If your welcome email is going out to addresses like xkqwe8812@ and dozens of new subscribers arrive within a few minutes, bots have found your signup form. Fake signups can trigger your welcome emails, bounce, use up sending volume and distort your list numbers. Enough bounces and complaints can also hit the limits your email provider uses to suspend sending. What helps is a mix of form protections, plus a clean-up of the contacts that already got in.

Picture how it plays out. The newsletter list grows faster than it ever has, which looks good for a day. Then the welcome automation report fills with bounces, someone notices signups with nonsense names, and in a bad case the email platform pauses the account before anyone has looked at the form.

How to tell it's bots

Open your recent signups and look for patterns:

  • many signups in a short burst or a tight time window;
  • names that are random strings, or a name field filled with a link or a sales message;
  • addresses from temporary-email services;
  • a spike in hard bounces on the welcome email;
  • real-looking addresses that never open anything and sometimes report spam.

That last one is easy to miss. Bots don't only invent addresses; they also submit real people's addresses without their knowledge. Those people get a welcome email they never asked for, and some of them press "Report spam".

Stop new fake signups

No single method stops everything. Brevo's own guide on form bots recommends combining several at once. Here's what each one does and what it costs real visitors:

Method What it stops What it costs real people
Honeypot (hidden field) Simple bots that fill every field Little: the field is hidden from visitors
CAPTCHA, visible checkbox or puzzle Automated submissions that can't pass the challenge One extra click, sometimes an image puzzle
CAPTCHA, invisible (reCAPTCHA v3, Turnstile) Bots that behave unlike people Usually nothing visible; you choose what to do with doubtful scores
Double opt-in (confirmation email) Fake addresses and addresses entered without the owner's consent One extra step; some real people never confirm
Block disposable addresses Throwaway signups Little, for a normal store
Block free addresses (Gmail, Yahoo...) Signups without a business address A lot for a consumer store, where many customers use these addresses
Rate limiting Many submissions from one IP address in a short time Nothing, unless the limit is set very low

A few notes on the less obvious rows.

Honeypot. It's a form field hidden with CSS. People can't see it, bots that fill in every field fill it in too, and any submission with that field filled is discarded. It takes basic HTML and CSS to add. It's a cheap first layer, but it only catches bots that fall for it, so don't rely on it alone.

Invisible CAPTCHA. Google's reCAPTCHA v3 never shows a challenge. It returns a score from 0.0 (very likely a bot) to 1.0 (very likely a person), and your site decides what to do below a threshold. Google suggests 0.5 as a default. Cloudflare's Turnstile works without a visual puzzle in most cases, and you don't need to route your site through Cloudflare to use it. Both need a server-side check of the token, so with a form plugin, confirm it actually does that step. Both are run by third parties, so check your privacy notice before adding one.

Blocking free addresses. This makes sense for a B2B service that only wants work emails. For a shop selling to consumers it can block many real customers. Blocking disposable addresses is the safer half.

Rate limiting. Capping how many times one IP address can submit the form in a given period stops floods from a single source. It's set up on the website side (server, firewall or form plugin), not in your email tool.

A sensible default for a small store: honeypot plus an invisible CAPTCHA plus disposable-address blocking. Add double opt-in if bots keep getting through or if you've already had complaints.

Double opt-in: the trade-off

With double opt-in, the signup only becomes a subscriber after the person clicks a link in a confirmation email. A bot can't click a link sent to an address it made up, and a stranger whose address was entered without their knowledge simply doesn't confirm.

The cost is that some real people don't confirm either: they miss the email, or forget. You get a smaller list in exchange for one where every address works and belongs to someone who asked. Brevo also points out that each confirmation step is logged, which gives you a record of consent.

If you switch it on, change two things in your welcome flow:

  1. Trigger the welcome sequence on confirmation, not on form submission.
  2. If the form promises a discount code, deliver it in the first email after confirmation, and say so on the form ("confirm your email to get your code").

Clean out the fake contacts already on your list

Protection only stops new signups. The ones already in your list will keep receiving every campaign until you remove them.

  1. Find the date range when the attack happened. The burst of signups from the first section can mark it.
  2. Filter contacts added in that window. Look for the same patterns: nonsense names, disposable domains, hard bounces, no opens or clicks.
  3. Remove or blocklist them, and remove them from any running automation so the welcome sequence stops sending.
  4. For contacts you can't classify, send one confirmation email ("did you mean to subscribe?") and keep only those who click.
  5. Check your welcome automation report afterwards. If bounces are back to normal, the cleanup worked.

Don't send a regular campaign to the whole list before this is done. That's the send that hits the bounce and complaint numbers hardest.

Why it puts your whole sending account at risk

Email platforms watch the results of your sends. Brevo, for example, can suspend campaigns and the account when a recent send goes above 2% hard bounces, 1% unsubscribes or 0.2% complaints, and it says it won't reactivate an account suspended a second time. Fake addresses push all three numbers in the wrong direction at once.

Brevo is also direct about forms: if an unprotected form gets hit by bots, the account can be suspended, and getting it back means adding a CAPTCHA to that form and contacting support with a link to it. Nothing sends from a suspended account until it's reactivated, so if the same account also sends your order or contact-form emails, a newsletter form can end up blocking mail customers actually need.

Where Brevo's form protection fits

If your newsletter form is built in Brevo, several of these protections are settings rather than code. Its forms can use Google reCAPTCHA or Cloudflare Turnstile, can require double confirmation, and can block signups from free and disposable addresses. The address blocking is only on the Standard, Professional and Enterprise plans; on lower plans, check what your form settings include and lean on CAPTCHA and double opt-in.

The limit: these settings protect forms built in Brevo. If your signup form comes from your store theme or a WordPress plugin, CAPTCHA, honeypot and rate limiting have to be set up there. Brevo can still run the double opt-in step for a form built elsewhere, through an automation.

Once the list is clean, it's worth checking that your welcome email sequence starts at the right moment, especially if you switched to double opt-in.