Web-to-lead feels limitless right up to the day it isn't. A campaign lands, a form gets traffic, and somewhere in the background Salesforce stops creating leads. Nobody on the sales team sees an error, because there isn't one on the page: the visitor gets the same thank-you screen either way. This post covers the cap, the confusing and conflicting accounts of what happens afterward, and the few cheap habits that keep a lead-flow problem from becoming a revenue problem.
The limit: 500 requests in 24 hours
Salesforce caps web-to-lead at 500 submissions within a 24-hour period. Several independent write-ups agree on that number, and on the fact that it can be raised: the usual route is to open a case with Salesforce Support and ask. It is an org-level limit, not a per-form one, so three forms on three landing pages share the same budget.
What happens to the 501st lead depends on who you ask
This is where the sources stop agreeing, and it is worth being plain about that rather than picking a favorite. SalesforceBen describes overflow requests being held in a pending queue that is shared with web-to-case and processed when the limit refreshes, counting against the next day's allowance. Other write-ups, including Formstack's and K2 University's, say Salesforce instead emails the lead details to the default lead owner or creator, leaving someone to re-key each record by hand.
Either behavior, or a mix, may apply depending on the org and the era of the documentation. We could not confirm the current rule from Salesforce's own documentation, so treat both as plausible and verify yours. What every account shares is the practical consequence: leads past the cap do not arrive in real time, and some may need manual rescue.
The usual cause is not demand — it is bots
Most teams that hit 500 have not had 500 buyers. Unprotected forms attract automated submissions, and without a challenge on the form, those fake entries spend the same budget as real ones. Sources covering the topic repeatedly point to reCAPTCHA as the first fix. A hidden honeypot field, one that real visitors never fill and bots usually do, is a cheap second layer, and a server-side check that discards entries with the honeypot filled keeps junk from ever being forwarded to Salesforce at all.
If your lead count has jumped but your pipeline hasn't, look at the lead source and email domains of the newest records before you celebrate. The same habit applies to site analytics generally; our note on bot traffic in reporting is coming up in the publishing queue.
A short checklist
1. Know your normal. Pull a report of leads created via web-to-lead per day for the last 90 days. If your busiest day is already above 250, you are within one campaign of the ceiling.
2. Filter before Salesforce sees it. Add reCAPTCHA and a honeypot so junk never counts against the budget.
3. Ask for more headroom before a launch. If a webinar, a trade-show push or a paid burst could plausibly spike submissions, open the Support case in advance. Doing it after the cap is hit means the leads you most wanted are the ones delayed.
4. Know where the fallback lands. Check who is named as the default lead creator or owner in your web-to-lead settings, and make sure that mailbox is monitored by a person, not an unwatched alias. If overflow is emailed, that inbox is your safety net.
5. Alert on silence. A daily report or dashboard alert that fires when web-to-lead creation drops to zero on a weekday catches a stalled form faster than anyone noticing in a pipeline review.
If the volume is genuinely real
Consistently high demand is a good problem, and it may outgrow web-to-lead altogether. At that point the sturdier route is posting form data through the Salesforce API or an integration platform, which brings its own limits and its own monitoring, but removes the single shared 500-a-day ceiling from the critical path. If you are still building the form side, our guide to capturing UTM parameters in web-to-lead forms covers attribution, and the walkthrough on round-robin lead assignment without a paid app covers what happens to a lead once it does arrive.
The takeaway
The cap itself is rarely the problem. The problem is learning about it from a sales rep asking where the leads went. Five minutes with a daily-count report, a spam filter on the form and a monitored fallback inbox turn a silent failure into a managed limit.
Sources: SalesforceBen, Formstack, K2 University, MassMailer.