Technical

CAPTCHA

CAPTCHA is a challenge a server sends a client to prove a person is present, such as picking images or typing distorted text. The test is meant to be easy for a human and costly for a script.

How it is measured

Count challenges issued, solved, and failed per endpoint per day. Solve rate and time-to-solve matter: a median of 9 seconds is fine, 40 seconds means the puzzle is hurting real people. The verdict comes from the server POSTing the response token to the CAPTCHA vendor and reading back a success flag.

Trust only that server-side verdict. A form that checks the widget in JavaScript but never on the server can be submitted with plain curl.

Worked example

The contact form on an Astro site, handled by a Netlify function, takes 220 spam posts a day. After an image CAPTCHA goes in, spam falls to 14, but completed forms on mobile drop from 61 to 38 a day with a median solve time of 17 seconds.

A week later a spam message shows a paid solving service clearing the puzzle for about $0.002 a try. The abuse is not stopped, only priced.

How it differs

A CAPTCHA asks the visitor to do something. Turnstile tries to decide from browser signals and escalates to a puzzle only when unsure. A CAPTCHA has no silent path, so every visitor sees the test.

Common errors

Verifying only in the browser. Reusing one token for several submissions. Putting it on every page view instead of the one abused action. Shipping one with no accessible alternative. Assuming solving farms and image models cannot beat it. Leaving the verification call without a timeout.

In practice

Put it on the single action being abused, such as sign-up, password reset, or comment post, and verify the token on the server. Watch the solve rate. If more than a fifth of real people fail, try a honeypot field or a lighter challenge first.

See also

Turnstile, Bot management

Sources

Count this on a real site.

Watch my website