-specific protection does not become effective. If the section is missing, first check whether the site uses an Elementor Pro plan that supports form integrations. Do not infer current prices, licensing terms or other plan conditions from this integration description.
Which Elementor Form Fields Should Akismet Scan?
There is no universal mandatory field list established by Elementor’s documentation. Elementor gives email and message fields as examples of fields that can be filtered, but the site owner chooses which fields are scanned. That means the correct configuration depends on what the form collects and what kind of abuse it receives.
Use Elementor’s examples as a starting point
For a typical contact form, begin by considering the email and message fields documented by Elementor. These examples can be a practical starting point because they contain contact information and user-provided content. They are not the only possible choices, and they are not a rule that every Elementor form must follow.
- Copy the shortcode from the Advanced tab of the email field if email content should be filtered.
- Copy the shortcode from the Advanced tab of the message field if message content should be filtered.
- Add other fields when their collected content is relevant to the abuse being screened.
- Verify each shortcode against the intended field before saving the form.
Do not assume that every available field must be mapped, or that a field is scanned simply because it appears in the form. Akismet protection depends on entering the selected field shortcodes in the form’s Akismet Spam Protection settings.
Test and Troubleshoot the Protection Setup
Testing should confirm two things at once: the protection is active, and legitimate visitors can still use the form. Start with a normal submission after enabling reCAPTCHA or completing the Akismet mapping. Check that the form loads with the intended reCAPTCHA presentation or behavior and that a valid entry succeeds.
For Akismet, use the controlled test material and process documented by Elementor when validating spam handling. Review the visible error behavior and the form submissions area after the test. A successful test demonstrates that the configuration responds in that scenario; it does not establish a guaranteed blocking rate.
A minimal post-configuration checklist
- Confirm that the reCAPTCHA field is present in the correct Form widget.
- Check that the Site Key and Secret Key belong to the intended domain and environment.
- Confirm that a legitimate submission succeeds.
- For Akismet, verify that real field shortcodes replaced the dummy values.
- Confirm that the selected shortcodes correspond to the intended email, message or other fields.
- Review false positives and form completion after changing a v3 score threshold.
If protection fails, review the key and domain match, the selected field shortcodes, the relevant Elementor plan and whether the integration was saved. Caching, optimization, consent-management and security-plugin interactions should be investigated as site-specific possibilities rather than assumed incompatibilities. Re-test after relevant environment or configuration changes.
Privacy, Security and Ongoing Maintenance
Credential handling remains important after the initial setup. Keep the reCAPTCHA Secret Key and Akismet API key private, and do not place them in public repositories, screenshots or general client documentation. Google recommends giving secret or API keys only to trusted third parties. Separate development and production keys are also recommended where practical, especially when agencies or freelancers test changes.
Review the site’s privacy notice, cookie configuration and consent-management approach when reCAPTCHA is enabled. Google documents that reCAPTCHA sets a necessary cookie for risk analysis. This article does not establish a universal legal conclusion; the appropriate review depends on the site’s jurisdiction and configuration.
Use layered protection without overpromising
reCAPTCHA and Akismet should be presented as complementary screening and abuse-reduction mechanisms. They can make automated or abusive submissions harder to process, but the research does not establish that either method blocks every unwanted message. Keep normal WordPress, Elementor, plugin and theme update practices in place, and retain monitoring, backups and an abuse-response process.
After changing a key, domain, form field, Akismet mapping or v3 threshold, run both legitimate and controlled tests. Watch for false positives and confirm that valid submissions remain usable. This measured approach is more reliable than enabling a protection method once and assuming the configuration will remain correct across every environment.
A dependable Elementor form spam protection workflow is straightforward when each dependency is checked: register reCAPTCHA for the correct domain, store the keys safely, connect them under Elementor settings, and add the matching field to the Form widget. If the plan supports Akismet, connect its API key and map real field shortcodes, starting with the documented email and message examples when appropriate. Finally, test normal and controlled submissions, review false positives, and repeat the checks after configuration changes. Explore our WordPress plugins, WooCommerce extensions, themes and membership plans to find the right tools for your website.