Home › Guides › Spam without puzzles

reCAPTCHA v3 on a WordPress contact form

reCAPTCHA v3 is invisible: instead of a puzzle, Google returns a score between 0.0 (likely a bot) and 1.0 (likely a person), and your site decides where to draw the line. You need a site key and secret key from Google, and the form plugin needs a sensible rule for low scores and for Google not answering.

Keys, and the move to Google Cloud

reCAPTCHA keys are now managed inside Google Cloud projects. The free tier covers 10,000 checks a month for each organisation, and a busy site — or a spam run — can reach it. What happens then depends on which of Google's pages you read: its general quota page says further requests fail with an error (HTTP 429), while the part about the check a form uses says that check “fails open” — every token passes, with a fixed score of 0.9 and the message “Over free quota.”, for the rest of the month. Either way the check has stopped checking. A form that treats the error as spam starts rejecting everybody; one that takes the 0.9 at face value lets every bot through without a word.

Choosing the threshold

Google's own suggestion is to start at 0.5. Lower lets more through; higher catches more bots and more real people using VPNs or privacy tools. A contact form usually wants to be forgiving, because a lost customer costs more than one spam message.

In Formsafe Contact Form

Choose Google reCAPTCHA v3 under Formsafe → Settings → Spam and paste your site key and secret; the secret is masked after saving. The script loads only on pages with a form. Then:

  • A score of 0.5 or more is accepted as a normal entry.
  • A score below 0.5 is saved as spam, with the reason and without a notification, and kept under Spam for 30 days so you can check it.
  • If Google can't be reached, or says the monthly quota is used up — with an error, or with a pass that mentions the quota — the entry is accepted and marked unverified. A notice tells you when Google rejected your secret or the quota ran out.
  • If the form arrives with no reCAPTCHA token at all — JavaScript off, or Google's script blocked — and reCAPTCHA is passing your other visitors, the entry is saved under Spam with that reason. If it hasn't passed anyone for about a day, reCAPTCHA isn't running on your forms: entries are taken in without the check, and a notice tells you.

The honeypot, time trap and per-address limit keep working the whole time, so the quiet checks still stop the everyday bots while you sort out the keys.

Bringing keys over from Contact Form 7

Contact Form 7 stores its reCAPTCHA keys in its own settings. When you import CF7 forms into Formsafe, the importer offers to take those keys over — and does so only if you say yes. More in reCAPTCHA keys after switching.

Formsafe Contact Form is a free contact form that saves every entry before it sends anything, and shows you what happened to each email.

See what it does