What the form spam filter costs
Only about one submission in ten reaches a model, which is what keeps this cheap even when the spam volume is high. Four hundred and fifty submissions a month is a small business with a busy contact form. Here is where each cent goes.
Key takeaways
- About $2 a month at 450 submissions. Roughly $5 at 2,000 submissions.
- One Bedrock read per submission is the only line that scales. Everything else is rounding.
- Nothing is always-on, so a quiet month genuinely costs almost nothing.
- Nine in ten submissions are decided by free structural signals and never touch a model.
- The duplicate test runs before the read, so resends are free.
- The three real risks: a retry loop, storage nobody expires, and a bigger model than the job needs.
The bill at three volumes
These are US East prices at the time of writing, at three volumes that bracket most small businesses. Find the bar closest to your own and read across.
Line by line
| Line | At 450 submissions | How it scales |
|---|---|---|
| Bedrock read | $0.18 | Linear. One call per submission, roughly 1,800 in and 200 out tokens. |
| SES | $0.24 | Linear. About 0.3 messages per submission. |
| DynamoDB + S3 | $0.35 | Storage grows with what you retain, not with throughput. |
| Lambda + SQS | $0.12 | Linear, and effectively free at this scale. |
| CloudWatch | $0.16 | Flat, if you set retention. Unbounded if you do not. |
| Secrets Manager | $0.40 | Flat. One secret, $0.40 a month. |
| AWS Budgets | $0.46 | Flat. Two actions, so you find out before the bill does. |
The read cost is one small call on roughly one submission in ten, with a short prompt carrying only the message body. Everything else on this bill is the fixed band.
The three ways this bill surprises you
Every one of these has happened to somebody, and all three are cheap to prevent.
- Sending everything to the model. Ten times the read cost for no measurable accuracy gain, because the nine in ten were already unambiguous, and it makes every decision unexplainable.
- Retrying a model call on a bot flood. A spam wave of ten thousand submissions in an hour, each retried three times, is the one way this bill becomes interesting. Rate-limit the model band per hour and route the overflow to review.
- Log retention left at never. Every submission logs its signals, and at volume that is the largest line within a year.
What it costs when nothing happens
This matters more than the headline number for a seasonal business. In a month with nothing to process the bill is the fixed band: Secrets Manager at forty cents, AWS Budgets at forty-six, and a few cents of storage. Call it a dollar. There is no instance to stop and nothing to remember to turn off.
- Management
- Analytics
- Front-end & mobile
Set these on day one
- A dead-letter queue on every SQS queue, with a maximum receive count of three.
- Thirty-day retention on every CloudWatch log group. There is no default that is safe.
- An S3 lifecycle rule on the object prefix, tiering at 90 days and expiring at your actual record-keeping horizon.
- Two AWS Budgets actions — one that emails at half your expected spend, one at double it. The second is how you find out about a loop in an hour instead of a month.
- Provisioned concurrency: none. Nothing here is latency-sensitive enough to justify paying for a warm function.
Next: the same system drawn for engineers — service names, resource identifiers, IAM scopes, table schemas and the model id.
All posts