In short
Not as a first line of defence. Visible reCAPTCHA puzzles cost measurable conversions, fail visitors with disabilities, add Google tracking that needs a privacy disclosure, and are now solved cheaply by AI services. Start with invisible layers: a honeypot field, a minimum-time check, server-side validation and rate limiting, which stop most automated spam with zero friction. If bots still get through, add an invisible challenge such as Cloudflare Turnstile or reCAPTCHA v3, which score visitors silently and only challenge the suspicious.
What a CAPTCHA is for, and why it works less than it did
A CAPTCHA is a test intended to be easy for humans and hard for software. For years the test was reading distorted text, then identifying traffic lights and buses. The premise has eroded from both sides: image recognition is now something software does better than people, and CAPTCHA-solving services will return an answer for a fraction of a cent using either AI or low-paid workers. A visible puzzle stops the laziest bots and none of the motivated ones.
Meanwhile the cost to real visitors has stayed. Studies of form abandonment consistently find that adding a visible CAPTCHA reduces completions, with estimates ranging from a few percent to well over ten depending on the audience and the difficulty. Older visitors, visitors on phones, visitors with visual or motor impairments, and non-native speakers fail or abandon at higher rates. A form that loses a tenth of its enquiries to protect against spam the inbox filter would have caught has made a bad trade.
The specific costs of reCAPTCHA
Conversion. As above, and worst for the version 2 checkbox that escalates to image puzzles.
Accessibility. Audio alternatives exist and are poor. Screen-reader users and people with motor impairments regularly report being unable to complete reCAPTCHA challenges, which is a WCAG failure on any form that requires it.
Privacy. reCAPTCHA is a Google service that loads a script and sets cookies, and its scoring uses signals about the visitor's behaviour and Google account. In the EU it requires disclosure and, in the view of several data protection authorities, consent. That is a cookie banner consequence for a spam filter.
Performance. Several hundred kilobytes of script on every page carrying the form.
Bias. The invisible version scores visitors partly on Google's knowledge of them. Visitors using privacy tools, VPNs, or uncommon browsers score as suspicious and get challenged more, which punishes the careful.
What to use first
Most form spam is automated scripts that never render the page. Four invisible measures stop nearly all of it:
- A honeypot field hidden from humans that bots fill in. Submissions with it populated are dropped silently.
- A minimum-time check. Reject submissions completed in under a few seconds of the form being rendered, using a signed timestamp.
- Server-side validation that refuses empty messages, multiple links, and malformed addresses.
- Rate limiting per address, so no source can submit more than a handful of times an hour.
We have written up why contact forms get spam and how each layer works. On our own site, a honeypot, validation and a five-per-hour rate limit with no CAPTCHA at all are enough. That is typical for a business site; the layers cost nothing to visitors and a few lines of code to implement.
When an invisible challenge is justified
Some forms are worth attacking: account registration, anything that sends email to an address the submitter chooses, comment systems, and anything that grants access or credit. If the four layers are in place and abuse continues, add a challenge that stays invisible for most visitors:
Cloudflare Turnstile. Free, runs a background check, shows a brief non-interactive widget, rarely challenges, sets no tracking cookies and is designed with privacy in mind. Currently the best default.
reCAPTCHA v3. Scores the visitor silently; you decide the threshold. No puzzle for most, but the privacy and bias costs remain, and low scorers get no recourse.
hCaptcha. A privacy-focused alternative with similar mechanics to reCAPTCHA v2, including visible puzzles in its challenge mode.
Proof-of-work challenges that make the visitor's browser compute something briefly. Invisible, privacy-neutral, and effective against volume.
In every case, verify the token on the server; a challenge checked only in the browser is decorative.
What still needs a visible puzzle
Almost nothing on a business site. High-value targets under sustained attack, such as ticket sales or limited-stock drops, sometimes escalate to visible challenges for suspicious traffic only. That is a scoring decision, not a default. If a form is showing puzzles to everyone, it is treating all visitors as the attacker.
The decision
Add the four invisible layers to every form; they solve the problem for most sites. Add Turnstile or an equivalent invisible challenge to forms that are genuinely attacked. Reserve visible puzzles for the small minority of visitors who have already scored as suspicious on a high-value form, and accept that some of those will be real people who leave. If your forms are losing real submissions to a CAPTCHA that is not stopping the fake ones, book a call and we will replace it with something quieter.
Common questions
Does reCAPTCHA reduce conversions?
Visible reCAPTCHA does. Form abandonment studies put the loss at a few percent to over ten depending on the audience and the difficulty of the challenge, with older visitors, mobile users and people with disabilities affected most. Invisible layers such as honeypots and rate limiting stop most spam with no loss at all.
Is reCAPTCHA GDPR compliant?
It is contested. reCAPTCHA sets cookies and sends behavioural data to Google, which several EU data protection authorities have said requires consent and disclosure. At minimum it must be listed in the privacy policy and, in the strict view, loaded only after consent. Cloudflare Turnstile is designed to avoid these issues.
What is the best alternative to reCAPTCHA?
For most business forms, no CAPTCHA at all: a hidden honeypot field, a minimum-time check, server-side validation and rate limiting stop nearly all automated spam invisibly. Where a challenge is still needed, Cloudflare Turnstile runs silently, rarely challenges, is free and sets no tracking cookies.
Is reCAPTCHA accessible?
Poorly. Image puzzles are difficult or impossible for visitors with visual impairments, the audio alternative is hard to use, and timed challenges disadvantage people with motor impairments. A form that requires completing reCAPTCHA v2 is likely to fail WCAG. Invisible protections or Turnstile avoid the problem for almost everyone.
Can bots solve reCAPTCHA?
Yes. CAPTCHA-solving services return answers for a fraction of a cent using AI or human workers, and modern image recognition handles the puzzles directly. A visible CAPTCHA stops only the least sophisticated scripts, which honeypots and timing checks also stop, without inconveniencing real visitors.
