WordPress

Akismet

Akismet is the spam-filtering service that Automattic bundles as a plugin with every WordPress download. It sends each new comment, and optionally form submissions, to a remote API and gets back spam or not-spam.

How it is measured

The plugin is installed but inactive on a fresh site and needs an API key before it does anything. Once active, Comments > Spam holds the caught items, and Settings > Akismet shows a running count of caught spam plus a monthly chart. Caught spam is auto-deleted after a retention window unless you change that, so the count in the chart outlives the rows in the table.

To confirm it is working, post a test comment from a logged-out browser using the author name viagra-test-123, which Akismet's documentation uses for this purpose, and check that it lands in Spam. A comment that goes to Pending instead means the key is missing or the API call failed.

Worked example

A recipe blog with 40 posts and a closed-off contact page gets about 220 comment attempts a day. Akismet puts 214 in Spam. The 6 that reach Pending are two real readers and four hand-typed link drops that read like praise.

Last Thursday the host blocked outbound requests to rest.akismet.com after a firewall change. For two days zero comments were classified, and 190 spam comments sat in Pending until the site owner noticed the Akismet notice in wp-admin.

How it differs

Akismet judges content that people submit. Jetpack is a larger bundle from the same company that includes stats, backups, and security tools, and it can run Akismet-style protection as one piece. Akismet does not harden logins, scan files, or stop XML-RPC brute force, and Jetpack's other modules do not replace a configured Akismet key.

Common errors

Leaving the plugin active with no API key and assuming the sidebar says protected. Using a free personal key on a commercial site and losing the key. Never opening the Spam folder, so real comments from new readers get buried. Turning on Akismet but leaving comments open on year-old posts, which still attract most of the junk. Expecting it to filter WooCommerce reviews without checking the integration setting.

In practice

Open Comments > Spam and scan the last 50 for false positives, then mark anything legitimate as Not Spam so the service learns. Close comments on posts older than 30 days under Settings > Discussion. If you run a form plugin, check whether it has an Akismet toggle and turn it on.

See also

Jetpack, WordPress

Sources

Count this on a real site.

Watch my website