Skip to content
Discussion options

You must be logged in to vote

I think the only way to mitigate bots hammering the open subscription form with random signups is to turn CAPTCHA on in Settings -> Security. Even IP ratelimits in a proxy like Nginx in front of listmonk aren't effective because of the large pool of IPs used in attacks. It's unfortunate.

listmonk uses hCaptcha currently, but in the next version, I'm planning to incorporate a self-contained system.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@JamesChevalier
Comment options

@JamesChevalier
Comment options

Answer selected by JamesChevalier
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants