Technical
CAPTCHA
CAPTCHA is a challenge a server sends a client to prove a person is present, such as picking images or typing distorted text. The test is meant to be easy for a human and costly for a script.
How it is measured
Count challenges issued, solved, and failed per endpoint per day. Solve rate and time-to-solve matter: a median of 9 seconds is fine, 40 seconds means the puzzle is hurting real people. The verdict comes from the server POSTing the response token to the CAPTCHA vendor and reading back a success flag.
Trust only that server-side verdict. A form that checks the widget in JavaScript but never on the server can be submitted with plain curl.
Worked example
The contact form on an Astro site, handled by a Netlify function, takes 220 spam posts a day. After an image CAPTCHA goes in, spam falls to 14, but completed forms on mobile drop from 61 to 38 a day with a median solve time of 17 seconds.
A week later a spam message shows a paid solving service clearing the puzzle for about $0.002 a try. The abuse is not stopped, only priced.
How it differs
A CAPTCHA asks the visitor to do something. Turnstile tries to decide from browser signals and escalates to a puzzle only when unsure. A CAPTCHA has no silent path, so every visitor sees the test.
Common errors
Verifying only in the browser. Reusing one token for several submissions. Putting it on every page view instead of the one abused action. Shipping one with no accessible alternative. Assuming solving farms and image models cannot beat it. Leaving the verification call without a timeout.
In practice
Put it on the single action being abused, such as sign-up, password reset, or comment post, and verify the token on the server. Watch the solve rate. If more than a fifth of real people fail, try a honeypot field or a lighter challenge first.