Introduction
Spam submissions are not just a nuisance; they waste your time, energy, as well as skew your conversion analytics in Gravity Forms. It may even pose security risks if it includes phishing links in the submissions. Gravity Forms doesn’t have the native functionality to block spam email IDs or domains.
To fix that, we have built the functionality to block spam submissions by email so that it never reaches your inbox. You can create an allowlist/denylist of emails for the form and have full control over the emails that can be used in your forms.

Why Email-Based Spam Happens
Most spam bots rely on free or disposable email services so that in case you reply to the form submission, then get the reply.
Disposable email domains like tempail.net, mailinator.com, yopmail, etc. don’t even require you to sign up to create temporary emails. So, they are mostly used by spam bots.
They are difficult to stop using anti-spam features like CAPTCHA, honeypots, or keyword filtering only.
How to Create Emails Denylist/Allowlist for Gravity Forms
Email filtering is part of the free version of Booster for Gravity Forms. Once you have installed and activated the plugin, follow the steps below
- Log in to your WordPress dashboard and navigate to Forms -> Booster.
- Select the form for which you want to create an email allow/deny list.
- Now to the Anti Spam panel and then the Restrictions section.
- Enable the Email Validation setting. Now you will get the following settings
- Allowlist/Denylist: From this list, select whether you want the form to be spam protection to only allow specific emails or block specific emails.
- Then you will have the option to enter the list of email IDs. You can add specific email IDs like abc@gmail.com or use *@gmail.com to block the whole domain.
- Action to Perform: If the email field contains the blocked email IDs, then decide whether to make the form entry as spam or give them a validation error.
- Validation Message: If you have selected to restrict form submission, then here you can enter the validation message, which will be shown to users in case of a blocked email ID.

Real World Example
Let’s say you’re getting a lot of spam emails from ‘john@spamseocompany.com, joe@spamseocompany.com, mark@spamseocompany.com’, then you can block all of them by just entering ‘*@spamseocompany.com’ in the denylist for your form
Private Forms with Allowlist
Let’s say you have an internal form in your company to submit feedback/suggestions for company policies. In such cases, you may only allow form submissions from email IDs belonging to your company.
In such a case, switch to ‘Allowlist’ and add *@yourcompany.com to it. For action to perform, select ‘restrict’ submission and give an error message like ‘this email ID is not allowed to submit the form’.
Features of Email Filtering for Gravity Forms
- Fully local – no external API calls
- Doesn’t slow down your site
- Works with multi-page forms
- Compatible with all email fields
- No styling conflicts or theme issues
Conclusion
The email filtering is a simple yet effective solution to block spam submissions in Gravity Forms. Moreover, you have full control over what gets blocked and what passes through. There are no third-party API calls.
If you’re fed up with spam Gravity Forms submissions, then this surely is an effective way to save your time and energy.

0 Comments