Humainbox stops spam from reaching you through your website’s contact forms — including the new kind, written by AI, that walks straight past CAPTCHAs and keyword filters. Real enquiries still reach you, and nothing is ever deleted.
This plugin connects your forms to Humainbox in a few clicks, and shows you where every form on your site sends its enquiries today.
Why contact form spam got worse
Spam used to be easy to spot: broken English, a dozen links, “SEO services”. Today it is written by AI. It reads like a real person, mentions your business by name, and passes every CAPTCHA, honeypot and keyword list — because it was designed to.
The usual fixes cost you real customers instead. A CAPTCHA makes genuine visitors give up before they press send. A stricter filter starts catching real enquiries, and a lost lead is silent: you only find out when somebody asks why you never replied.
How Humainbox works
- Your form sends to Humainbox. Each form sends its notification email to your own Humainbox address instead of straight to your inbox. That is the only change — nothing is added to your website, and your visitors see no difference.
- Humainbox checks every submission. Machine-written spam is held back. Each held message comes with the reason it was held.
- Real enquiries reach you. They are forwarded to the people you choose, with the visitor’s own address set as the reply address — so pressing Reply answers the visitor, exactly as before.
Held is not deleted. Anything Humainbox holds stays readable in your Humainbox panel, and one click sends it on.
What it holds back, and what always reaches you
Held back as spam:
- SEO, link-building and “rank higher on Google” offers
- Web design, app and offshore development pitches
- Crypto, traffic and directory-listing schemes
- Template messages sent to thousands of sites at once
- All of the above when written fluently by AI — the kind CAPTCHAs no longer stop
Always reaches you:
- Enquiries, quote requests and bookings
- Complaints and support questions
- Job applications, press and partnership approaches
- Suppliers introducing themselves
- Anything Humainbox is unsure about — when in doubt, it delivers
Safe from the first minute
- Nothing is blocked in the first week. Every new Humainbox inbox starts in dry run: every submission is still delivered to you, while Humainbox shows you what it would have held. You decide to switch filtering on once you have seen it work on your own mail.
- Every change can be undone. Before this plugin changes a form, it saves the address the form used. One button puts it back.
- A test before anything depends on it. One button sends a test message to your Humainbox address, the same way your forms send theirs. It also tells you if your site cannot send email at all — which would mean your forms have not been delivering either.
What this plugin does
- Lists every form from Contact Form 7, WPForms, Gravity Forms, Elementor Forms, Ninja Forms, Fluent Forms, Forminator and Formidable Forms, and the address each one sends its enquiries to. This part works without an account, and warns you about any form that notifies nobody.
- Points the forms you choose at Humainbox in one action, instead of opening each form’s settings one by one.
- Keeps the addresses it replaced and restores them on request.
- Leaves alone what it should not change — for example, the “copy of your message” email that goes back to the visitor.
It adds nothing to your pages: no scripts, no styles, no CAPTCHA, no links. It works only on its own settings screen, under Settings → Humainbox.
Getting started
- Install and activate the plugin, then open Settings → Humainbox. The table shows your forms and where each one sends today.
- Create a free Humainbox account at humainbox.com — no card needed.
- In Humainbox, choose who should receive your enquiries. Anyone other than you gets one email asking them to confirm; until they do, their mail waits in your Humainbox panel.
- Copy your inbox address (under Inboxes), paste it into the plugin and press Send a test message. It should appear in your Humainbox panel within a minute.
- Tick the forms you want protected and press Connect selected forms to Humainbox.
Supported form plugins
- Contact Form 7
- WPForms and WPForms Lite
- Gravity Forms
- Elementor Forms (Elementor Pro)
- Ninja Forms
- Fluent Forms
- Forminator
- Formidable Forms
Other form plugins are not listed and are never touched. You can still connect them by pasting your Humainbox address into their notification settings by hand — the steps for each are at https://humainbox.com/integrations
About Humainbox
Humainbox is an online service run by Reaktör Teknoloji. It has a free plan for one inbox and paid plans for teams and agencies. Everything in this plugin works the same on every plan.
External services
This plugin makes no network requests. It does not call any API, load anything from a
remote server or send any data about your site in the background.
The address you enter is stored in your own database and written into your own form
plugins’ settings.
Two things do result in email being sent, both only when you press a button:
- Send a test message sends one email, through your site’s own mail (wp_mail), to the
Humainbox address you saved. It contains your site’s address and the display name of
the logged-in user who pressed the button.
- Connect selected forms to Humainbox changes where those forms send their notifications.
From then on, each form submission — the fields your visitors fill in — is emailed by
your form plugin to your Humainbox address instead of to the address it used before.
Mail sent by your forms goes wherever the address you choose points — that is what
changing a notification recipient means, and it is true of any address you type into
those settings, ours or anyone else’s. If that address is a Humainbox address, the
Humainbox service handles the message under its own terms and privacy policy:
- Terms: https://humainbox.com/legal/terms
- Privacy: https://humainbox.com/legal/privacy