Spam is a big problem. It is extremely annoying, intrusive and unwanted. And sometimes it can undermine what you do, or even in the worst case, destroy it.
Google defines spam as “irrelevant or unsolicited messages sent over the Internet, typically to large numbers of users, for the purposes of advertising, phishing, spreading malware, etc.” We have all experienced spam in some way, from a tonne of unwanted comments to our blogs or email accounts being hacked to distribute porn and being blocked by Google (I’ve had spamming malware that was so clever it rejuvenated itself after it was deleted, so I had to close that blog down).
Why do spammers do this sort of thing? In the beginning is was probably technically clever programmers having a bit of fun, but now it has escalated to either increase backlinks from content placed around the web to improve page ranking within websites, or to make money using the old fashioned ‘spray and pray’ techniques: if enough stuff was spread as wide as possible within the Internet, some poor unwitting soul will ‘let it in’ so it could cause its mischief and havoc. There must be enough ‘successes’ for it to be financially viable, or it would have died down by now.
The answer is to be aware of spam and take preventative methods to check it before it can become a nuisance. There are many applications available that can help, but the first thing is to make sure you have a good ‘spam eater’ in place and that your blog is secure against hackers.
Activate your Akismet
WordPress uses Akismet as its main spam controller. WordPress.com blogs use it by default, and WordPress.org blogs have the Akismet plugin installed as standard, though it needs to be activated (via an API key) from a WordPress.com account. For a personal blog you can set the slider to zero if you don’t want to pay for your spam protection.
Akismet is brilliant at chewing up spam, and any unwanted comments can be eradicated overnight. I recommend you activate it immediately if you haven’t already done so. It works with an algorithm that uses a special database that enables it to ‘learn’ which comments are spam and which are legitimate.
This means if you mark an unwanted comment as spam, Akismet will take note and add that information to its database so it can recognise similar comments using the same content and from the same IP address (computer) and prevent it from bothering other blog users. Deleting the spam from your blog activates this memory system. Alternatively if you ‘trash’ a comment it will not be recognised as spam, so it depends on how ruthless you are feeling.
For the more technically advanced WordPress users there is a Spam Nuke plugin that can recover deleted comments marked as spam, and if Akismet isn’t good enough or you are bombarded by robot spam, you can resort to a CAPTCHA plugin which only allows humans to leave a comment.
Manage your moderation
In last month’s how-to post I talked about comments and how to moderate them. It’s worth popping back to refresh your memory and make sure your comment moderation is set up correctly. In this comment post from my blog I explain in more detail about white- and black-listing comments to help counteract spam, especially if you have prior knowledge of who is bothering you.
How secure is your login?
If you have a WordPress.com blog you will have created your own username (which acts for all the blogs you have that are created within WordPress.com) and a suitable password (WordPress gives excellent hints as to the strength of passwords) when you signed up.
But for WordPress.org blogs or websites this is not the case. You should not use the generic username ‘admin’ that is offered by some hosting companies by default. Before you finalise your uploading of WordPress there should have been an additional option that allows you to choose your username and password. Take advantage by entering in an example that only you will remember and nobody else can guess.
Leaving your username as ‘admin’ is like waving a red flag to a hacker. They will use this in the username field and then put in place automated systems to try and work out your password. This is because it’s very easy to find the WordPress login menu (just type in /wp-login.php after the blog’s URL or web address to bring it up), and I use this to see if a website is created using WordPress or not. This means you need to have secure login details to keep your blog or website safe.
If you do have ‘admin’ as your username (go to Users in your Dashboard left hand sidebar) you can easily change it. Click on ‘Add New’ and create a new user for yourself with a secure username and password, but you need to use another email address. Then log out and log in as the new user, and go to Users again. Now you can delete the old ‘admin’ user and transfer over all your posts and content to you as the new user (WordPress will request this). Then you can update your User Profile back to the original email address if you want to.
There are plugins, such as ‘Limit Login Attempts’, that can prevent a hacker from trying to access your website. This one allows just four attempts before blocking logging in for as long as you like (I’ve chosen 1000 minutes, which is almost a day). You also get email notification whenever anyone has tried and failed to login in, including which username they tried and their IP address if you want to report them. But this also means you need to be careful when logging in yourself, or you might be blocked too!
When did you last update?
And finally another way is to regularly update your blog or website. WordPress is constantly working hard to beat the system and defy those pesky spammers and hackers who are so determined to destroy your world.
If you use WordPress.org, go to your Dashboard and under Dashboard in the left sidebar there should be the link to Updates. There you will see what needs updating: WordPress, themes and plugins, and the ability to do so.
But beware, even if you have a lot of faith in your hosting provider, remember to back up your website beforehand just in case anything goes wrong! Then you can restore your website and try again.
And if you have a WordPress.com blog, you don’t need to worry about updating or backing up as this is automatically done for you!
About Alice Elliott
Alice Elliott, aka Fairy Blog Mother, is an award winning blogging consultant who has been looking after bloggers since 2006! Woah, that's a long time! She specialises in "explaining things really simply" about WordPress, and has twice been noted as a top WordPress influencer for 2019.



Tom @Ideas4Dads
Thursday 6th of March 2014
I was having terrible problems with spam u til I installed akismet and its been brilliant. Couldnt recommend it highly enough :-)
Alice Elliott
Thursday 6th of March 2014
Yes, Tom, it's an amazing application. It's a shame people forget to activate it. One particular blogger I came across was receiving 100s of comments every day, and he thought they were all legitimate and was publishing them, as he didn't realise they were spam. Goodness knows what they were doing to his blog's reputation!