Earlier quoted context omitted.
> IMHO CPATCHA is a lazy way to protect your service as you shift the burden to your users. What is the non-lazy solution to having a basic website contact form that _doesn't_ receive hundreds of spam submission per day?
Like most kinds of gated security, many solutions are borne out of inspecting the payload instead of who's sending it. Captchas prevent bots from submitting spam, but they don't prevent humans from submitting spam. In 99% of cases, your problem is the spam, not who is submitting it. The non-lazy solution is to look at the content itself and directly determine whether it's spam, instead of relying on a related heurist…
For example, let's look at an actual service for identifying spam payloads: Akismet. It still lets a lot of spam through, especially in non-English languages.