Last Updated: November 18th, 2017 by Dan Astriden

How to stop Salesforce® web to lead spam and why you are getting spam using web to lead website forms

This article will describe why you are receiving Salesforce spam and how to stop it. The first thing to check is the source code of the web page where you have a web form that goes to Salesforce. If you have a hidden field named “OID”, this is the source of the problem. Spammers now have your Salesforce account number and can send spam directly to Salesforce. Even if you remove the website form you will still receive spam in your Salesforce account. Salesforce will not issue a new OID number for your account. To avoid this issue in the future, you can remove the hidden field with the OID number and pass it in server side coding before sending the information to Salesforce. This can be done in any scripting language such as PHP. To stop the spam that is currently going to your Salesforce account you can setup Lead Validation Rules within Salesforce that will check input data and flag anything with specific words or characters.

Diagram of how to stop spam going to your Salesforce account

Web to lead form example that can cause spam to enter Salesforce database.

<form action="" method="POST">  
<input type=hidden name="oid" value="0hxx0TRgyZ0xxxx">  
<input type=hidden name="retURL" value="">

Salesforce validation rule example.

The following rule would stop any submission with FieldName containing the words “bad word” or if the length of the FieldName is greater than 20 characters.

ISPICKVAL(FieldName,”bad word”)),
  LEN(FieldName) > 20)

If your OID isn’t in the HTML source code and you are still receiving spam, there are many methods to prevent the spam without using a spam filter. You will need some programming added to your form processing application. Captcha isn’t recommended since it’s annoying for most users and many of the open source plugins don’t effectively stop spam.

Hint. Many posts on the web suggest to use CSS to hide a form field on the website form and kill the form processing script if text is detected in this field. This is no longer effective against spam and a better method is to use javascript or jquery to add / remove / modify form content before the form is submitted and then check in the form processing script to make sure the content matches.

So, why are you receiving spam in the first place? It’s a good idea to check the mail logs on the server to make sure you don’t have insecure code and are victim of email injection. If this is the case, your server could be sending spam to other people.


Need Help? Get your problem solved today. I will either fix your issues or refer you to a certified Salesforce consultant. For a limited time I’m offering a free website audit. If you have this issue with you website just imagine what other issues I’ll find. Everyone is always shocked by what I uncover.



About the Author

Avatar for Dan Astriden

Dan Astriden Web Developer

Hello. I'm a senior web developer located in the Bay Area, California. I've been managing the web properties of several Silicon Valley tech companies for many years and have a strong background in web development, digital marketing and search engine optimization. Contact me for a free consultation and see how I can improve your business. Protection Status