Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

WordPress can restrict comments to logged-in users and hold comments for approval, but neither a typed name nor email address proves who submitted a comment. For stronger control, require registration and login, review comments before publication, or disable comments on posts that do not need them.

What WordPress can—and cannot—verify

WordPress’s Discussion settings can require commenters to have an account and be logged in. That creates an account gate; it does not establish the registrant’s real-world identity.

The option “Comment author must fill out name and e-mail” only requires those fields. WordPress’s Settings Discussion screen documentation states: “In reality, the name and e-mail address are not verified in any way prior to the comment being submitted.” Treat a name and email in a comment form as information supplied by the commenter, not proof that the person named wrote it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose controls that match your site

Configuration What it changes Trade-off
Open comments Visitors can submit comments without a login requirement. Less friction for readers, but anyone may enter a name and email.
Require registration and login Only logged-in users can comment. Adds an account hurdle; it does not verify a user’s legal identity.
Selective moderation Comments matching your moderation rules are held for review. Less review work than holding every comment, but rules are general moderation controls, not an impersonation detector.
Approve every comment No comment appears until an authorized reviewer approves it. Maximum editorial review, with the highest approval workload.
Disable comments Visitors cannot comment on the posts where comments are disabled. Removes discussion on those posts.

WordPress explains account requirements and comment approval options in its Discussion settings documentation. The appropriate balance depends on whether open participation or pre-publication review matters more to your site.

Require an account to comment

  1. In the WordPress dashboard, open Settings > Discussion.
  2. Under the section for other comment settings, select Users must be registered and logged in to comment.
  3. Save the changes, then check the comment form on a post to confirm the setting behaves as intended.

This limits commenting to logged-in accounts, which can make casual participation harder. It is not independent identity verification: the cited WordPress documentation does not say the setting confirms a person’s legal identity.

Hold comments for review

Approve every comment

To review all submissions before they appear, open Settings > Discussion and enable An administrator must always approve the comment. Comments remain unpublished until an authorized person approves them. This is the clearest option when a false attribution could cause harm, but it means every comment requires attention.

Use selective moderation rules

If reviewing every submission is too burdensome, configure comment moderation rules in the same Discussion settings screen so comments meeting the rules are held in the moderation queue. Review suspicious comments before approving them. These rules can help manage unwanted comments generally; they do not establish who wrote a comment or specifically detect impersonation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use the previously approved commenter rule carefully

The option Comment author must have a previously approved comment uses the submitted author email and compares it with an email associated with a previously approved comment. It can route first-time submissions or comments using a changed email address for review. It is a moderation condition, not proof that the current commenter controls the email or is the person previously approved.

Review comments before they appear

Open Comments in the dashboard to review, edit, approve, mark as spam, or move comments to Trash. WordPress describes these actions in its Comments in WordPress documentation.

Because editing can change the author name and email, use a clear editorial policy for any corrections. Do not treat a familiar display name, a plausible email address, or a previously approved comment as conclusive evidence of authorship. If a comment appears to impersonate someone, keep it unpublished while you assess whether it should be rejected, edited under your policy, marked as spam, or trashed.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Disable comments where discussion is not needed

If a post should not accept comments, disable them for that post. The global setting for new posts does not automatically close comments on older posts, so existing content may need changes individually or in bulk. WordPress notes this distinction in its Understanding comment spam documentation, updated May 7, 2026.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

WordPress also cautions that requiring details or registration may make commenting harder for spammers without stopping every spammer. Disabling comments or using moderation can reduce opportunities for unwanted publication, but these controls should not be presented as guaranteed identity protection.

A practical setup for most sites

  • For open communities: keep participation accessible, but use selective moderation and review any questionable attribution before approval.
  • For sensitive discussions: require registered, logged-in users and hold every comment for approval if your staff can sustain the review workload.
  • For posts with no useful discussion: disable comments on those posts and check older content separately.

WordPress’s documentation does not establish that a specific plugin or third-party service verifies commenter identity or prevents impersonation. Evaluate any outside tool on its current, documented capabilities rather than assuming spam filtering is identity verification.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.