Skip to main content

Bot and fraud prevention tools

All plans; some tools need Scale or Max Last reviewed

ShortStack protects your campaigns at four points — when the page loads, when an entry is submitted, when a vote is cast, and after entries arrive in your list. This article lists every anti-fraud tool, what it blocks, where to find it and which plan includes it. No single tool blocks every bad actor, so the strongest setups combine several.

Quick reference

Each tool links to its own article with the setup steps. Compare what's included at every tier on the pricing page.

ToolWhat it blocksWhere to configurePlan
Cloudflare TurnstileBots loading the campaign pageCampaign Settings → SecurityScale
Google reCAPTCHABots submitting entries and votesCampaign Settings → SecurityScale
Rate LimitingHigh-volume submissions from one IPCampaign Settings → SecurityAll plans
Referrer BlacklistTraffic from giveaway/aggregator sitesCampaign Settings → SecurityMax
Embedding WhitelistUnauthorized embedding of your campaignCampaign Settings → SecurityAll plans
Country-Based VisibilityTraffic from outside your target regionsWidget → VisibilityMax
Fraud FilterEntries matching known spam patternsForm Container → Fraud FiltersScale
Entry RestrictionsRepeat entries from the same personForm Container → Entry RestrictionsAll plans
Email Login (entries)Entries without a verified email addressForm Container + Login FieldMax
Vote RestrictionsRepeat votes from the same visitorEntry Display Widget → VotingAll plans
Email Login (voting)Votes without a verified email addressCampaign Settings → Email LoginMax
Disposable Email BlockingThrowaway email addressesAutomatic — no setupAll plans
Manual ApprovalSpam entries reaching a public galleryForm Container → Approvals/AlertsAll plans
Two-Factor AuthenticationUnauthorized access to your accountPreferences → Username & PasswordAll plans

Page-level protection

Screens visitors before they can interact with your campaign.

Cloudflare Turnstile

Available on Scale plan and higher.

A CAPTCHA alternative that verifies visitors are human when the page loads, with no visual puzzle to solve. Three modes: Invisible (default, best for embeds), Visible (may show a checkbox, best for landing pages), and Disable (not recommended).

Active on all landing pages by default and off for embeds — check Enable if my campaign is embedded to turn it on. Verification adds a small delay to page load.

See Cloudflare Turnstile.

Rate limiting

Caps entries accepted from one IP address per minute. Default is 20. Lower it for high-value prizes; raise it if legitimate entrants share an IP, as happens at offices, schools, and events.

See Campaign Settings.

Referrer blacklist

Available on Max plan.

Blocks visitors arriving from domains you specify. Most often used against sweepstakes aggregator sites, which drive high volumes of low-intent entries.

See Campaign Settings.

Embedding whitelist

Restricts which sites can embed your campaign. Enter root domains only, separated by spaces. If an embed stops displaying, check this first.

See Campaign Settings.

Country-based visibility

Available on Max plan.

Shows or hides individual widgets by the visitor's country, based on IP address. Limiting your form to eligible regions reduces spam and improves lead quality.

See Widget Visibility.

Entry-level protection

Screens the submission itself.

Google reCAPTCHA

Available on Scale plan and higher.

Validates the visitor at submission and returns a risk score from 0.0 (likely bot) to 1.0 (likely legitimate). Available on the Form Container Widget and Entry Display Widget. Turnstile screens page loads; reCAPTCHA screens submissions.

  • You supply your own keys. Google provides 10,000 free calls per month, which covers most campaigns. Usage above that is billed by Google directly to you. See How to Create Google reCAPTCHA Keys.
  • Sensitivity Level sets the minimum score required for acceptance. A second slider sets the minimum score for Instant Win eligibility, so you can accept borderline entries as leads without letting them win prizes.

Manage saved keys in the Entry Profiles Manager.

See Restricting Entries Using reCAPTCHA.

Fraud Filter

Available on Scale plan and higher.

Catches entries matching patterns you define — specific email addresses, IP addresses, street addresses — using ? for a single character and * for any number of characters. Searches Address, Email Address, and Phone fields, plus IP address automatically. Custom fields aren't searchable.

Actions available on a match: Reject Entry (discarded silently — the submitter still sees a confirmation), Label Entry, Force Instant Win Loss, and Do Not Auto Approve Entry.

See Prohibit Fraudulent and Spam Entries with Fraud Filter Feature.

Entry restrictions

Limits how often one person can enter, by Email Address or Login, with a custom error message for anyone over the limit. Also caps total entries across every Form Container connected to the same list.

See Entry Restrictions.

Email login for entries

Available on Max plan.

The most secure entry restriction. Entrants confirm a code sent to their email address, so entries require a working inbox and bots can't retrieve the code. Set up using a Login Field in the Field Widget.

See Entry Restrictions.

Disposable email blocking

Throwaway and temporary email domains are blocked automatically. No setting to configure.

Vote-level protection

Configured separately from entry restrictions, in the Entry Display Widget under Voting.

Vote restrictions

Four options: No Restrictions, Anonymous Fingerprint (anonymized browser and IP data, all plans), Anonymous IP (stricter, IP only), and Email Address (Max plan).

See How to Set Up Voting.

Frequency limits

Set how often a visitor can vote, scoped by entry, category, or list, in days, hours, minutes, or seconds.

Email login for voting

Available on Max plan.

The most secure vote restriction. Voters receive a 6-digit code that expires after 15 minutes and can't be reused. Dialog text, error messages, and verification frequency are all customizable.

Email addresses are used only to verify the voter, not for promotional use. To collect voter data for marketing, see How to Collect Voter Data.

See Setting Up Email Login for Voting.

reCAPTCHA on votes

Available on Scale plan and higher.

Uses the same key profile and Sensitivity Level slider as entry reCAPTCHA.

Additional safeguards

Use Start with Vote Button Hidden plus an Action Widget to require a form submission before voting; this sharply reduces fraudulent votes and captures leads. You can also set a wait time before the vote button reappears, and schedule the voting window.

Reviewing entries after submission

Even a well-protected campaign benefits from a review pass before winners are announced.

  • Manual approval — Uncheck Automatically approve entries in the Form Container Widget, and enable Hide Unapproved Entries in the Entry Display Widget to keep unreviewed entries out of a public gallery. Email Alerts can notify you on each submission.
  • Filter by reCAPTCHA score — In the Entries Manager, open the Other filter section and set a score range.
  • Exclude labeled entries — Enter your fraud labels in the Exclude Labels field to hide them from view.
  • Exclude entries when picking winners — Enter fraud labels in the Exclude Entries field to remove them from the drawing pool. See How to Select Winners.

Account and integration security

  • Two-Factor Authentication — Adds a second credential beyond your password, using an authenticator app. See Setting Up Two-Factor Authentication.
  • Webhook security — Add a Secret Key to your webhook integration; ShortStack signs each request in the X-Ss-Signature header for your server to verify. You can also restrict your endpoint to ShortStack's IP address. See Securing Webhook Form Integrations.

Low-value prize — Turnstile on Invisible, entry restriction by email address, Rate Limiting at default.

High-value prize or public voting — Turnstile plus reCAPTCHA, Email Login, Fraud Filter patterns, Country-Based Visibility, Referrer Blacklist, and manual approval with a review pass before picking winners.

Embedded campaign — Check Enable if my campaign is embedded, confirm your root domain is in the Embedding Whitelist, and add your ShortStack publishing domain to your reCAPTCHA key rather than your website's domain.

Before you launch, run through Testing Your Campaign and Campaign Best Practices.

Limitations

No bot prevention method is completely effective. Determined bad actors adapt, and CAPTCHA services are third-party products whose detection logic ShortStack does not control. These tools reduce fraudulent traffic substantially; they do not eliminate it.

Combine several layers, and set contest rules that reserve your right to disqualify entries at your sole discretion. See the Sweepstakes and Contest Rules Guide.

ShortStack engineers continue to develop and improve bot prevention.

How to Select Winners (Help Doc)

Setting up Email Login for Voting (Help Doc)

7 Essential Security Features to Prevent Cheating (Blog)

Rules Generator (Free Tool)

Campaign Checker (Free Tool)

FAQs

Do I need both Cloudflare Turnstile and Google reCAPTCHA?

They cover different moments — Turnstile at page load, reCAPTCHA at submission. For high-value campaigns, use both.

Do I have to supply my own reCAPTCHA keys?

Yes, for new campaigns. Google introduced API fees for reCAPTCHA, and rather than raise plan prices, ShortStack now requires your own keys. Existing published campaigns already using reCAPTCHA continue to work unchanged.

Does any of this cost extra?

Not from ShortStack. Google includes 10,000 free reCAPTCHA calls per month; usage above that is billed by Google directly to you.

What's the single most effective tool?

Email Login (Max plan). A verified email address blocks bots and makes duplicate entries and votes substantially harder.

Why does my campaign load more slowly with Turnstile enabled?

Turnstile verifies each visitor before the campaign renders. If the delay is a problem, change the mode in Campaign Settings → Security.

Was this helpful?