There is one thing a script can’t fake convincingly: patience. A human reading a contact form, thinking about their message, and typing it out takes seconds. A bot that parses the HTML and posts the form can do it faster than you can blink.
That gap between human deliberation and machine speed is one of the most reliable, lowest-friction signals in form protection — and you can measure it without ever showing the user a challenge.
How submit-timing works
The mechanic is simple: record when the form is rendered, record when it is submitted, and look at the elapsed time.
- On page load, the form quietly stamps a start time (a token, a hidden timestamp, or a server-side session marker).
- When the submission arrives, you compare the submit time to the render time.
- If the delta is implausibly small — a full message composed and posted in 300 milliseconds — the submission is almost certainly automated.
Real users produce a natural distribution of fill times. Even a fast typist filling a short form needs a couple of seconds to read the labels and enter a message. Bots cluster at the impossible end of that distribution, and that cluster is easy to isolate.
Why timing beats a visible challenge
Submit-timing shares the honeypot’s greatest virtue: it is completely invisible. The user does nothing, sees nothing, and clicks nothing extra. There is no puzzle, no accessibility barrier, and no conversion penalty.
It also degrades gracefully. Where a CAPTCHA is either present or absent, timing produces a continuous signal you can weigh. A submission at 900 milliseconds is more suspicious than one at four seconds, which lets you make nuanced decisions rather than a hard yes/no.
The evasion arms race
Sophisticated bots know about timing checks and will deliberately wait before submitting to look human. This is why timing must never stand alone. A bot that inserts an artificial delay to defeat timing still has to:
- Avoid the invisible honeypot field it can’t see the purpose of.
- Produce message content that doesn’t read as link spam, keyword stuffing, or a foreign-script mismatch.
- Come from an IP and device that aren’t already flagged for abuse elsewhere.
Each additional signal multiplies the cost of a successful submission. A bot can fake one behavior; faking all of them simultaneously, at scale, across thousands of forms, is expensive enough to send the spammer looking for softer targets.
How Prynt layers timing into Form Shield
Prynt’s Form Shield treats submit-timing as one input among several. In a single cloud call it evaluates timing, checks the invisible honeypot, and runs content analysis — including Cyrillic and CJK script-mismatch detection — then enriches the verdict with server-side Smart Signals: is this a known bot, a VPN or proxy, a datacenter IP, a device with poor reputation on Prynt’s cross-site network?
Because Prynt assigns every visitor a stable visitorId, it can also spot a device that submits many forms in rapid succession — a pattern no honest user produces. The timing signal at the individual submission level and the velocity signal across submissions reinforce each other.
Implementing it well
A few practical guidelines keep timing accurate and fair:
- Anchor the start time server-side or in a signed token so a bot can’t simply forge an older timestamp to fake a slow fill.
- Set the threshold to your form. A long, multi-field application deserves a higher minimum than a two-field newsletter box.
- Watch the tails, not just the mean. The suspicious traffic lives in the impossibly-fast tail; focus your threshold there.
- Log before you block. Run in monitor mode first, confirm real users cluster well above your threshold, then enforce.
Done right, timing removes a large slice of automated spam before content or reputation checks even run, and it does so with zero cost to the humans you actually want.
Submit-timing is the quiet workhorse of CAPTCHA-free form protection: invisible, cheap, and brutally effective against the automation that floods contact forms every day. Start free on Prynt and try it on your forms via the pricing page.
Try it free
Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.