On a website that I have created, I have a contact page that is filled with email contacts, and my client asks me if this same address will be protected by spoofing, that's why I ask if there is a filter in modsec's wap or in directadmin's filtering via Brute Force.
Spoofing protection can't be handled by modsec or Brute Force. People even can spoof e-mail addresses on other mailservers.
The prevention of spoofing is done by strict SPF settings and additionally the use of DKIM and DMARC records.
Is the contact form protected for brute force spamming attacks? I don't know, I don't use modsec and the Brute force filtering of DA does not look at WP contact forms.
Maybe somebody else can answer that for you how to best protect against that on contact forms.