Why Some of Your Leads Are Fake (And How Verification Fixes It)
Every form has a spam problem — bots, throwaway emails, one person padding a raffle entry five times. Here's how Keepp's built-in verification, a one-time code or one-click Google sign-in, filters them out before they reach your inbox.
By Keepp Team
Not every submission in your leads inbox is a real person. A bot fills in a fake address because the form was public and it could. Someone enters a made-up email five times to get five raffle entries instead of one. A competitor scrapes your form just to see what you’re asking. None of that shows up as spam in an obvious way — it just sits in your data next to the real leads, quietly making your list noisier and your feedback averages wrong.
A form block on Keepp can close that gap with a verification step: before a submission counts, the person confirms they actually control the email address they typed in. This post covers how that works — the two ways to verify, what happens when someone doesn’t finish it, and how it compares to what other form tools do about the same problem.
Two ways to verify, not just one
When you turn on verification for an email field, a visitor has two options to confirm it’s really them:
- A one-time code — a 6-digit code sent to the address they entered, which they type back into the form. It expires after 10 minutes and allows up to 5 attempts, so a wrong digit doesn’t lock someone out of their own submission.
- Continue with Google — a one-click sign-in that verifies the address instantly, no code to check email for and copy back. This is the lower-friction option, and it’s what most people reach for when they’re filling out a form on their phone and don’t want to switch apps to find a code. It shows up whenever a form has exactly one field that needs verifying — the common case for a lead or feedback form with a single email field.
Both roads end at the same guarantee: a verified submission is tied to an inbox someone actually controls, not a string of characters that happened to be shaped like an email address. Which one a visitor uses is their choice — you’re not picking a single verification method for the whole form, you’re offering both and letting whichever is more convenient for that person win.
An unverified submission isn’t thrown away
If someone starts verification and doesn’t finish it — they close the tab before entering the code, or never click through the Google prompt — the submission isn’t lost. It’s still saved in your Data view, just marked unverified instead of dropped. You can see it, filter by verification status, and decide for yourself whether an unverified lead is still worth following up on. Nothing forces a choice between “verify or nothing” — you get the full list either way, with a clear label on which entries you can trust as confirmed and which ones you can’t.
That matters most for anything you’re counting rather than just reading. A feedback average, a raffle entry, an RSVP headcount — those need the unverified noise separated out, not silently discarded, in case you want to double-check the raw numbers later.
Why it’s a switch, not a default
Verification is a per-field toggle you turn on when a submission needs to be trustworthy, not something every form does automatically. A low-stakes “notify me when it’s back in stock” lead form is usually better off without it — the extra step costs you a few completions for a list where a bit of noise doesn’t really matter. Turn it on for anything where the count matters: a feedback score you’re going to average, an RSVP you’re going to cap, a giveaway entry, a request you want to know is real before you spend time on it. Collecting leads and feedback from your page covers the rest of the form block — presets, custom questions, where submissions land — if you haven’t set one up yet.
How other form tools handle this
Most tools in this space either don’t verify email submissions at all, or verify something that isn’t quite the email field itself:
| Keepp | Typeform | Google Forms | Beacons | |
|---|---|---|---|---|
| Email verification on submission | Yes — one-time code or Google sign-in | No native option | ”Verified” toggle exists | No |
| What it actually confirms | The person controls that exact email address | Nothing, without a third-party add-on | The respondent is signed into some Google account | Not applicable — no verification step |
| Works on a freeform email field | Yes | Not applicable | No — only the built-in “collect email” setting | Not applicable |
| Unverified submissions kept, labeled? | Yes, filterable in the Data view | Not applicable | Not applicable | Not applicable |
Typeform has no built-in way to verify an email at submission time — it’s one of the more requested features in their own community forum, and the workarounds people use today are third-party spam-checking integrations bolted on after the fact. Google Forms’ “Verified” option sounds like the same thing, but it only confirms the respondent was logged into a Google account when they answered — it doesn’t check whatever address they typed into a regular email field, and a second Google account gets around it just as easily as a fake email would anywhere else. Beacons, which bundles a store, link-in-bio, and email marketing the same way Keepp bundles a store, bookings, and forms, handles spam through account policy rather than a submission-time check — there’s no verification step for someone filling out a lead form.
If you’ve been burned by a padded raffle, a feedback score you didn’t trust, or a leads list you weren’t sure was real, that’s usually why — the tool didn’t have a way to check.
What this actually protects against
- Bots filling in forms with generated or scraped addresses, because there’s no cost to submitting garbage.
- One person, many entries — the same visitor submitting a raffle or feedback form repeatedly under different made-up addresses to pad a count.
- A dead-end lead list — a “verified” badge on a submission means you know, before you spend time following up, that a reply will actually reach someone.
None of this requires a separate tool. It’s the same Data view you already check for every form on your page, with one more column telling you which rows you can trust.
Common questions
Does verification slow down every form? No — it’s off by default and only applies to fields you specifically turn it on for. A form with no verified fields works exactly as fast as it always has.
What if someone doesn’t have a Google account? The one-time code option is always there too — verification never requires Google specifically, it’s just the faster of the two paths when it applies.
Can I see which leads are unverified after the fact? Yes — the Data view filters by verification status, so you can work through verified submissions first and decide separately what to do with the rest.
Add a form with verification to your keepp.link page — free to start. See pricing for the full plan breakdown.