Authyo | OTP

How to add otp verification to contact form 7

📂 Authyo  •  🗓 August 24, 2026  •  👁 142 Views

Table of Contents

Complete Guide 2026

How to Add OTP Verification to Contact Form 7 in WordPress

Secure every form submission with real-time Email, SMS, WhatsApp & Voice Call OTP verification — featuring the Authyo OTP plugin for CF7.

By Authyo Team · WordPress Security · Plugin Guide

If you run a WordPress website and use Contact Form 7, you already know how powerful it is for collecting leads, inquiries, and user information. But there's a persistent problem that almost every site owner faces sooner or later: spam submissions, fake entries, and unverified contact details flooding your inbox.so get ready to how our authyo OTP verification for Contact Form 7 integration works.

Standard CAPTCHA solutions slow users down and frustrate legitimate visitors. Email validation links require extra steps. And basic honeypot techniques are increasingly easy to bypass.

What if you could verify every form submission with a real-time, one-time password — delivered directly to the user's email address or phone — before the form is even submitted?

That's exactly what Authyo OTP for Contact Form 7 does. In this comprehensive guide, we'll walk you through everything you need to know — what it does, how it works, how to install and configure it, what shortcodes to use, and why it's one of the most complete OTP verification solutions available for WordPress today.

What Is Authyo OTP for Contact Form 7?

Authyo OTP for Contact Form 7 is a WordPress plugin that integrates real-time OTP (One-Time Password) verification directly into Contact Form 7 forms. Built and maintained by the Authyo team, it connects your forms to the Authyo verification API — a cloud-based service that delivers one-time codes via email, SMS, WhatsApp, and Voice Call.

When a visitor fills out a form on your website, they must first verify their email address or phone number by entering a short OTP code before the form can be submitted. This single step eliminates bot spam, ensures all contact details are real and reachable, and significantly improves the quality of every lead your forms generate.

The plugin goes far beyond a simple OTP widget. It includes a built-in leads database, a Google Sheets integration, WhatsApp admin notifications, an advanced phone number validator, a country code dropdown, GDPR tools, and more — making it a complete form security and lead management suite built on top of Contact Form 7.

Authyo OTP admin panel inside WordPress
The Authyo OTP admin panel — manage all settings, forms, and leads from one place inside WordPress.

Why Add OTP Verification to Your WordPress Forms?

The Problem with Unverified Form Submissions

Contact Form 7 is installed on tens of millions of WordPress websites. Its popularity makes it a massive target for spam bots, which submit forms with fake names, throwaway email addresses, and random phone numbers. Even with CAPTCHA enabled, you still end up with:

  • Low-quality leads — contacts who typed their email wrong or used a fake one.
  • Wasted sales effort — your team chases numbers and email addresses that don't exist.
  • Bot spam — automated submissions flooding your inbox and CRM.
  • False analytics — inflated form submission numbers that don't reflect real interest.

What OTP Verification Solves

When a user must enter an OTP code delivered to their actual email inbox or phone, you get real-time proof of ownership. They cannot proceed unless they have access to the email address or phone number they entered. This means:

  • Every email address in your leads list is confirmed deliverable.
  • Every phone number is confirmed reachable.
  • Bots and spam scripts cannot pass verification — they cannot receive OTP codes.
  • Your lead quality improves dramatically — every submission is from a real, reachable person.
  • Your sales and marketing teams spend time on genuine prospects.

OTP verification is already standard practice in banking, fintech, e-commerce, and SaaS — and it's now accessible to every WordPress site through this plugin.

Key Features at a Glance

Before diving deep, here's a quick overview of what Authyo OTP for Contact Form 7 includes:

📧
4 OTP Delivery Channels
Email, SMS, WhatsApp, and Voice Call — enable any combination.
Dual Verification
Verify both email and phone in a single form simultaneously.
🔄
Smart Fallback
Auto-show alternative delivery options when primary channel is slow.
🌍
Country Code Dropdown
Built-in, searchable country selector — all countries, selected, or single.
📱
Advanced Phone Validation
libphonenumber integration for real-time client-side number checking.
📊
Built-in Leads Manager
All verified submissions saved with filters, CSV export, and bulk actions.
📋
Google Sheets Integration
Push form data directly to a Google spreadsheet per form.
💬
WhatsApp Admin Alerts
Receive instant WhatsApp notification every time a form is verified.
🔒
AES-256-CBC Encryption
API credentials encrypted using your WordPress site's unique salts.
🛡️
Rate Limiting
Server-side protection against OTP abuse and brute-force attacks.
⚖️
GDPR Tools
Privacy policy content, personal data eraser, and consent management.
Cache-Plugin Compatible
Auto DONOTCACHEPAGE on forms — works with WP Rocket, LiteSpeed, and more.

Deep Dive: Every Feature Explained

1. Multiple OTP Delivery Channels

📧 Email OTP 📱 SMS OTP 💬 WhatsApp OTP 📞 Voice Call OTP

Authyo OTP supports four distinct channels for delivering one-time passwords. As an admin, you can enable any combination and configure which one is the primary method for phone-based forms.

  • Email OTP — The OTP code is sent to the email address the user entered in the form. Ideal for email capture forms, newsletter signups, and contact forms.
  • SMS OTP — The OTP is sent as a text message to the user's phone number. SMS delivery is fast, works on any mobile phone (no internet required), and has extremely high open rates.
  • WhatsApp OTP — Particularly effective in regions where WhatsApp is the dominant messaging platform (India, Brazil, Southeast Asia, Middle East, Africa).
  • Voice Call OTP — Authyo calls the user's phone number and reads the OTP code aloud. The most accessible option for users who have difficulty reading texts.

2. Dual Verification — Email and Phone in One Form

Most OTP plugins force you to choose: email or phone. Authyo OTP for Contact Form 7 supports both simultaneously within a single form using separate shortcodes —

and
. The plugin's submission guard will require both to be verified before allowing the form to be submitted.

3. Smart Fallback Method

When a user doesn't receive an OTP via the primary channel, the plugin displays a fallback method selector after a configurable timer expires. The user can then trigger the OTP again via a different channel — for example, switching from SMS to WhatsApp, or from WhatsApp to a Voice Call. This dramatically reduces friction and improves form completion rates.

4. Visitor Method Choice

If you enable the Allow Visitor Method Choice setting, users are presented with a method selector at the start of the OTP flow — letting them choose their preferred delivery channel before clicking "Send OTP." This respects user preference and increases the likelihood of successful OTP delivery.

5. Country Code Dropdown with Phone Validation

For phone-based OTP, the plugin renders a searchable, scrollable country code dropdown. Country display modes:

  • All countries — Show the full global list, suitable for international forms.
  • Selected countries only — Restrict to a specific subset of countries.
  • Single country — Lock the form to one country, hiding the dropdown entirely.

Country data is fetched from the Authyo API and cached locally for 7 days — no API call overhead on every page load.

6. Advanced Phone Validation (libphonenumber)

When enabled, the plugin loads the industry-standard libphonenumber library (the same library used by Google) in the browser. This enables real-time phone number validation that detects invalid formats, warns users about incorrect digit counts, and identifies potential landline numbers — reducing failed OTP sends caused by user input errors.

7. Built-in Leads Manager

Authyo OTP Leads Manager showing verified form submissions
The Leads Manager — a complete database of every verified form submission, with filters, CSV export, and bulk actions.

Every successful form submission is automatically saved to a dedicated database table (wp_authyo_leads). The Leads Manager displays:

  • Form name and ID, submitted data, and verification status (Verified / Skipped / Unverified).
  • Verification channel and WhatsApp notification status.
  • Date and time of submission.
  • Filter by status, form, or date range.
  • Export to CSV for use in Excel, Google Sheets, or any CRM.
  • Bulk delete selected leads.

8. Google Sheets Integration

Connect a Google Apps Script web app URL and map CF7 form fields to columns in your Google Sheet. Every verified submission automatically pushes data to your specified sheet — in real time. Per-form mappings mean you can send different forms to different sheets with customized column layouts.

9. WhatsApp Admin Notifications

WhatsApp notification received on phone showing form submission details
Instant WhatsApp alerts for every verified form submission — know the moment a new lead comes in, even on the go.

Beyond sending OTPs to users, the plugin can send a WhatsApp notification to the admin every time a form is verified and submitted. The notification uses a pre-approved Authyo template and automatically includes a human-readable summary of all form fields:

"Name: Jane Smith | Email: jane@example.com | Message: I'd like to request a quote..."

The plugin intelligently skips internal plugin fields, file upload fields, and handles checkbox groups as comma-separated lists. Textarea values are trimmed at 500 characters; the total message is capped at 1,000 characters.

10. Rate Limiting and Anti-Abuse Protection

Server-side rate limiting prevents abuse of the OTP send and verify endpoints:

  • Send OTP: Maximum 5 sends per 10-minute window, scoped to IP, form ID, and target.
  • Verify OTP: Maximum 8 verification attempts per 10-minute window.
  • Resend cooldown: Configurable timer (default 30 seconds) prevents hammering the Resend button.

11. GDPR and Privacy Compliance

The plugin automatically adds a privacy policy section to the WordPress Privacy Policy editor and registers a personal data eraser with WordPress's built-in Tools → Erase Personal Data tool — so GDPR erasure requests are handled automatically. Only real user-submitted data is stored; all internal plugin tokens and hidden fields are stripped.

12. Encrypted Credential Storage

Your Authyo API credentials are encrypted using AES-256-CBC encryption with keys derived from your WordPress site's unique secret salts before being stored in the database. They are decrypted only when needed for API calls and are never exposed in plaintext once saved.

13. Caching Plugin Compatibility

The plugin automatically sets the DONOTCACHEPAGE constant whenever it renders an OTP widget, ensuring pages with OTP forms are excluded from caching by WP Super Cache, W3 Total Cache, WP Rocket, LiteSpeed Cache, and more — no manual configuration required.

How to Install Authyo OTP for Contact Form 7

Prerequisites

  • Contact Form 7 installed and activated on your WordPress site.
  • An active Authyo account at authyo.io with a configured application.
  • WordPress running PHP 7.4 or later.

Via the WordPress Plugin Repository (Recommended)

  1. Log in to your WordPress admin dashboard.
  2. Go to Plugins → Add New.
  3. In the search box, type "Authyo OTP for Contact Form 7".
  4. Find the plugin in the results and click Install Now.
  5. Once installed, click Activate.

After activation, you'll see a new "Authyo OTP for CF7" menu item in your WordPress admin sidebar. A guided tour will also launch to walk you through initial setup.

Step-by-Step Configuration Guide

Step 1: Create Your Authyo Account and Application

  1. Visit authyo.io and sign up for a free account.
  2. Once logged in, create a new Application in your Authyo dashboard.
  3. Note down your App ID, Client ID, and Client Secret.

Step 2: Enter API Credentials in WordPress

  1. In your WordPress admin, navigate to Authyo OTP for CF7.
  2. You'll land on the General settings tab.
  3. Enter your App ID, Client ID, and Client Secret in the respective fields.
  4. Click Save Settings. Credentials are encrypted immediately.

Step 3: Configure Verification Methods

Click on the Verification Methods tab. Enable/disable channels, set the primary phone method, configure OTP length (4–9 digits), expiry time, resend cooldown, maximum resends, and fallback timer.

Step 4: Configure Country Settings

If you're using phone OTP, configure the country dropdown behavior: All countries (global), Selected countries (regional), or Single country (one market). Enable Advanced Phone Validation for real-time client-side number checking.

Step 5: Enable OTP for Your Forms

Authyo Form Integration tab showing CF7 forms with OTP enable toggles
The Form Integration tab — enable OTP per form, set the target field, and configure redirect URLs.
  1. Click on the Form Integration tab.
  2. For each form you want to protect, toggle Enable OTP to on.
  3. Set the Target Field — e.g., your-email or your-phone.
  4. Optionally set a Redirect URL — the page sent to after successful submission.
  5. Click Save.

Step 6: Add OTP Shortcodes to Your CF7 Form

CF7 form editor with Authyo OTP shortcode added between form fields
The CF7 form editor — add the Authyo OTP shortcode in the position where you want the verification widget to appear.

Open your Contact Form 7 form for editing (Contact → Contact Forms → Edit). Add the appropriate Authyo shortcode in the position where you want the OTP widget to appear. See the full shortcode reference below.

Step 7: Configure WhatsApp Admin Notifications (Optional)

  1. Go to the WhatsApp Notifications tab.
  2. Enter your admin phone number with country code (e.g., +91XXXXXXXXXX).
  3. Enable the global toggle and enable per form as needed.
  4. Save settings.

OTP Shortcodes Reference

The plugin uses WordPress shortcodes to embed OTP widgets inside CF7 forms. Here is the complete reference:

Renders a complete email OTP verification widget — including the "Send OTP to Email" button, the OTP input field, and the resend link. Use when your form collects an email address.

Renders a complete phone OTP verification widget — including the country code dropdown, the "Send OTP" button, the OTP input field, and the fallback method buttons. Use when your form collects a phone number.

Renders only the country code dropdown without any OTP widget. Use this when you want to add a country selector to a phone field without triggering OTP verification.

Example: Dual Verification Form Layout

<label> Your Name [text* your-name] </label> <label> Your Email [email* your-email] </label>
<label> Your Phone [tel* your-phone] </label>
<label> Your Message [textarea your-message] </label> [submit "Submit"]

In this example, both email and phone must be verified before the form can be submitted.

Authyo OTP verification widget displayed on a live CF7 form
The OTP verification widget rendered on a live CF7 form — clean, responsive, and embedded directly in the form flow.

How OTP Verification Works — The User Journey

Email OTP Flow

  1. The user fills in their email address in the form.
  2. They click "Send OTP to Email".
  3. The plugin calls the Authyo API, which sends a one-time code to that email address.
  4. The user checks their inbox and enters the code in the OTP input field.
  5. The plugin verifies the code with the Authyo API.
  6. A green "Email verified ✔" message appears. The user can now submit the form.

Phone OTP Flow

  1. The user selects their country from the dropdown and enters their phone number.
  2. They click "Send OTP via SMS/WhatsApp/Voice Call".
  3. If the code doesn't arrive within the fallback timer, alternative method buttons appear.
  4. The user enters the OTP code.
  5. A green "Phone verified ✔" message appears. The form can be submitted.

Server-Side Guard

Even if a malicious user bypasses the JavaScript UI, the plugin runs a server-side verification check using the wpcf7_before_send_mail hook. If valid, server-stored verification tokens are not present, the form is aborted before the email is sent or the lead is saved. The verification is not bypassable from the client side.

Real-World Use Cases

🎯
Lead Generation Forms
Marketing teams can trust their lead lists — every email and phone has been actively verified.
📅
Appointment Booking
Verify customers booking appointments can actually be reached. Reduce no-shows from fake details.
💼
Job Application Forms
Ensure candidates provide real, reachable contact info before entering your recruitment pipeline.
🏦
Financial & Legal Inquiries
Loan applications and legal intake forms benefit from dual email + phone verification.
🛒
Callback & Quote Requests
Verify customer phone numbers so your sales team isn't chasing dead ends.
🏥
Healthcare & Professional Services
Patient intake forms and consultation requests benefit from verified, trusted contact details.

Authyo OTP vs. CAPTCHA vs. Email Confirmation Links

Feature Authyo OTP reCAPTCHA v3 Email Confirmation Link
Verifies real email ownership Yes No Yes
Verifies real phone ownership Yes No No
Works without user friction Moderate Yes (invisible) No (inbox action)
Blocks bots Yes Yes No
Verifies data quality Yes No Partially
Works for phone number fields Yes No No
GDPR friendly Yes Requires consent Yes
Admin notification WhatsApp No No
Mobile-first UX Yes Variable No

CAPTCHA is effective against bots but does nothing to verify that the contact details submitted are real. A bot that fills in a form with fake but plausible-looking data can pass reCAPTCHA. OTP verification catches this entirely different category of problem.

Email confirmation links work but require the user to leave the page, check their inbox, click a link, and potentially return — creating significant drop-off. OTP keeps the entire verification experience within the form in under 30 seconds.

Security Features Deep Dive

Security is at the core of how Authyo OTP for Contact Form 7 is designed:

  • Encrypted Credential Storage — API credentials encrypted with AES-256-CBC using keys derived from your WordPress site's unique secret salts. Even database access cannot expose your credentials without the salt configuration.
  • Server-Side Verification Authority — Verification state is stored in WordPress transients — not in cookies, local storage, or hidden form fields that can be manipulated. The submission guard queries the server-side transient directly. Client-side JS state is irrelevant to whether the server allows a submission.
  • Rate Limiting — Scoped per IP address, form ID, and target — preventing automated abuse of OTP endpoints from a single source.
  • REST API Nonce Authentication — Both OTP endpoints (/send and /verify) are protected by WordPress REST API nonces. Every request must include a valid X-WP-Nonce header, preventing CSRF attacks.
  • OTP Expiry — Codes expire after a configurable window (default 5 minutes), limiting the attack surface for OTP interception or reuse.
  • Token Cleanup — Verification tokens are cleared from the server immediately after a successful form submission, preventing token replay attacks.
  • Input Validation — All inputs are sanitized and validated before processing. OTP codes are validated against a strict numeric pattern on the server side.

GDPR and Privacy Compliance

For website operators serving EU users (or any jurisdiction with strong data protection laws), GDPR compliance is not optional.

What Authyo OTP Does with User Data

During the OTP process, the Authyo cloud service temporarily processes the email address or phone number to deliver the OTP code. Verified form submission data is stored in the wp_authyo_leads table in your own WordPress database — never on Authyo's servers.

Right to Erasure (GDPR Article 17)

The plugin registers a personal data eraser with WordPress's built-in privacy tools. Administrators can go to Tools → Erase Personal Data, enter a user's email address, and WordPress will automatically call the plugin's eraser — which searches the wp_authyo_leads table for all records containing that email and deletes them.

Privacy Policy Content

A pre-written, plugin-provided privacy policy section is automatically suggested in the WordPress Privacy Policy editor — reducing the burden on site administrators to write technical privacy language themselves.

Frequently Asked Questions

Does this plugin work without Contact Form 7?

No. Authyo OTP for Contact Form 7 requires Contact Form 7 to be installed and activated. It extends CF7's functionality and is not designed to work standalone or with other form plugins.

Do I need an Authyo account to use this plugin?

Yes. The plugin connects to the Authyo API to send and verify OTP codes. You need to create an account at authyo.io, create an application, and obtain your App ID, Client ID, and Client Secret.

Can I verify both email and phone in the same form?

Yes. Use

and
in the same CF7 form. Both must be verified before the form can be submitted.

What happens if the OTP is not received?

The user can click Resend after the cooldown period. If a fallback timer is configured, alternative delivery methods (SMS, WhatsApp, Voice Call) automatically appear after the timer expires so the user can try a different channel.

Will OTP verification break my caching setup?

No. The plugin automatically sets the DONOTCACHEPAGE constant on pages containing OTP forms. This instructs all major caching plugins to serve those pages dynamically, ensuring nonces remain fresh. No manual configuration required.

Can I export my leads to a CSV file?

Yes. The Leads Manager includes a CSV export feature. You can export all leads or apply filters (by status, form, or date range) before exporting.

Can I disable OTP for specific forms?

Yes. The Form Integration tab lets you enable or disable OTP independently for each CF7 form on your site.

Can I use this plugin to just add a country code dropdown without OTP?

Yes. Use the

shortcode. This adds the searchable country code selector to your phone field without triggering OTP verification.

Is the plugin compatible with multilingual WordPress sites?

Yes. The plugin is fully translation-ready and uses the authyo-otp-for-contact-form-7 text domain. All frontend-facing strings are wrapped in WordPress internationalization functions.

Is the plugin GDPR compliant?

The plugin includes built-in GDPR tools: a privacy policy content suggestion, a personal data eraser integrated with WordPress's Tools → Erase Personal Data, and consent management features. Overall GDPR compliance also depends on your specific site setup and data retention policies — consult a legal professional if in doubt.

Conclusion: Secure, Verify, and Trust Every Form Submission

If your business depends on Contact Form 7 to generate leads, bookings, inquiries, or registrations — and if the quality of those contacts matters — then Authyo OTP for Contact Form 7 is one of the most valuable plugins you can add to your WordPress site.

It solves the spam and fake data problem at the source, before submissions enter your system. It gives your sales and marketing teams a clean, verified, trustworthy lead list to work from. And it does all of this without replacing Contact Form 7, forcing you to rebuild your forms, or creating a disruptive experience for genuine users.

With four OTP channels, dual verification, smart fallbacks, a built-in leads database, Google Sheets integration, WhatsApp notifications, GDPR tools, and advanced phone validation — all in one plugin — it's a genuinely complete solution.

Ready to Verify Every Lead?

Install Authyo OTP for Contact Form 7 today and start collecting only real, verified, reachable contacts — every time.