captcha is a very common way to prevent such (and for a very good reason, you should think about it)
If you could not set a cookie and check if its set is installed, if there is one, prohibit sending mail or register an IP address in a file or database and check when ip sent the last mail, and if the difference is small enough, prohibit sending mail
source share