All articles

Best reCAPTCHA Alternatives in 2026, Including No-CAPTCHA Options

Published Updated By GoodInbound team

Compare reCAPTCHA alternatives for 2026: Turnstile, hCaptcha, Friendly Captcha, ALTCHA, Cap, CleanTalk, Akismet, honeypots, and options with no CAPTCHA at all.

The main reCAPTCHA alternatives in 2026 are Cloudflare Turnstile (free and mostly invisible), hCaptcha (the closest drop-in), and the privacy-first proof-of-work options: Friendly Captcha, ALTCHA, and Cap. CleanTalk and Akismet filter the submission instead of challenging the visitor, and a honeypot costs nothing. If you want no CAPTCHA at all, screen each submission after it's sent.

None of the CAPTCHAs stop a person, which is why so many forms with reCAPTCHA still fill up with agency pitches. Catching those takes screening that reads the message. For every other fix, see the full guide on how to stop contact form spam.

GoodInbound Lead Screen replaces reCAPTCHA with no CAPTCHA at all. Add one script to your existing form and it screens every submission in the background, with nothing for the visitor to solve:

  • Stops bots and fake sign-ups without a puzzle, a checkbox, or a badge.
  • Catches unsolicited sales pitches from people and AI tools by reading the message.
  • Labels every submission with a one-line reason, deletes nothing, and notifies you by email, Slack, or Telegram only for the labels you choose.
  • Sends only real leads on to your CRM and ad platforms.

The free plan screens 500 submissions a month; the message check that catches sales pitches is on Pro. Start free, or read on for every method.

Why people are leaving reCAPTCHA

  1. The free tier shrank and moved into Google Cloud. Classic reCAPTCHA allowed up to a million calls a month. Google stopped issuing classic keys in 2024 and moved existing ones into Google Cloud projects between late 2025 and early 2026, and now sells reCAPTCHA as part of Google Cloud Fraud Defense. The free Essentials tier covers 10,000 assessments a month, counted across your whole organization. Above that, Premium is an $8 flat fee up to 100,000, then $1 per 1,000 (checked October 2026). Go over without billing turned on and, per Google's migration guide, siteverify fails open: it returns success with a score of 0.9, so bots get through.
  2. Privacy. reCAPTCHA runs Google's script on your page, sets a _GRECAPTCHA cookie, and sends browser signals to Google. Since April 2, 2026, Google says it acts as your data processor. You're still the controller, though, the data still goes to a US company, and some EU privacy teams decide it needs consent, so it can't run until the cookie banner is accepted.
  3. Friction. The v2 checkbox turns into an image grid whenever Google isn't sure about a visitor, and every puzzle loses you some people who were about to get in touch. v3 drops the puzzle but leaves you to pick a score threshold (Google suggests 0.5 to start). See reCAPTCHA v2 vs v3.
  4. Accessibility. The W3C's note on CAPTCHA inaccessibility says traditional CAPTCHAs still block many people with disabilities, and that keyboard users of reCAPTCHA v2 are increasingly sent to an inaccessible fallback.
  5. It doesn't stop people. A CAPTCHA proves a human is present. Agencies, link sellers, and recruiters are humans, and they tick the box like anyone else. More in why reCAPTCHA isn't stopping your spam.

reCAPTCHA alternatives compared

Prices and limits are from each vendor's own pricing page and docs, checked October 2026.

Option How it works What visitors see Free tier Reads the message
reCAPTCHA (for reference) Google risk analysis Checkbox and image puzzles (v2), a badge (v3) 10,000 assessments a month per organization No
Cloudflare Turnstile Background browser challenges Usually nothing, sometimes a checkbox Free, unlimited challenges No
hCaptcha Risk analysis plus image challenges A challenge for most visitors on Free Free plan; Pro from $99/month No
Friendly Captcha Proof-of-work plus risk signals A widget that solves itself Non-commercial sites only; paid from €9/month No
ALTCHA Self-hosted proof-of-work A widget that solves itself Open source, no limits No
Cap Self-hosted proof-of-work plus browser checks A widget that solves itself Open source, no limits No
CleanTalk Cloud check of IP, email, and content Nothing 7-day trial, then $12/year per site Checks it for spam patterns
Akismet Cloud spam filter on content Nothing Name your price for personal sites Checks it for spam patterns
Honeypot + time trap Hidden field and fill-time check Nothing Free (you build it) No
GoodInbound Lead Screen Screens behavior, network, and identity Nothing 500 screened submissions a month On Pro, against what you sell

The first six are CAPTCHAs: they challenge the visitor's browser before the form sends. The last four look at the submission instead, so there's nothing for the visitor to do.

The alternatives, one by one

1. Cloudflare Turnstile

Cloudflare's free CAPTCHA replacement, and your site doesn't have to run through Cloudflare to use it. The widget runs small non-interactive challenges in the browser (proof-of-work, proof-of-space, browser API probes) and gives your form a token, which your server must check with Cloudflare's Siteverify API.

  • Visitor friction: none for most visitors in Managed mode, and a checkbox when risk looks higher.
  • Privacy: Cloudflare says Turnstile doesn't read form entries and processes only what the security check needs.
  • Price: free with unlimited challenges, up to 20 widgets. Enterprise is priced by sales.
  • Best for: most sites that want a free, low-friction swap. See Turnstile vs reCAPTCHA.
  • Misses: people. Anyone typing a pitch in a real browser passes.

2. hCaptcha

The closest drop-in replacement. hCaptcha's API is compatible with reCAPTCHA's, so switching is mostly a new script URL, h-captcha in place of g-recaptcha, and a new verify endpoint.

  • Visitor friction: high on the free plan, where hCaptcha's own FAQ says most visitors will see a challenge. Pro adds a passive mode in which, by hCaptcha's figures, fewer than 0.1% of real users see one.
  • Privacy: hCaptcha says it complies with GDPR, CCPA, LGPD, and PIPL.
  • Price: Basic is free. Pro is $99/month billed yearly ($139 month to month) for 100,000 evaluations, then $0.99 per 1,000.
  • Best for: sites that want reCAPTCHA-compatible code and can live with a visible challenge, or pay for Pro.
  • Misses: people, and on Free it adds friction instead of removing it.

3. Friendly Captcha

A German service built around privacy. The widget solves a proof-of-work puzzle in the background, combined with risk signals, and finishes on its own. No image tasks.

  • Visitor friction: nothing to click. Slower phones take a little longer to finish the work.
  • Privacy: Friendly Captcha says it doesn't store personal data. EU-only data centers come with the Advanced plan.
  • Price: free only for non-commercial, low-traffic sites (1,000 requests a month). Starter is €9/month for 1,000 requests, Growth €39/month for 5,000, and Advanced €200/month for 50,000, each with a 30-day trial.
  • Best for: EU businesses with modest traffic that want a hosted, privacy-first CAPTCHA and a WordPress plugin.
  • Misses: people, and the request caps are low for busy sites.

4. ALTCHA

An open-source (MIT) proof-of-work CAPTCHA you host yourself. Your server issues a challenge with one of ALTCHA's server libraries, the browser solves it in the background, and your server checks the answer. Version 3 uses memory-hard algorithms (Argon2 and scrypt), so GPUs help attackers less.

  • Visitor friction: nothing to click, just a moment of work on the visitor's device.
  • Privacy: no cookies, no fingerprinting, and nothing goes to a third party when you self-host. ALTCHA says it meets WCAG 2.2 AA.
  • Price: the open-source widget is free, with no sign-up, API keys, or usage limits. ALTCHA Cloud (hosted in the EU) starts at €47/month, self-hosted Sentinel at €99/month, and the WordPress plugin at €18.90/month.
  • Best for: developers who want full control and no data sharing.
  • Misses: people. A spammer with enough computing power pays the cost, and you maintain the server side.

5. Cap

A newer open-source (Apache 2.0) CAPTCHA you host yourself, with its latest release in September 2026. It pairs proof-of-work with browser checks generated on the server and runs as a standalone Docker server. Its verify API is compatible with reCAPTCHA's, though you swap the widget on the page.

  • Visitor friction: nothing to click.
  • Privacy: self-hosted, and Cap says it sets no cookies and sends no telemetry.
  • Price: free.
  • Best for: teams already running their own servers who want a second layer beyond proof-of-work.
  • Misses: people, and you host and update it.

We left out mCaptcha, another self-hosted proof-of-work project, because its last release was in March 2024.

6. CleanTalk

Not a CAPTCHA. CleanTalk's plugin or API sends each submission (IP address, email, message, and other field values) to CleanTalk's cloud, which checks it against its spam database and returns allow or deny. Plugins cover WordPress, WooCommerce, and other CMSs.

  • Visitor friction: none.
  • Privacy: the submission goes to CleanTalk, stored in the US and EU by default, with an EU-only option.
  • Price: no free plan. After a 7-day trial it's $12/year for one site with unlimited API calls.
  • Best for: WordPress sites that want cheap, invisible spam blocking.
  • Misses: it's tuned to known spam. A polite pitch from a clean address and IP may not match anything in a spam database.

7. Akismet

Automattic's spam filter, built for WordPress comments and now used on forms too. Your site sends the content to Akismet and gets back spam or not spam. It works with Jetpack, Contact Form 7, Gravity Forms, and Formidable Forms.

  • Visitor friction: none.
  • Privacy: submission content goes to Automattic for checking.
  • Price: personal sites name their own price. Commercial sites need Pro, $9.95/month billed yearly for 500 spam checks a month, or Business at $49.95/month, also billed yearly, for 5,000.
  • Best for: WordPress comments and forms.
  • Misses: it judges whether something looks like spam, not whether it's relevant to your business, so a tailored pitch can pass.

8. Honeypot and time trap (DIY)

Two free checks you add to your own form. A honeypot is a field people can't see but simple bots fill in. A time trap rejects forms submitted faster than a person could type.

<input type="text" name="website" tabindex="-1" autocomplete="off" aria-hidden="true" style="position:absolute;left:-9999px">
<input type="hidden" name="loaded_at" id="loaded_at">
<script>document.getElementById("loaded_at").value = Date.now();</script>

On the server, reject the submission if website has a value or if it arrived less than three seconds after loaded_at. A bot can fake a timestamp the page provides, so sign it on the server if you can.

  • Visitor friction: none. Privacy: nothing leaves your server. Price: free.
  • Best for: low-traffic forms, and as a first layer under anything else.
  • Misses: bots that render the page properly, and every human. How to stop contact form spam without a CAPTCHA goes further.

9. GoodInbound Lead Screen (no CAPTCHA at all)

A different category: nothing challenges the visitor. Lead Screen screens the submission itself and gives it a label (lead, review, spam, junk, or bot) with a one-line reason. It runs from one script tag on your existing forms (HubSpot, Marketo, Webflow, WordPress, Framer, or plain HTML), or on GoodInbound's hosted forms and headless endpoint.

The checks run in order: your own rules (domains that are always a lead or always spam), behavior (fill time, typing cadence, pastes, pointer or touch, automation tells, a honeypot), network (datacenter IPs, VPNs, proxies, Tor, bursts from one IP), and identity (mail server, disposable and role addresses, domain age, gibberish). On Pro, it also reads the message against what your business sells, which is what catches sales pitches, recruiting, and link-building offers.

  • Visitor friction: none. No widget, no badge, no puzzle.
  • Privacy: no challenge script from an ad company. The script records how your form was filled in and sends it with the submission.
  • Price: Free covers 500 screened submissions a month with rules, behavior, network, and identity, but doesn't read the message. Pro is $29/month ($290/year) for 2,500 and adds the message check. Extra packs add 3,000 submissions for $30/month.
  • Best for: contact, demo, and quote forms, where the costly spam is pitches and fake leads, and where only real leads should reach your CRM and ad conversions. Nothing is deleted, so a mislabeled lead is one click from rescue.
  • Misses: it isn't a login or checkout defense, so keep a challenge there. Behavior and network checks need the script on the page. And pitches from real people need the message check, which is on Pro.

To see a label in action, paste a submission into the free form spam checker.

Which one should you use?

If you want Use
A free swap with minimal friction Cloudflare Turnstile
To keep your reCAPTCHA code almost unchanged hCaptcha, or Turnstile's compatibility mode
No third party at all ALTCHA or Cap, plus a honeypot
A managed service hosted in the EU Friendly Captcha or ALTCHA Cloud
Cleaner WordPress comments Akismet or CleanTalk
No CAPTCHA on lead forms, and no sales pitches GoodInbound Lead Screen, with the message check on Pro

How to replace reCAPTCHA on your form

Swap one form at a time.

  1. Remove reCAPTCHA from the page. Delete the https://www.google.com/recaptcha/api.js script and the g-recaptcha div, or, for v3, the grecaptcha.execute() call on submit.

  2. Add the replacement.

    • Turnstile: load https://challenges.cloudflare.com/turnstile/v0/api.js?compat=recaptcha with your Turnstile site key. Compatibility mode keeps v2-style grecaptcha calls and the g-recaptcha-response field working.
    • hCaptcha: load https://js.hcaptcha.com/1/api.js, rename g-recaptcha to h-captcha, and read h-captcha-response on the server.
    • GoodInbound: drop the CAPTCHA and add your script tag. Submissions land in your GoodInbound inbox with their labels.
    <script src="https://cdn.goodinbound.com/leadscreen.js" data-key="YOUR_PUBLISHABLE_KEY" async></script>
    
  3. Update the server check. For a CAPTCHA, replace Google's https://www.google.com/recaptcha/api/siteverify call with https://challenges.cloudflare.com/turnstile/v0/siteverify (POST only) or https://api.hcaptcha.com/siteverify, and swap the secret key.

  4. Test as a real visitor. Submit from a phone, from a VPN, and with the keyboard only, then confirm tokens verify, or that your test lands as lead.

The short version

If all you need is fewer bots, Turnstile is the easy free swap, or ALTCHA and Cap if you'd rather host it yourself. If the spam that eats your time is people pitching services, no CAPTCHA will fix it, because they pass every one. That's the gap GoodInbound fills: nothing for visitors to solve, a label and reason on every submission, and the message check on Pro to stop sales pitches on your contact form. For the rest of the toolkit, see the guide to stopping contact form spam.

FAQ

Is Google reCAPTCHA still free?

Partly. The Essentials tier is free up to 10,000 assessments a month per organization, and it now runs inside a Google Cloud project. Above that, Premium costs an $8 flat fee up to 100,000 assessments and $1 per 1,000 after that (checked October 2026).

What is the best free reCAPTCHA alternative?

Cloudflare Turnstile is free with unlimited challenges and works on sites that don't use Cloudflare. ALTCHA and Cap are free with no limits if you host them yourself. A honeypot and time trap cost nothing and add no friction, though they only stop simple bots.

Is Google reCAPTCHA GDPR compliant?

Google says it complies with GDPR under its Cloud Data Processing Addendum, and since April 2026 it acts as your processor. You're still the controller, though, and the script sets a cookie and sends visitor data to Google, so whether you need consent is a call for your privacy team. Self-hosted or EU-hosted alternatives make that question much simpler.

Which reCAPTCHA alternatives work on WordPress?

Most of them. Akismet, CleanTalk, Friendly Captcha, and hCaptcha have their own plugins on WordPress.org, Turnstile works through third-party plugins such as Simple CAPTCHA with Cloudflare Turnstile, and ALTCHA sells a WordPress plugin from €18.90/month. GoodInbound has no plugin: you add its script tag to your theme, and it screens the forms already there.

How can I verify visitors without a CAPTCHA?

Use invisible checks: a honeypot field, a minimum fill time, background proof-of-work, or screening the submission itself. Screening looks at how the form was filled in, the network, and the email, and can read the message to catch pitches from real people.

What is a proof-of-work CAPTCHA, and does it slow phones down?

The browser has to compute a small cryptographic puzzle before the form is accepted. It's tuned to be quick on a normal device, while costing a bot that sends thousands of submissions real computing time. Older phones take longer, so set the difficulty with your slowest visitors in mind.

Switch in 5 minutes

Setup with your agents