Infrastructure
Comment Spam: The Case for Closing Your Business Website's Comments

Turn off the comments on your business website. I know that sounds blunt coming from the person whose job is keeping sites healthy and online, but I will stand behind it. For the overwhelming majority of Irish business sites, an open comments section is not engagement. It is an open door that only automated software ever walks through.
Let me explain how I landed here, after years of watching what actually turns up in those comment queues.
The comment box was never really for your customers
Your customers ring you. They email, fill in the contact form, or message you on WhatsApp. Almost nobody who wants to book a physio or hire a plumber leaves a public comment under a blog post to do it. The box just sits there, empty of anything human, and automated software finds it within days of a new site going live.
It is hard to overstate the scale. Akismet, the anti-spam service built into a large share of WordPress sites, reports having blocked over 500 billion pieces of spam across more than 100 million websites, and on a normal day it filters tens of millions of spam comments [3]. Those are the vendor's own figures and the exact count moves constantly, so treat them as an order of magnitude rather than a precise reading. The point stands either way. Spam is not a trickle that occasionally reaches you. It is a firehose, aimed at every site with an open form.
What that open box is actually doing to you
An empty-looking comments section feels harmless. It is not, and the damage is quiet, which is exactly what makes it worth taking seriously.
Start with what your customers see. A comment left unmoderated appears on your live site, in public, whether you have logged in that fortnight or not. Consider a Cavan physiotherapy clinic that wrote a genuinely useful post about recovering from a knee operation. Underneath it sits a comment linking to a counterfeit-medication shop, because a bot decided that page was a good spot to advertise. Every prospective patient who reads that article now sees the clinic apparently vouching for a dodgy pharmacy. That is reputation damage doing its work silently, days before anyone on the inside notices.

Now think about what Google sees. When your site publishes a comment containing a link, you are, in search terms, vouching for that link unless it is marked correctly. Google introduced the rel="ugc" attribute back in 2019 precisely so that links inside user-generated content like comments are read as hints rather than endorsements [2]. Well-run comment systems apply that automatically. A neglected one can end up passing signals to malware and scam domains, which is not an association any business wants stapled to its name in the search results.
And there is the cost that never shows on the page. Every spam comment, approved or not, is a row written to your database. Multiply that by the firehose above and a small brochure site quietly accumulates tens of thousands of junk records, bloating the database, slowing the admin area, and padding every backup with rubbish. I have seen a neglected site carrying more spam comments in its database than it had real pages of content. Nobody noticed until a routine restore took far longer than it should have.
Sometimes comments genuinely earn their place
I am not going to pretend the answer is always to switch them off. That would fail my own honesty test.
If you run an active community blog, a membership site, or a publication where readers genuinely talk to each other and you have someone moderating daily, comments are an asset worth defending. A busy recipe site or a local news outlet lives on that back-and-forth, and turning it off would gut the thing that makes it work. If that is you, keep them, and resource the moderation properly.
But a plumber, an accountant, a clinic, a shop? The engagement you actually want happens in the inbox and on the phone, not in a public box beneath your posts.
If you keep them, run them like an operator
Say you have a real reason to keep comments open. Then run them deliberately instead of leaving the defaults in place. By default, WordPress lets anyone leave a comment without logging in, which is exactly the behaviour the bots rely on [1].
A handful of settings, all found under Settings then Discussion, change the game:
- Hold everything for approval. Turn on "Comment must be manually approved" so nothing appears publicly until you have verified it. Nothing goes live behind your back.
- Install a proper spam filter. A dedicated anti-spam service catches the overwhelming majority automatically, so you are reviewing a handful each week, not a thousand.
- Close comments on older posts. Set them to close after a couple of weeks. Most automated spam targets forgotten, ageing pages.
- Handle the delete-on-sight list with care. WordPress can bin matching comments instantly using the Disallowed Comment Keys list, but it deletes them without any notification, so a badly chosen keyword can quietly erase a genuine message too.
One honest limitation: no filter is perfect. The good ones advertise very high accuracy, but a determined spammer occasionally slips through, and every so often a real comment gets wrongly flagged and sits in the spam folder unseen. That is the trade. Manual approval plus a solid filter is not zero effort, but it is far less effort, and far less risk, than cleaning up after an open door. If you want the wider picture on locking a WordPress site down, our guide to WordPress security and backups shows where comment hygiene fits alongside everything else.
The protection you never see
Comment moderation is the layer you control. Underneath it should sit a layer you never have to think about.
On a properly managed platform, a great deal of automated abuse is stopped before it ever reaches your comment form: server-level filtering, intrusion prevention that blocks the addresses hammering your login and comment endpoints, and malware scanning that flags a malicious payload if one gets through. This is the kind of automated protection a managed platform runs while you sleep, and in practice it is the difference between a site that shrugs off the firehose and one that slowly drowns in it.
That is the thinking behind Web60's managed, server-level security. The platform absorbs the automated noise (fail2ban intrusion prevention and automatic malware scanning run as standard on Irish infrastructure, all inside the €60 a year) so a business owner spends their moderation time on the rare genuine comment, not the thousandth fake advert.
The decision is smaller than it looks
Strip away the fear of missing out on engagement and the choice gets simple. Look at your own comment queue this week. If it is nothing but spam and the odd lost tourist, you already have your answer, and closing the section costs you nothing you were actually using. When it is a living conversation, protect it, moderate it, and give it the attention it earns. Either way, that open box was never neutral. What belongs behind it is your call to make.
Sources
Ian oversees Web60's hosting infrastructure and operations. Responsible for the uptime, security, and performance of every site on the platform, he writes about the operational reality of keeping Irish business websites fast, secure, and online around the clock.
More by Ian O'Reilly →Ready to get your business online?
Describe your business. AI builds your website in 60 seconds.
Build My Website Free →More from the blog
A Fake Website Impersonating Your Business Can Be Online by Lunchtime
Scammers can clone your site, register a lookalike domain and add an SSL padlock in an afternoon. How Irish businesses spot the fakes and shut them down.
WordPress Just Patched a Critical Flaw. 'It Updates Itself' Is Not the Same as 'I Am Protected.'
A pre-authentication WordPress core flaw let anyone break in without a password. Here's what 'automatic updates' actually covers, and what still needs checking.
