Every filter that blocks anything makes occasional wrong calls. The design question is not whether that happens — it is what happens to the lead next, and who holds the evidence.
Any vendor who tells you their filter never blocks a real person is telling you something about their marketing, not their filter. A system judging the traffic you can watch arriving on the live threat feed makes millions of calls, and at any accuracy short of perfect, a tiny fraction of those calls are wrong in the direction that matters: a real person, blocked.
Most anti-spam products handle that case in one of two uncomfortable ways. Either the blocked submission is simply gone — discarded at the moment of judgement, no appeal, no record — or the vendor keeps a copy of everything so you can dig through it later, which means your lead data now lives in someone else's database, under their retention policy and their breach surface.
SpamKill's answer is a layered one, and the layers are worth understanding separately, because each covers the failure mode of the one before it. (This guide is about what happens after a block — for how the blocking itself works without challenging your visitors, start with how to stop form spam without a CAPTCHA.)
On every plan, a flagged visitor is not silently discarded. They are offered a one-step verification — depending on configuration, a device biometric, a quick social sign-in, or re-entering a field value — and on completing it they come straight through. No image grids, no puzzles. For the overwhelming majority of false positives, this is the whole story: the person proves they are a person, the lead lands, and the cost was a moment's delay.
But "the overwhelming majority" is not "all". Some people abandon anything unexpected. Some are on devices or networks where the verification does not complete. If your leads are worth hundreds or thousands of dollars each, "they probably verified" is not an answer you want to rely on.
Assume the worst case: a real lead was flagged, and the person did not or could not verify. This is where Submission Logging comes in.
With Submission Logging enabled and configured, SpamKill streams every submission your forms receive — allowed and blocked alike — to your own Datadog account in real time, with full metadata: the submitted fields, the IP and country, the timestamps, and the exact reason for the decision. Not a summary. Not a sample. The lead itself.
The stream goes to your Datadog account, not ours. SpamKill judges the submission in-flight and keeps nothing afterwards — the only durable copy of your lead data is the one in the account you control, under your retention settings, your access rules, and your export tools. If you cancelled tomorrow, the log would still be yours.
Because it is ordinary Datadog log data, you can also do ordinary Datadog things with it: dashboards over submission volume, alerts on block-rate spikes, queries joining form activity to the rest of your observability. The integration is read-only — SpamKill writes the stream and cannot process or act on anything from there.
A raw log makes the lead recoverable in principle. Blocked Lead Review makes it recoverable in practice: a dedicated interface that connects to your Datadog account and reads the blocked submissions straight from your logs, presented one decision at a time — who it was, what they submitted, and why it was blocked.
When you spot a real lead in there, two things happen. One click marks it as a false positive, and the model learns from the correction — your feedback tightens future judgement on your traffic. Then you copy the person's details — name, email, message — into your CRM or list by hand, and follow up as if the block never happened. The lead is not lost; it was delayed.
The manual copy step is a design choice, not a limitation. SpamKill has no write access to your CRM, your list, or your Datadog account beyond appending the log stream — so there is no path by which it could alter, sync, or leak what it judged.
It would have been easier to build this the usual way: keep a copy of every submission on our side, show it back to you in a dashboard. Most tools do. The trouble is what that architecture means for you:
| Vendor stores your leads | Your own Datadog stores them | |
|---|---|---|
| Who controls retention | The vendor's policy | You |
| Who controls access | The vendor's staff and systems | Your account permissions |
| Extra breach surface | Yes — a second database of your leads | No new copy created |
| Data after you cancel | Whatever the contract says | Still in your account |
| Auditable independently | Only through the vendor | Yes — it is your log |
A form protection product necessarily sees your leads for the milliseconds it takes to judge them. It does not need to keep them, and with Submission Logging the review workflow works without it ever doing so. Your data stays under your ownership because it never leaves it.
SpamKill blocks automated submissions at 99.9% accuracy for 1,500+ businesses — and treats the residual error honestly instead of pretending it away. A flagged real person verifies through in one step; with Submission Logging enabled, even the ones who don't are sitting in a log you own, reviewable and recoverable, with nothing about your leads stored on our side. See Submission Logging and Blocked Lead Review for the feature details, or how the guarantee leans on that log. From $29/month with a 30-day free trial, no credit card.
The visitor-side recovery still works on every plan: a flagged person can verify in one step and come straight through, so a false positive is a moment's delay rather than a silent loss. But a blocked submission that nobody verified is not kept — SpamKill does not store your lead data. Submission Logging exists precisely to close that gap: with it enabled, every submission is in your own Datadog account whether or not anyone verified.
The decision is made in-flight and nothing is kept afterwards. With Submission Logging enabled, submissions stream directly to your own Datadog account, and the Blocked Lead Review interface reads them back from your account at the moment you open it. The one exception is deliberate and opt-in: the Elite plan's Submission Audit & Review stores submissions on SpamKill's side so the full stream is reviewable in one place — encrypted at rest under your own personal secret key, not a shared platform key.
Yes — it is a separate subscription, and that is the point: the log lives in an account you control, under your own retention settings and access rules. If you are not on Datadog, the built-in console still reports block reasons, country breakdowns, and challenge results without any external tooling; what it cannot give you is a full copy of every submission, because we do not keep one.
Open it in Blocked Lead Review, which shows the full submission and the exact reason it was blocked. One click marks it as a false positive, which the model learns from. Then copy the person's details into your CRM or list by hand. The manual step is deliberate — SpamKill has no write access to your systems, so nothing can be inserted, altered, or synced on your behalf.
SpamKill screens at 99.9% accuracy, and most of the residual error never becomes a lost lead: a flagged real person is offered a one-step verification and comes through on their own. The blocked-and-unverified case — someone flagged who did not or could not complete the step — is rare, which is exactly why it deserves a recovery path rather than a shrug.
Paste your form HTML into the Form Transformer and get the protected version back — no signup, no card, nothing to install.
Open the Form Transformer