Home › Guides › Spam without puzzles

When the contact form’s CAPTCHA is down: failing open

Most form plugins treat any CAPTCHA problem as a failed check. If the service is down, slow or rejects your secret, every visitor is told they look like a bot, and every enquiry is lost until someone notices. A safer design accepts the message, marks it as unverified, and keeps the other spam checks running.

Four ways a CAPTCHA fails that aren't the visitor's fault

  1. The service doesn't answer — an outage, a network problem between your host and the provider, or a timeout.
  2. Your secret key is rejected — rotated, deleted, or pasted with a character missing.
  3. A usage limit is reached — once reCAPTCHA's free monthly allowance is used, Google stops checking: by its own documentation it either refuses with an error or passes every token for the rest of the month.
  4. A script blocker in the visitor's browser prevents the widget from loading.

In the first three, rejecting the message punishes the visitor for your configuration or someone else's outage.

How Formsafe handles each one

  • No answer — the entry is accepted and marked unverified. It's saved and the notification sent as normal.
  • Secret rejected, or limit reached — the same, plus a notice on Formsafe's screens for administrators saying the key needs fixing. It disappears after the next successful check or a new key.
  • No answer in the form — a script blocker or JavaScript switched off, so the visitor never saw a challenge. While the CAPTCHA is passing your other visitors, the entry is saved under Spam with that reason, where you can still read it. If it hasn't passed anyone for about a day, it isn't running on your forms: entries are taken in without the check, and a notice says so.
  • A Turnstile or hCaptcha challenge left unanswered — the visitor saw it and pressed Send anyway. While the CAPTCHA is passing your other visitors, they're asked to confirm they're human and press Send again, with what they typed kept; if it hasn't passed anyone for about a day, the entry is taken in without the check.
  • A real failed check — the visitor is asked to confirm they're human and press Send again, with what they typed kept.
  • A Turnstile or hCaptcha widget that shows its own error — a site key that doesn't list your domain, say. The visitor had nothing to tick: the entry is kept as under No answer in the form, and a notice gives you the error code the visitor's browser reported (the service has not confirmed it).
  • A low reCAPTCHA score — saved as spam, where you can still read it.

Throughout, the honeypot, the 3-second time trap and the limit of five messages per address per ten minutes keep working, so an unverified entry has still passed three checks.

Why “fail open” is the right default here

A contact form exists to receive enquiries. A few extra spam messages during an outage cost you a minute; a day of refused customers costs you business you never hear about. The same principle runs through Formsafe: save first, tell the owner what went wrong, and never let an outside service decide that a real message disappears.

Formsafe Contact Form is a free contact form that saves every entry before it sends anything, and shows you what happened to each email.

See what it does