Stopping Spam Signups on a Ghost Site
What spam signups do to a Ghost site, what Ghost already blocks on its own, and what to add in front of it. We tested the built-in limit on our own site.
Quick answer: Spam signups use your site to send email. Ghost already blocks the crude versions. A hidden field catches simple bots, one visitor address gets eight attempts in twelve hours, and you can block email domains under Settings → Membership → Spam filters. What gets through comes from many addresses at once. A rate limit on the signup path, at Cloudflare or your web server, handles that. If you do not need open signups, invite-only mode ends the problem outright.
Your member list has started growing with addresses you do not recognise. Some never confirm. Some do, and later leave comment spam. Your host may have written about complaints. This is one of the most common problems a Ghost site runs into once it is a few months old. Among self-hosters it has been one of the most discussed topics of the past year.
This guide explains what the spam is for, what Ghost does about it without any setup, and what to add when that is not enough. We read Ghost’s own protection code and tested its limit on one of our own sites in September 2026. Our recommendation is at the end, and it depends on one question: whether you need open signups at all.
What spam signups are for
A Ghost signup form does not create an account. It asks Ghost to send a sign-in link to the address entered, and the account exists only after that link is clicked. So the form is, to a bot, a way to make your site email anyone. Two kinds of abuse follow.
The first uses your site as a mail cannon. The bot submits addresses it wants to reach, and your site sends each one a message with your name on it. The recipients did not ask for it. Some mark it as spam, and every such mark counts against your domain and your sending service, until your real newsletters start landing in spam folders too.
The second wants the account. A bot with a real inbox confirms the link and becomes a member, usually to leave comment spam or to hold accounts for later. This is the version that shows up as strange names in your member list, often from real company domains, a handful a day.
The scale can be large. Site owners have publicly reported signup traffic of more than a million requests a day from Tor exit nodes and rented servers, which is why the defences are layered rather than one switch.
What Ghost already does
Ghost’s signup endpoint has four defences built in. We read them in Ghost’s source, and the limits below are its defaults.
A hidden field that only bots fill. Ghost’s signup form includes a field a person never sees. If a request arrives with it filled in, Ghost answers as if everything worked and sends nothing. Simple form-filling bots fall for this and never know.
A limit per visitor address. One visitor address may request sign-in links for eight different email addresses within twelve hours. The ninth is refused, and the wait grows with each further attempt. We tested this on one of our own sites. Eight requests went through to the next check, and the ninth came back with “Too many different sign-in attempts, try again in 10 minutes”. A separate limit covers repeated requests for the same address.
A token the real form fetches first. Before Ghost’s signup form submits, it asks the site for a short-lived token and sends it along. A script that posts to the endpoint directly does not have one. By default Ghost only logs the missing token; a self-hoster can make it a hard refusal, which the technical note below covers.
Blocked email domains. Under Settings → Membership → Spam filters you list domains, one per line, and any signup from those domains is refused with a message saying so. Ghost’s help page covers the setting, and adds that Ghost(Pro) watches for abuse patterns across its whole network and blocks them for every site it hosts.
These four stop the crude bots. What they do not stop is the pattern that actually reaches most sites: many addresses, each staying under the limit, some of them real browsers with real inboxes. For that you add something in front of Ghost.
What to add in front
A rate limit on the signup path. The signup requests all go to one path, /members/api/send-magic-link/. A rule that limits how often one address may hit that path stops bursts without touching anyone reading the site. Cloudflare’s free plan includes one rate limiting rule, matched on path and counted over ten seconds. A rule that blocks an address after a handful of signup requests in ten seconds is enough, because a person never makes more than one. On your own web server, nginx has request limiting built in, Caddy needs its rate-limit module added when Caddy is built, and in both the same path is the thing to limit.
A challenge for Tor visitors, on pages only. A large share of the reported spam arrives through Tor exit nodes, which Cloudflare labels with the country code T1. A custom rule that challenges visitors from T1 on your pages cuts most of it off before they reach the form. Block rather than challenge only if you have decided your site has no Tor readers; there are legitimate ones.
Never challenge the signup path itself. Ghost’s signup form submits in the background, from a script, and a script cannot solve a challenge. A managed challenge on the API path makes signups fail for everyone. Rate limits block, they do not ask questions, so they are safe on the path; challenges belong on page views.
Invite-only, if you can. Under Settings → Membership → Access, set signups to invite only or paid only. Ghost then refuses every free signup request with a plain message and sends nothing at all. The two of our own sites we tried run this way, and both answer every signup request with “This site is invite-only, contact the owner for access”. It is the only defence that is complete, and for a site that does not need open signups it is the right one.
For the technical reader, two more knobs exist on a self-hosted site. Setting verifyRequestIntegrity to true in the config makes Ghost refuse any signup request that arrives without the token its own form fetches, which turns the logged warning into a real block. Test any custom signup form you run after enabling it, because a form that posts directly to the endpoint will stop working. A second approach self-hosters share adds a custom header to the form’s request through code injection and rejects requests without it at the web server. It stops scripts that post directly, and not headless browsers.
Cleaning up what already got in
Members created by spam are ordinary members, and Ghost’s member list has the tools to remove them. Filter by creation date to find the wave, search for the domain if one dominates, or filter by a label you attached when importing them, if that is how they arrived. The … menu on a filtered list can delete every member it shows, and Ghost downloads a backup of them before it does.
Two checks help decide what is spam. A member who never opened anything and joined in a burst with others is spam. A member from a company domain who joined alone might be a real reader who signed up from work. The safe move is to leave those and watch the comments instead.
While you clean up, add the worst domains to the spam filter. If your sending service shows a rising complaint rate, pause newsletters to new free members until the list is clean.
When this is not your problem
A few things look like spam signups and are not. Security software at a recipient’s company sometimes opens every link in an email, including your sign-in link, which creates a member that no person asked for. A single unexpected member from a real domain, with no burst around it, is more likely that than a bot. And if members appear without any sign-in email being sent, someone has your Admin API key, which is a different and more serious problem. Regenerate the key, or delete the integration, under Settings → Integrations first.
Where this leaves you
You know what the spam is for and which layer stops which kind. Ghost’s own four defences run on every site; a rate limit on the signup path, and a challenge for Tor visitors on pages, handle the rest; invite-only ends it. If you are tuning how members sign up in the first place, the Portal guide covers the signup window, and the membership setup guide covers tiers and access.
Frequently Asked Questions
Why is my Ghost site getting spam signups?
Does Ghost have built-in spam protection for signups?
How do I add a captcha to Ghost signups?
How do I stop signups completely on Ghost?
Keep reading
Ghost as a Publishing Platform: Full Overview
Ghost combines a CMS, newsletter system, and membership platform into one. Here is what makes it different from WordPress, Substack, and website builders.
Why Ghost Asks Subscribers to Confirm by Email
Ghost makes every new subscriber click a link before they exist on your list, and never shows the ones who did not. Why that is, and how to lose fewer of them.
Ghost Editor: Cards, Formatting & Publishing
How the Ghost editor works: formatting, the card menu for images, galleries, embeds and callouts, and how to preview, schedule and publish a post or newsletter.
Ghost Memberships: Set Up Free and Paid Tiers
How Ghost memberships work and how to set them up: free and paid tiers, connecting Stripe, gating posts and managing members. Ghost takes no cut of revenue.
Recommended Themes
Themes with at least one of the features this guide touches: membership pages and newsletter integration.
Tribune
Strongest hereTribune is the front page of a newspaper. Lead stories beside the day's picture, a Featured list at the edge, then your sections by topic, each in its own layout, under a masthead that folds away as the reader scrolls. Built for newspapers and multi-author magazines that publish several stories a day, and managed entirely from Ghost admin.
Luno
Strongest hereLuno is a blog that works like an app. A menu that stays open in a fixed sidebar, search a keystroke away, a light and dark switch beside your logo, and a homepage that opens with three featured stories as cover cards. Built for travel, lifestyle and product blogs whose readers expect an interface they already know, and managed entirely from Ghost admin.
Comparing options? Browse all premium Ghost themes side by side.
Get every theme in one bundle
The complete Luxe Themes bundle: every theme, one purchase.