There are now four concerts on Garth Brooks’ 2026 tour itinerary. The singer and songwriter just announced two additional Blame It All On My Roots Tour dates.
Garth Brooks announced his 2026 Blame It All On My Roots Tour on July 7.
It begins in Indianapolis, Ind., wi
…
Read More
Hank Williams Jr. has been forced to postpone two concerts originally scheduled for this weekend due to poor air quality conditions across Michigan.
The Great Lakes State has experienced some of the worst air quality in the United States this week as smoke from wildfires burning in Minnesota and parts of Canada has moved into the region, creating hazardous conditions for residents and visitors.
According to The Detroit News, the conditions across the state could be “very unhealthy and hazardous.”
Hank Williams Jr.; Photo by Alysse Gafkjen
Hank Jr.’s team announced the schedule changes on social media early Friday morning, revealing that both of his Michigan shows have been rescheduled for next month.
Hank Jr. Reschedules Michigan Shows to Next Month
“Out of an abundance of caution regarding air quality, this weekend’s Hank Williams Jr. shows in Michigan have been postponed and rescheduled to August 13 at Pine Knob Music Theatre and August 14 at Acrisure Amphitheater,” the statement read.
The team also assured ticket holders that their tickets will remain valid for the new dates.
Country Thunder Wisconsin, which kicked off Thursday and runs through Sunday, has been keeping attendees updated as officials continue to monitor air quality conditions caused by the wildfire smoke. The festival shared that it is working closely with local officials to ensure the safety of everyone on-site.
“Your health and safety is our top priority, and we will be providing masks for attendees at all entrance points if required,” the festival shared in its latest statement.
Organizers also reminded fans that “onsite medical staff is available 24/7 to assist with anyone experiencing health concerns.”
Meanwhile, Country Jam USA in Eau Claire, Wisconsin, is also moving forward as planned while keeping a close eye on conditions. Festival organizers said they are working with emergency coordination teams to monitor smoke alerts and the heat index throughout the event.
Fans attending the festival are encouraged to stay hydrated, take breaks in shaded areas, and wear masks if the smoke begins to impact them.
CBJ-The American Red Cross will host a free workshop and resource fair on Sunday, July 19 at the Mendenhall Valley Library. The event is designed to help older adults, individuals with access or functional needs, and medically fragile persons prepare for emergencies.
The event begins at 12 p.m. with a presentation, available both in-person and online, followed by a planning workshop and resource fair from 1 to 3 p.m.
Attendees will have the opportunity to build an individualized disaster plan, complete an emergency contact card, learn how and where to safely store important documents and more.
Registration is free and available online at bit.ly/4vZJlPL. Information for virtual attendance will be provided upon registration
The Northwest ICE Processing Center in Tacoma, which is one of the largest immigrant detention facilities in the western U.S. (Grace Deng/Washington State Standard)
U.S. Immigration and Customs Enforcement arrested an Alaska state attorney in Anchorage and is holding him in an ICE detention facility in Washington state, according to an agency spokesperson.
Shucheng Yang, a 32-year-old Chinese national, was arrested in Anchorage on July 10.
“Yang violated the terms of his admission and is a deportable alien,” said Jason Chudy, an ICE Public Affairs officer, by email on Thursday. He said Yang is currently detained in the Northwest ICE Processing Center in Tacoma, Washington, pending immigration proceedings.
Yang is an attorney with the Alaska Department of Law’s labor, business and corporations section, according to the state employee database. Yang was admitted to the Alaska Bar Association and licensed to practice law in the state in June 2025. A spokesperson for the department declined to respond to questions about his immigration status, employment status or work authorization when hired, saying the department does not comment on personnel matters.
Chudy declined to say how Yang violated the terms of admission into the country. “To be clear, work authorization does NOT confer legal status in the United States,” he said in the email.
He referred further questions about Yang’s work authorization to the U.S. Citizenship and Immigration Services. A spokesperson for USCIS referred the question back to ICE, and said the agency does not comment on individual immigration cases.
The state requires applicants to self-disclose their employment eligibility and work authorization through the I-9 verification process during hiring, according to the Alaska Department of Administration, as reported by Alaska News Source.
There are no state criminal charges against Yang, according to court records. Yang pleaded no contest on June 26 for a speeding citation.
A spokesperson for the Municipality of Anchorage confirmed the Anchorage Police Department issued the traffic ticket on April 25. “They have had no other interaction with Mr. Yang since April,” said Nora Morse, communications director for the municipality, by email on Thursday.
“The Anchorage Police Department does not ask for someone’s immigration status as part of a routine traffic stop,” Morse said.
A spokesperson for the ACLU of Alaska said they were trying to get in touch with Yang’s attorney, and had no other information on his case.
The Alaska Department of Corrections contracts with ICE to hold detainees in Alaska under an agreement with the U.S. Marshals. A spokesperson confirmed that Yang was detained in Alaska for two days after his arrest until he was transferred on July 12.
DOC has held 17 people arrested by ICE since June 1, and 73 people since the beginning of the calendar year, according to spokesperson Betsy Holley on Thursday.
The Alaska House of Representatives on Thursday voted down a multibillion-dollar tax break for the proposed trans-Alaska natural gas pipeline project. Glenfarne LLC, the project’s lead developer, has said the tax break is necessary for it to obtain financing from banks and equity investors.
The Alaska Senate voted 11-8 to approve a compromise version of House Bill 381, which contains the tax break. But after that vote and as the House gaveled in, Dunleavy announced he would veto the bill if it were to pass.
In a statement on social media, the governor said a provision that applies a corporate income tax to certain kinds of privately owned oil and gas companies “raises serious concerns.”
Legislators are meeting in a second 30-day special session devoted to HB 381, and Dunleavy said he will call the Legislature into a third session starting July 27.
After the governor’s message was read on the House floor, only 19 members of the House voted in favor of the bill. Twenty-one votes were needed to approve it.
Many of those who voted against the bill spoke against the provision identified by the governor, with Rep. Dan Saddler, R-Eagle River, calling it a “parasite” within a bill intended to benefit the gas pipeline.
The provision came at the insistence of state senators who said it was necessary for the bill to earn their votes.
“If you want a gas line, everybody’s got to compromise, and I think that’s ultimately what you saw today,” said Sen. Bill Wielechowski, D-Anchorage and one of the most vocal advocates of the provision questioned by the governor.
After the governor’s announcement, Senate President Gary Stevens, R-Kodiak, said he was unsure how the Senate would proceed in the next special session.
The bill could be referred back to the Senate Resources Committee, chaired by Sen. Cathy Giessel, R-Anchorage and a leading project critic. The Senate Finance Committee could consider the issue further.
Senators could simply take no action and wait for the current Legislature to end and Dunleavy to leave office in December.
“I sort of feel you need to go to the next Legislature,” Stevens said.
First gas expected before 2030, developer says
As currently planned, the Alaska LNG project would include three separate subprojects, built in two stages. Altogether, the project is expected to cost as much as $54.5 billion, making it one of the largest natural gas projects in the world.
Gas would be pumped from North Slope wells to a processing plant on the North Slope, then down a pipeline to an export facility on the Kenai Peninsula.
Developers expect to reach a final investment decision on the project’s first phase this year. It would include the pipeline, part of the North Slope processing plant and part of the export facility.
Initially, the export facility would function in reverse, as a place for Alaska to import natural gas for local use while the pipeline is under construction.
Adam Prestidge, president of Glenfarne Alaska, told state senators on June 3 that after the final investment decision, it should take about three years for construction and commissioning before gas begins flowing through the pipeline to in-state residents.
The second, export phase of the project would take several more years to complete.
Switching from a property tax to a gas tax
The main intent of the bill is to replace Alaska’s 2% petroleum property tax with a lower tax on gas shipped through the pipeline.
The pipeline is exempt from the tax during construction, but the state would start collecting taxes when gas begins flowing. Glenfarne has said that’s a problem because it won’t begin making money until exports begin several years later.
Glenfarne executives have said they cannot get financing to build the pipeline unless the tax is changed.
That led Gov. Mike Dunleavy to propose the tax change in March. Legislators were unable to pass the bill by the time the regular legislative session ended in May, and Dunleavy has now called lawmakers into special session twice to get it done.
Because petroleum property taxes mostly go to municipalities, the amount received by cities and boroughs during that period would drop by another $5.3 billion.
Proponents of the change have focused on the benefits, rather than the lost revenue. Without the reduction, the pipeline cannot be built, they say. If the pipeline isn’t built, the state and municipalities get nothing.
“We want Alaskan gas for the Alaskan people, instead of Canadian gas for Alaskan people, instead of imports,” said Rep. Kevin McCabe, R-Big Lake, on the House floor. “It means the world to our people…lowered heating bills, a stronger economy.”
While proponents of the tax break have run a “Build the Line” ad campaign insinuating that the tax reduction would guarantee a pipeline, some state legislators say there is a low chance of a pipeline, even if the tax break becomes law.
Members of the conference committee tasked with negotiating a final compromise AKLNG tax bill from House and Senate versions, debate the bill on July 16, 2026, before moving it to a vote before the full House and Senate. (Photo by Corinne Smith/Alaska Beacon)
“This has been billed as the bill that either makes a pipeline be built or does not make a pipeline be built, and that just really is not true,” said Rep. Justin Ruffridge, R-Soldotna.
No ‘better shot’ at compromise, drafter says
The House and Senate passed different versions of HB 381 in June, sending the bill to a six-member multipartisan conference committee tasked with negotiating a compromise.
For weeks, the key point of contention has been whether or not the bill will also include the erasure of a tax exemption for “pass-through corporations,” generally large companies that are owned privately and not traded on public markets.
In Alaska, erasing that exemption would affect the oil and gas company Hilcorp, which operates the vast Prudhoe Bay oil field, among other work in the state.
It also would raise taxes on the proposed gas pipeline.
On Thursday morning, the conference committee adopted a new version of HB 381 that specifically exempts “income of an Alaska liquefied natural gas project” from the revised tax.
That would include all three segments of the pipeline project. But it was unclear whether it would cover gas shipments between the wellhead and the North Slope processing plant.
“It will be up to the Department of Revenue to determine the scope of that exemption,” said legislative attorney Emily Nauman, answering a question from Ruffridge.
The revised bill also delays the start of the tax until 2029. Affected companies would be required to submit an “informational tax return” the year before the tax starts.
That would give the state better information about how much money the tax will raise and whether the proposed tax rate needs to be changed.
Rep. Calvin Schrage, I-Anchorage, chaired the conference committee.
Rep. Calvin Schrage speaks on the House floor in support of the compromise AKLNG gas line tax bill in July 19, 2026. (Photo by Corinne Smith/Alaska Beacon)
“I don’t think, frankly, that we’re going to get a better shot at this,” he said before the House vote.
“I don’t think you’re going to get closer alignment between the different factions on this issue than you are going to get today.”
While the conference committee consulted with Glenfarne, the Dunleavy administration and the Alaska Gasline Development Corp., it didn’t discuss the bill at length with members of the House’s 19-person, all-Republican minority caucus.
Ruffridge, the minority caucus representative on the conference committee, said he received the final copy of the bill only 30 minutes before the meeting that adopted it.
On the House floor, members of the House minority lambasted the final version.
“In my opinion, this process was neither transparent nor collaborative,” said Rep. Frank Tomaszewski, R-Fairbanks and a member of the minority.
One member of the Democratic-independent-Republican coalition majority in the House also voted against the bill.
House Majority Leader Chuck Kopp, R-Anchorage, alluded to the way the pass-through tax would impact Hilcorp. Changing its taxes, he said, would deter future drilling because it would create uncertainty about what additional changes might be made in the future.
“From my perspective, that’s what’s killed this iteration of the bill,” Gov. Dunleavy said about the pass-through tax.
Climate protesters and oil advocates opposed the compromise
On Thursday morning, a small group of demonstrators gathered on the steps of the Capitol to protest the gas line and the proposed tax break. Protest signs called for investment in renewable energy instead of fossil fuels to help combat climate change, and called the megaproject a “pipedream” and a “scam.”
Protesters gather outside the Capitol on July 16, 2026, as lawmakers consider a tax cut for the proposed AKLNG gas line project. (Photo by Corinne Smith/Alaska Beacon)
“I’m really concerned about the cost to the state and to the communities that would be impacted by the project,” said Sally Schlichting, a Juneau resident. “Especially by these proposed tax breaks. I just think it’s horrendous to forego all that revenue for so long, and I feel like there’s very little guarantee this project will ever happen.”
Schlichting said she’s concerned that Alaska is giving up too much, and the project developer Glenfarne has not disclosed who is investing or how much.
“I just think this is the most wrong-headed way of approaching resource development,” she said. “We don’t fund our education. We are running out of money, and Alaskans own the resources, and we deserve to receive the revenue from it — and not later, now.”
Another Juneau resident, Emily Kane, called the project a “boondoggle,” and said she also came out to protest the project’s climate change impacts.
“I am very concerned about the habitability of the planet if we don’t seriously dial down fossil fuels,” she said. “I know young adults who are choosing to not have children, and it just really breaks my heart — this selfishness about not thinking about future generations.”
A group of pro-development organizations, including the Alaska Oil and Gas Association, Alaska Support Industry Alliance, Alaska Chamber of Commerce and Resource Development Council, briefly found themselves on the same side as the protesters.
After the conference committee passed its compromise version of HB 381, they sent a letter to legislators, urging them to vote down the conference committee compromise.
Rebecca Logan, CEO of the Support Industry Alliance, said by phone that the pass-through tax would hit companies that are drilling for gas in Cook Inlet, at a time when the region is running short.
“The gasline is our future, but what we’ve got right now, we can’t hurt,” she said.
With the cost of everything on the rise, getting a quick meal at an affordable price is becoming more of a necessity. Some restaurants offer great discounts.
If you run a WordPress site, then you know that spam is a real annoying problem whether it comes to contact forms, WordPress comments, or user registrations.
The good news is that stopping spam in WordPress is a lot easier than you probably think, and you don’t need expensive tools either.
We have spent over 16 years testing anti-spam plugins, tools, and refining strategies to keep WPBeginner and our other business websites safe from daily spam attacks.
In this ultimate guide, we’ll walk you through how to block each type of WordPress spam, step by step from the basics to advanced modern automated spam protection. These are the exact methods we’re using to protect our own websites.
We’re covering a lot of ground in this ultimate guide, so use the quick links below to jump straight to the section you want to learn about first:
WordPress comes with several anti-spam options that can protect your site against spam. These built-in options won’t stop every bot, but they will remove the easiest targets right away.
We always recommend turning these settings on first, because they cost nothing and take only a few minutes to set up.
Tighten Your WordPress Discussion Settings
To prevent comment spam, the built-in discussion settings in WordPress act as your first line of defense. They allow you to control who can post, what kind of links are permitted, and how much control you have over the conversation.
To configure these anti-spam controls, go to Settings » Discussion in your WordPress dashboard.
The most useful tool on this screen is the comment moderation queue. This tool acts as a holding area that keeps submissions hidden from the public until you have a chance to look them over.
Because nothing goes live automatically, spam never reaches your visitors, even if it manages to get past your other filters.
To turn this on, scroll down to the ‘Before a comment appears’ section and check the box next to ‘Comment must be manually approved.’
If you want, you can also enable ‘Comment author must have a previously approved comment.’ This lets returning commenters post without waiting for approval. However, be sure to review your published comments regularly since they won’t appear in your moderation queue.
After that, scroll to the ‘Comment Moderation’ box, where you’ll find a setting that limits links. Because spam comments almost always contain web addresses, WordPress can automatically hold any submission that includes too many links.
The field labeled ‘Hold a comment in the queue if it contains [X] or more links’ is set to 2 by default. Lowering that number to 1 will help you catch even more junk.
On the same screen, you can use the comment blocklist to automatically filter out unwanted content. This tool looks for specific words, names, email addresses, or web addresses and sends any matching comment straight to the trash.
In the ‘Disallowed Comment Keys’ box, you can paste your own trigger words, putting one on each line, and then save your changes.
Require a Name and Email, and Hold First-Time Commenters
Healthy discussions start with real people. Requiring commenters to enter a name and email encourages more thoughtful conversations and discourages anonymous drive-by comments.
Most genuine visitors won’t mind providing these details, and it helps create a more welcoming and trustworthy community around your website.
To enable this, scroll to the ‘Other comment settings’ section and check the box next to ‘Comment author must fill out name and email.’
Depending on the type of website you have, you may not need a comment section at all. If that’s the case, then you can simply disable comments entirely and that’ll get rid of the WordPress comment spam problem once and for all.
The most thorough option is the code method, which disables comment support across your entire site at once. It’s safest to add the snippet with a free code snippets plugin like WPCode rather than editing your theme’s files directly, so a theme update can’t undo it.
add_action('admin_init', function () {
// Redirect any user trying to access comments page
global $pagenow;
if ($pagenow === 'edit-comments.php') {
wp_safe_redirect(admin_url());
exit;
}
// Remove comments metabox from dashboard
remove_meta_box('dashboard_recent_comments', 'dashboard', 'normal');
// Disable support for comments and trackbacks in post types
foreach (get_post_types() as $post_type) {
if (post_type_supports($post_type, 'comments')) {
remove_post_type_support($post_type, 'comments');
remove_post_type_support($post_type, 'trackbacks');
}
}
});
// Close comments on the front-end
add_filter('comments_open', '__return_false', 20, 2);
add_filter('pings_open', '__return_false', 20, 2);
// Hide existing comments
add_filter('comments_array', '__return_empty_array', 10, 2);
// Remove comments page in menu
add_action('admin_menu', function () {
remove_menu_page('edit-comments.php');
});
// Remove comments links from admin bar
add_action('init', function () {
if (is_admin_bar_showing()) {
remove_action('admin_bar_menu', 'wp_admin_bar_comments_menu', 60);
}
});
If you’d rather not go site-wide, you can also turn comments off on individual pages. This is handy when you only want them gone on specific pages, like your Contact or About pages, which rarely need a comment section.
To do this, open the page in the WordPress content editor. Then click the ‘Discussion’ option in the right-hand sidebar and select ‘Closed.’
You can also stop spam from piling up on older content without touching your newer posts. If you don’t expect comments on old posts, then WordPress can close them automatically after a set number of days.
This gives spam bots fewer chances to target your archived content.
To set this up, head to Settings » Discussion and find the ‘Other comment settings’ section. Check the box next to ‘Automatically close comments on posts older than [X] days’, then set a sensible limit such as 30 or 90 days.
Disable Trackbacks and Pingbacks
Trackbacks and pingbacks notify you when another website claims to have linked to one of your blog posts.
While they were originally designed to help bloggers connect conversations across different websites, they’re now commonly abused by spammers to send fake link notifications.
Turning this feature off completely removes a whole category of junk notifications from your dashboard.
To disable these notifications, go to the Settings » Discussion screen in your WordPress dashboard. Here, uncheck the box next to ‘Allow link notifications from other blogs (pingbacks and trackbacks) on new posts.’
With that done, don’t forget to click ‘Save Changes’ at the bottom of the screen.
Just be aware that changing this option only protects the posts you publish from this moment forward. If you want to clean up the content you’ve already published in the past, you can follow our step-by-step guide on how to disable trackbacks and pings on existing WordPress posts.
2. Set Up Modern AI-Powered Spam Bot Protection for WordPress
In the era of AI where automated spam is increasing, the best defense against it is a modern AI-powered spam protection for WordPress.
These spam filtering solutions automatically detect and block spam on your WordPress comments, contact forms, and user registrations without the use of CAPTCHA which can hurt conversions.
On WPBeginner, we use ActiveLayer for this. It is AI-powered and runs server-side, so it stops spam invisibly, without a CAPTCHA and it’s GDPR compliant.
In the last 30 days, it has blocked over 25,739 spam comments and contact form submissions on our website. It even shows you a confidence score, and the reason behind every submission it flags, not just a pass-or-fail verdict when you look at their logs.
The free plan includes 1,000 spam checks with no credit card, and paid plans start at around $4 per month billed yearly.
The two other popular spam filtering plugins for WordPress you could try are Akismet or CleanTalk.
Akismet is very popular and still is a good fit for personal blogs, where its “name your price” plan can be free for non-commercial sites. But they have raised their prices significantly for commercial sites which is quite expensive for smaller businesses. For a business site, we would point you to either ActiveLayer or CleanTalk.
Whichever tool you choose, stick to just one, because running two spam filters at once can conflict and block real visitors. The benefit of these spam protection plugins are that they integrate with all other popular contact form plugins by default.
3. Power-User Tips for Stopping WordPress Comment Spam
So far we’ve configured the built-in spam prevention settings in WordPress, and an automated spam filtering plugin for WordPress. The combination of these two should block most spam.
However if you are not able to set up modern AI spam protection due to costs or another reason, then you can use one of these tips below to combat comment spam in WordPress.
Add a Free CAPTCHA to Your Comment Form
CAPTCHA is a simple test that most human visitors pass without any effort, while automated scripts fail it. We recommend adding Cloudflare Turnstile CAPTCHA to your WordPress comments because it’s free and fairly straight forward to set up.
To set it up, install and activate the free Simple Cloudflare Turnstile plugin. You will be asked to create a free account on Cloudflare’s website and connect it with the plugin.
Once that’s done, you can scroll to the ‘Enable Turnstile on your forms’ section. Simply check the boxes to protect all your WordPress forms and click ‘Save Changes’.
Google reCAPTCHA is another option, which you can add with the Advanced Google reCAPTCHA plugin. We no longer recommend it because Google has capped their free tier at 10,000 assessments per month for your entire organization whereas Cloudflare Turnstile stay free without limits.
Limit or Require Login to Comment
Another really effective way to stop comment spam in WordPress is to control who’s allowed to participate in comments.
If your comment section is open to everyone, then spammers can continuously flood your forms with automated links. Restricting comments to registered account holders ensures that only verified users can post. This forces a level of accountability that most bots will not bother trying to bypass.
Because it requires readers to go through the extra step of creating and logging into an account, this approach is best suited for membership sites, online forums, and private communities.
If you run an open, public blog, then we’d recommend using an automated filtering service or a reader challenge instead as those add less friction.
If you do decide to turn this restriction on, go to Settings » Discussion in your WordPress dashboard. Under the ‘Other comment settings’ section, check the box next to ‘Users must be registered and logged in to comment.’
As always, don’t forget to save your changes.
Use Antispam Bee for Free Keyword and Pattern Filtering
Some spam slips through basic checks by mimicking human writing. This is where a dedicated filtering plugin can help protect your site.
Antispam Bee is an excellent free, privacy-friendly anti-spam plugin that doesn’t require an API key or account registration. Installing Antispam Bee gives you a powerful set of local rules to analyze comment data before it even hits your database.
Once it’s activated, you can configure your rules by going to Settings » Antispam Bee.
We recommend enabling the options to:
Trust approved commenters.
Mark as spam.
Do not delete.
Use regular expressions (which allows the plugin to scan for known text and link patterns).
You should also check the box to ‘Look in the local spam database.’ This allows Antispam Bee to cross-reference new submissions against previous spam history on your site.
Under ‘Advanced,’ you can set Antispam Bee to delete existing spam after a set number of days, which keeps your database tidy without any manual effort.
We highly recommend leaving the email notifications for spam turned off in this section. A busy website can attract hundreds of automated submissions a day, and these alerts will quickly flood your inbox.
If you want to try one more free tweak, then you can remove the website address field from the comment form.
4. Stopping WordPress Contact Form Spam (Best Practices)
Contact and lead forms are among the most attacked parts of any WordPress site. We know this firsthand because we once had to combat more than 18,000 spam entries flooding a single form.
We use WPForms to build forms on WPBeginner, and it’s a popular form builder plugin used by over 5 million websites. Their free version includes smart anti-spam protection, CAPTCHA integrations with Google / Cloudflare Turnstile, and the paid plans add the filtering options we cover below.
Other popular form builders like Gravity Forms and Fluent Forms have similar anti-spam settings, so check the options in whichever form builder plugin you use. We will show WPForms here because it’s what we use and consider the best fit for beginners.
Enable Default Anti-Spam Token (or Similar HoneyPot)
To combat lead form spam, WPForms silently attaches a unique, time-sensitive token to your form on every page load. The anti-spam token blocks automated scripts, which means spam entries are blocked before they reach your inbox.
It’s turned on by default for new forms, but it’s worth confirming.
Open your form, go to Settings » Spam Protection and Security, and make sure ‘Enable modern anti-spam protection’ is switched on.
This is a modern version of the Honeypot technology which most WordPress form plugins come with, so it may be labeled as Honeypot in another form tool that you might be using.
Enable a CAPTCHA on Your Contact Form
More aggressive bots mimic human browsing and slip past the invisible token. Adding a visible CAPTCHA field stops them by forcing a challenge they can’t read or solve.
WPForms has both Cloudflare Turnstile and Google reCAPTCHA built in, and we default to Turnstile here. It’s free for everyone and runs its checks in the background, so most real visitors pass without solving a puzzle.
To set it up, go to WPForms » Settings » CAPTCHA and choose ‘Cloudflare Turnstile’.
Google reCAPTCHA is also selectable on that same WPForms » Settings » CAPTCHA screen. We default to Turnstile because it’s free without limits, but reCAPTCHA still works if you prefer it.
If you’d rather not send visitor data to Google or Cloudflare, then WPForms’ Custom Captcha field (available on any paid plan) builds the challenge on your own server instead.
Add the field, then set it to a random math problem or your own question and answer.
Use Time-Based Behavioral Checks to Stop Contact Form Spam
A real person needs several seconds to read a question and fill out a form, while a bot submits in a fraction of a second. Time-based checks flag those impossibly fast submissions without changing anything the visitor sees.
With WPForms, the ‘Enable minimum time to submit’ option is enabled by default with a minimum time to submit of 2 seconds. However, you can update the minimum time to any value you like.
Block Form Submission by Country, IP, Email Address, and More
Some spam form submissions still gets through unless you screen the content itself. In the Pro version, WPForms lets you block entries by specific email address, by keyword, and by country or IP address.
To block a sender, open your form, select the Email field, open the Advanced tab, choose Denylist, and enter the addresses or domains to ban. A wildcard like *@example.com blocks an entire domain.
To block spammy phrases, go to Settings » Spam Protection and Security.
Turn on ‘Enable keyword filter’, open ‘Edit keyword list’, and add each term on its own line.
And if you only serve certain regions, turn on ‘Enable country filter’ on the same screen to allow or deny locations.
5. Stopping Spam User Registrations in WordPress (Best Practices)
On a membership site or WooCommerce store, spam registrations are more than a nuisance. Fake accounts clog your user database and skew your customer and email metrics.
Here’s what you can do to prevent spam user registrations in WordPress.
Turn Registration Off When You Do Not Need It
If you’re not running a membership site or an eCommerce store, then you likely don’t need to allow user registration. The easiest thing to prevent user registration spam there is to turn it off.
Simply go to Settings » General in your WordPress admin area, and uncheck the ‘Anyone can register’ box.
Require Email Confirmation Before an Account Activates
If you do need open registration, then the goal is to let only real people in while keeping spam bots out. The setting that stops the most fake signups is requiring a confirmed email address, or a manual review, before an account goes live.
Where that control lives depends on what plugin you’re using to manage user registration in WordPress. You will want to start with your platform’s default setting instead of bolting a general form plugin onto a system that already handles this.
If you run a WooCommerce store, then go to WooCommerce » Settings » Accounts & Privacy. This is where you decide whether shoppers can create an account at all, limit account creation to checkout, or keep guest checkout on so no account creation is needed.
WooCommerce core doesn’t add a separate email-confirmation step on its own. If you want one, then you’ll need a custom email verification extension or the custom signup form covered below.
Other membership and course platforms handle account verification in their own settings, so start there:
BuddyPress and BuddyBoss: email activation is built in, so new members stay inactive until they click the activation link. Enable registration under Settings » General (BuddyPress) or BuddyBoss » Settings » Login & Registration. See BuddyPress documentation and BuddyBoss documentation for more details.
LearnDash: registration runs on WordPress’s own user system, so there’s no native email-confirmation step. An account goes live the moment someone signs up. To hold new accounts until the email is verified, add that check at the WordPress or form level, using a user verification plugin or the custom WPForms registration form covered below.
If you’re building a custom registration form rather than using one of the systems above, then you can use WPForms User Registration addon which lets you turn on email activation under the form’s User Registration settings, with either an email confirmation link or manual admin approval.
Similar options are available in Gravity Forms, WSForm, and other popular WordPress form plugins. For the full walkthrough, see our guide on how to moderate new user registrations.
Add CAPTCHA and Honeypot to WordPress Signup Form
The same tips that protect your WordPress contact forms also work on WordPress signup form. Since you already set up Cloudflare Turnstile earlier, you can switch it on for your registration form in a click.
If you’re using the default WordPress registration page, then you can add hidden honeypot fields to your registration form with the free WP Armour plugin. The plugin logs every bot it blocks under WP Armour » Statistics.
Use AI-Powered Tools for Blocking WordPress Registration Spam
Honeypots and CAPTCHAs stop obvious bots, but they can’t spot someone signing up with a throwaway email or from a known-bad IP address.
That’s where automated detection helps. It screens each new signup against live reputation data and blocks the ones that look fraudulent.
ActiveLayer and CleanTalk both offer this for WordPress registrations, and you can switch it on for your signup form the same way you did for your contact forms.
6. Add a Site-Wide WordPress Firewall
A Web Application Firewall (WAF) screens every visitor and blocks malicious requests before they reach your site. Since most form spam is automated, a good firewall can stop a lot of it at the perimeter.
We recommend a DNS-level firewall, which filters traffic on the provider’s network before it touches your server.
On WPBeginner, we use Cloudflare, which has a free plan with basic firewall protection (setup requires pointing your domain’s nameservers to Cloudflare).
Stopping new spam is only half the job. If you’re like most websites, you already have a backlog of old junk that needs cleaning up.
A quick cleanup keeps your database tidy and helps your new tools run at their best.
🚨 Always create a complete WordPress backup before deleting anything in bulk. These actions permanently wipe data, with no undo button if you make a mistake.
Bulk-Delete Existing Spam Comments
WordPress spam filter flags junk comments but doesn’t delete them, so they can build up in your spam folder and take up database space until you clear them out.
In your dashboard, go to Comments, click the ‘Spam’ filter at the top, and hit ‘Empty Spam’ to permanently clear everything your filters caught.
If you have thousands of junk comments, the dashboard can freeze or time out. A free plugin like WP Bulk Delete is faster and more reliable for big backlogs.
Leaving bot profiles in your database is a security risk and skews your analytics. That’s why it’s important to clean out these fake accounts.
For a handful, go to Users » All Users, click the ‘Subscriber’ user role filter (the role almost all registration bots use), select the fake accounts, and choose Delete from the ‘Bulk actions’ menu.
⚠️ Be very careful to select only fake Subscriber accounts, and never an Administrator account.
For thousands of accounts, the free WP Bulk Delete plugin can remove users by role, inactivity, or registration date in one sweep.
No filter is perfect, so never auto-delete your spam folder without a quick glance first.
In Comments » Spam, hover over a legitimate comment and click ‘Not Spam’. That also teaches your filter to recognize similar comments as safe in the future.
Set a Monthly Anti-Spam Review Routine
A few minutes each month keeps spam from piling back up. Add these three checks to your maintenance routine:
Scan for false positives: skim your spam comment folder and form entries so no real messages were caught by accident.
Empty your spam folders: once you’ve rescued anything real, clear them to keep your database lean.
Check your user list: glance at new registrations for gibberish usernames or suspicious email domains that slipped through.
Key Takeaways
Here is a summary of the best practices we have covered to completely protect your WordPress website from spam:
Start with free WordPress settings: turn on comment moderation, tighten your link limits, build a comment blocklist, and disable trackbacks. These cost nothing and clear out the easiest spam.
Use automated, invisible filtering: a server-side tool like ActiveLayer, Akismet, or CleanTalk blocks bots in the background without making real visitors solve puzzles.
Layer your contact form defenses: honeypots alone no longer stop modern bots, so combine them with timing checks, token validation, and an automated filter.
Secure your registrations: require email confirmation for new accounts and screen every signup with an automated tool.
Add a site-wide firewall: a DNS-level firewall like Cloudflare blocks a lot of automated spam at the perimeter, before it ever reaches your forms.
Run regular cleanup: bulk-delete old spam comments and fake accounts, then spend a few minutes each month checking for false positives.
Frequently Asked Questions About WordPress Spam Protection
Is free Akismet-style filtering enough, or do I need
more?
For a small personal blog with only comment spam, a single free filter like Akismet is usually enough. Once you add contact forms, signup forms, or user registration, you’ll want a service that protects those too, like ActiveLayer or CleanTalk.
Will adding a CAPTCHA hurt my form conversions?
It can. The extra step causes some real visitors to give up on the form. This is why we prefer invisible, server-side detection that blocks bots without asking anyone to solve a puzzle.
Why am I still getting spam after installing an anti-spam
plugin?
Usually because the plugin only guards one entry point. If it protects your
comments but not your signup or contact forms, bots just move to those
instead, and older tricks like basic honeypots no longer stop modern bots. The
fix is a layered setup: your built-in WordPress settings, an automated
filter, and a firewall working together.
How do I stop fake user registrations without turning off signups
completely?
Turn on email confirmation so new accounts stay inactive until the person
clicks a link in their inbox, which bots can’t do. Pair it with a honeypot and
an automated filter, and real people can still sign up freely.
Can spam actually hurt my SEO or get my site
blacklisted?
It can, but it depends on where the spam is. Comment spam sitting in your moderation queue is never published, so search engines never see it and your SEO stays safe.
Published spam is the real risk, because it can slowly pull down your rankings. WordPress does tag comment links as nofollow, which limits the damage.
We hope this article helped you learn how to protect your WordPress website against spam. You may also want to check out our ultimate WordPress security guide to improve your website security.
If you liked this article, then please subscribe to our YouTube Channel for WordPress video tutorials. You can also find us on Twitter and Facebook.
Luke Bryan is celebrating a milestone today as the country superstar officially turns 50 years old.
Ahead of the big 5-0, we caught up with Bryan backstage at CMA Fest, where he closed out the four-day festival with a headlining performance at Nashville’s Nissan Stadium. While fans were excited to see him take the stage, we couldn’t resist asking what he had planned for such a major birthday.
In true Luke Bryan fashion, his answer was equal parts hilarious and over-the-top.
Luke Bryan; Photo by Andrew Wendowski
“It will be a ginormous undertaking. It’s going to be a big party,” he teased.
Then, taking inspiration from his buzzed-about new song, “Fish Hunt Golf Drink,” Bryan painted a picture of what his dream birthday celebration would look like.
“There will be fishing. There will be golfing. There will be climbing of trees. There will be coffee. There will be Advil. There will be IVs. There’ll be Vitamin C… There’s going to be golf. There’s going to be skydiving, bungee jumping. Yeah. It’s going to be a blowout.”
Whether or not any of those plans actually make the itinerary remains to be seen, but one
thing’s for sure: Bryan knows how to keep fans laughing.
One person who may or may not receive an invitation is his longtime friend and fellow country superstar, Blake Shelton, who celebrated his own 50th birthday just a few weeks earlier.
Never one to pass up the opportunity to poke fun at his buddy, Bryan joked, “I wear 50 a lot better than him.”
He doubled down on the playful rivalry by revealing he wasn’t exactly rolling out the red carpet for Shelton on his birthday.
Luke Bryan performs at Nissan Stadium on Sunday June 7, 2026, during CMA Fest presented by SoFi in downtown Nashville; Photo Courtesy CMA
“[I’m] not inviting him to my party,” Bryan laughed, before adding that he sent Shelton “a save the date, but I didn’t even put the date on there.”
Of course, the friendly back-and-forth is all part of the duo’s longtime relationship, which has been filled with years of playful jabs. If Bryan’s birthday celebration is anything like he described, fans can expect it to be every bit as entertaining as the man himself.
Luke Bryan is currently on a break from his Word on the Street Tour, and will return to the road on July 23 with a show in Southaven, MS at Bank Plus Amphitheater. The tour runs through September 12.
His brand new album, Signs, is set to drop on September 18.
The timing was enough to make fans wonder if there was any overlap between these two relationships.
Ariana Grande attends the “Wicked: For Good!” New York Premiere at David Geffen Hall on November 17, 2025 in New York City. (Photo by Jamie McCarthy/Getty Images)
Thankfully, a source close to the situation assures the Daily Mail that Ariana “never crossed the line while she was with Ethan.”
So no, despite rumors to the contrary, Ari is not guilty of “branch-swinging” (the term for when you start a new relationship while still another one).
But it seems that Ethan didn’t hear the news of Ariana’s new relationship directly from his ex.
“Ariana hasn’t told Ethan specifically, but mutual friends have told him that she is now dating Ricky again,” an insider told the Mailon Friday.
The revelation comes just days after reports confirmed that Grande and Alvarez — who dated from 2015 to 2016 — have given their relationship another chance.
And apparently, Ethan found out through people in their shared circle after news of Ariana’s reunion with Ricky began spreading.
Despite the awkward circumstances, the source insisted there isn’t any lingering hostility between the former couple.
“There isn’t any bad blood,” the insider claimed, adding that Grande and Slater remain on good terms despite ending their relationship several months ago.
The report also pushes back on any suggestion that Grande’s romance with Alvarez began before her relationship with Slater ended.
According to the source, Grande and Alvarez stayed friendly over the years because they share many mutual friends, but they never crossed any romantic boundaries while she was still dating Slater.
Only after Grande’s relationship with the Broadway actor came to an end did she and Alvarez begin spending more time together one-on-one.
The insider described the reunion as a more mature relationship than the one they shared nearly a decade ago.
“They’ve both talked through what went wrong the first time,” the source said, adding that they’re approaching this chapter differently.
Ariana has already altered the lyrics to “thank u, next” in live performances in order to better express her change of heart toward Ricky.
And the way things are going, it sounds like she might be writing whole songs about him soon!