Feature guide

Recovering wrongly blocked leads

Every filter that blocks anything makes occasional wrong calls. The design question is not whether that happens — it is what happens to the lead next, and who holds the evidence.

Updated July 2026 · 7 min read

Any vendor who tells you their filter never blocks a real person is telling you something about their marketing, not their filter. A system judging the traffic you can watch arriving on the live threat feed makes millions of calls, and at any accuracy short of perfect, a tiny fraction of those calls are wrong in the direction that matters: a real person, blocked.

Most anti-spam products handle that case in one of two uncomfortable ways. Either the blocked submission is simply gone — discarded at the moment of judgement, no appeal, no record — or the vendor keeps a copy of everything so you can dig through it later, which means your lead data now lives in someone else's database, under their retention policy and their breach surface.

SpamKill's answer is a layered one, and the layers are worth understanding separately, because each covers the failure mode of the one before it. (This guide is about what happens after a block — for how the blocking itself works without challenging your visitors, start with how to stop form spam without a CAPTCHA.)

Layer one: the visitor recovers themselves

On every plan, a flagged visitor is not silently discarded. They are offered a one-step verification — depending on configuration, a device biometric, a quick social sign-in, or re-entering a field value — and on completing it they come straight through. No image grids, no puzzles. For the overwhelming majority of false positives, this is the whole story: the person proves they are a person, the lead lands, and the cost was a moment's delay.

But "the overwhelming majority" is not "all". Some people abandon anything unexpected. Some are on devices or networks where the verification does not complete. If your leads are worth hundreds or thousands of dollars each, "they probably verified" is not an answer you want to rely on.

Layer two: a record of everything — sealed with your key

Assume the worst case: a real lead was flagged, and the person did not or could not verify. This is where Submission Logging comes in.

Every blocked submission is kept, with full metadata: the submitted fields, the IP and country, the timestamps, and the exact reason for the decision. Not a summary. Not a sample. The lead itself. Submissions that pass the filter are delivered to your destination and are not retained by us — the queue holds what was blocked.

The part that is unusual

The record sits in our store, but it is encrypted before it gets there — with a public key you generate. Its private key is stored only locked under your password, which never reaches us. So the copy we hold is ciphertext: we cannot open it, and neither can anyone who compels us or breaches us. It is decrypted in your own browser, when you enter your password to open the queue.

This works identically however your forms are protected — the SpamKill form builder, the WordPress plugin, or the form converter. There is no third-party logging account to buy and nothing to connect: the store is built in, and the encryption is what keeps it yours rather than the hosting arrangement.

Layer three: review, flag, recover

A stored record makes the lead recoverable in principle. Blocked Lead Review makes it recoverable in practice: a dedicated interface that decrypts the queue in your browser and presents it one decision at a time — who it was, what they submitted, and why it was blocked.

When you spot a real lead in there, you recover it: everything they submitted is in front of you — the fields, the UTMs and the hidden fields — ready to follow up or add to your CRM. Marking it as a false positive teaches the model, and confirming a bot tightens the filter, so your feedback sharpens future judgement on your traffic. The lead is not lost; it was delayed.

Why "we cannot read it" is the load-bearing part

It would have been easier to build this the usual way: keep a readable copy of every submission on our side and show it back to you in a dashboard. Most tools do. The trouble is what that architecture means for you:

Vendor can read your leadsSpamKill holds ciphertext
Who can read the contentsThe vendor's staff and systemsOnly you, in your own browser
Who holds the keyThe vendorYou — we never receive it
What a subpoena to the vendor yieldsReadable leadsCiphertext
If the vendor's database is breachedYour leads are exposedEncrypted blobs
Where decryption happensThe vendor's serversYour device

A form protection product necessarily sees your leads for the milliseconds it takes to judge them. What it does not need is the ability to read them again afterwards. Encrypting to a key we never hold removes that ability by construction rather than by policy — which is the difference between a promise and a property.

What you need

  1. A plan with the Advanced Intelligence pack — Submission Logging and Blocked Lead Review are available on the Professional plan and above.
  2. Your encryption key, generated once — you create it in your browser when you turn the queue on. We keep the public half to seal leads, and the private half only locked under the password you set, which never reaches us. That password unlocks it in your browser afterwards.
  3. Nothing else — no third-party logging subscription and no connector to configure. Recovery only reaches back as far as the queue does, so this is worth switching on before you need it, not after. The console reports block reasons, country breakdowns and challenge results either way — see the reporting overview.
Where SpamKill fits

SpamKill blocks automated submissions at 99.9% accuracy for 1,500+ businesses — and treats the residual error honestly instead of pretending it away. A flagged real person verifies through in one step; the ones who don't are sitting in an encrypted queue that only you can open, reviewable and recoverable, with the copy we hold unreadable to us. See Blocked Lead Review and Submission Logging for the feature details, or how the guarantee leans on that queue. From $29/month with a 30-day free trial, no credit card.

Frequently asked questions

What is the difference between Blocked Lead Review and Submission Logging?

Blocked Lead Review keeps the blocked submissions in the encrypted queue, which is what you need to rescue a wrongly blocked lead. Submission Logging adds fuller visibility into your form activity alongside it. Both are in the Advanced Intelligence pack, on the Professional plan and above.

Does SpamKill see or store my lead data?

SpamKill sees a submission in flight, for as long as it takes to judge it. What is stored afterwards is encrypted before it reaches our store, using a public key you generate — and the matching private key is stored only locked under your password, which never reaches us. So we hold your leads as ciphertext we cannot open. We cannot read them, search them, or hand their contents to anyone, including in response to a subpoena, which we would refer to you. They are decrypted in your own browser, when you enter your password to open the queue.

Do I need any external account or tooling for this?

No. The encrypted store is ours and the review interface is built in — there is no third-party logging subscription to buy and nothing to connect. The console also reports block reasons, country breakdowns and challenge results without you opening the queue at all.

How do I get a wrongly blocked lead into my CRM?

Open it in Blocked Lead Review, which shows the full submission and the exact reason it was blocked. Recover it: everything the person submitted is there, UTMs and hidden fields included, ready to follow up or add to your CRM. Marking it as a false positive teaches the model; confirming a bot tightens the filter. The lead is not lost; it was delayed.

How often does a real lead actually get blocked?

SpamKill screens at 99.9% accuracy, and most of the residual error never becomes a lost lead: a flagged real person is offered a one-step verification and comes through on their own. The blocked-and-unverified case — someone flagged who did not or could not complete the step — is rare, which is exactly why it deserves a recovery path rather than a shrug.

See the judgement layer in action

Paste your form HTML into the Form Transformer and get the protected version back — no signup, no card, nothing to install.

Open the Form Transformer