Can anyone tell me what reporting spam actually does, as it appears like very little?

Login forms wouldn’t generate an email. However you might still get “failed login” logs depending on the system you’re using.

What type of login forms are these? Are you talking about Webflow’s password pages?

If they’re e.g. Memberstack login forms, I’d just create them using custom elements if I want to avoid the Turnstile install.

It affects all native Form elements, but it ignores custom elements and Embedded HTML. Depending on what your login form is connecting to, that’s probably the best approach.

Maybe. It would require a giant hashtable keyed on form id + key-value hash.
A lot of effort for a very narrow case, most SPAM I see does change up randomly, even if it’s only a word or two.

However it’s worth sharing your concern to Webflow- just open a support ticket.