Cloudflare Turnstile vs reCAPTCHA: Which One Stops Form Spam? (2026)
Turnstile vs reCAPTCHA compared on friction, privacy, pricing, setup code, and migration, plus the form spam that gets past both and how to stop it.
For most sites, Cloudflare Turnstile is the better choice. It's free with unlimited challenges, never shows an image puzzle, needs no Google Cloud project, and works on any website. reCAPTCHA still makes sense if you rely on v3's risk scores or Google's fraud features. On form spam, though, both stop the same thing: automated submissions. Neither reads what's typed into your form, so neither stops a person pasting in a sales pitch, and both stop nothing if your server doesn't check the token.
Below: how each one decides, what visitors see, privacy, pricing, setup code, and migrating with Turnstile's reCAPTCHA compatibility mode. For every other spam fix, see how to stop contact form spam.
GoodInbound Lead Screen stops form spam without a widget. One script on your existing form screens every submission, with no CAPTCHA and nothing for the visitor to click:
- Bots and fake sign-ups stopped, using how the form was filled in, the network it came from, and the email address.
- Sales pitches caught, from people and from AI, by reading the message.
- Every submission labeled with a one-line reason, and nothing is deleted.
- Email, Slack, or Telegram notifications for only the labels you choose, so only real leads reach your CRM and ad platforms.
The free plan screens 500 submissions a month; the message check that catches sales pitches is on Pro. Start free, or read on for the full comparison.
Turnstile vs reCAPTCHA at a glance
From Cloudflare's and Google's own docs, checked October 2026.
| Cloudflare Turnstile | Google reCAPTCHA | |
|---|---|---|
| How it decides | Background browser challenges, then pass or fail | v2: risk check, then a challenge if unsure. v3: a score from 0.0 to 1.0 |
| What visitors see | Usually nothing, sometimes a checkbox. Never an image puzzle | v2: a checkbox, sometimes image challenges. v3: a badge |
| Widget modes | Managed, non-interactive, invisible | v2 checkbox, v2 invisible, v3 |
| Privacy | Processes IP, TLS fingerprint, user agent; no cookies used to collect information | Sets a _GRECAPTCHA cookie; Google is a data processor since April 2, 2026 |
| Free tier | Unlimited challenges, 20 widgets, 10 hostnames each | 10,000 assessments a month per organization |
| Paid | Enterprise, via sales | $8 flat up to 100,000 a month, then $1 per 1,000 |
| You need | A free Cloudflare account, no Cloudflare DNS or proxy | A Google Cloud project, billing above 10,000 a month |
| Token | Valid 5 minutes, single use | Valid 2 minutes, single use |
| Accessibility | WCAG 2.2 AA, per Cloudflare | v2 puzzles are hard for some visitors |
| Reads what was submitted | No | No |
How each one decides
Turnstile is what Cloudflare calls a CAPTCHA alternative. When the widget loads, it runs small non-interactive JavaScript challenges in the browser (proof-of-work, proof-of-space, probing for web APIs) and adjusts them per visitor. A browser that passes gets a token. Your server sends the token to Cloudflare, which answers success: true or false. There's no score and no threshold to tune.
reCAPTCHA v2 runs Google's risk analysis when the visitor ticks "I'm not a robot" or, in invisible mode, clicks your submit button. Trusted visitors pass straight through; the rest get a challenge, usually an image grid. reCAPTCHA v3 never challenges anyone. It returns a score from 0.0 (very likely a bot) to 1.0 (very likely good), and you decide what to do with it. Google suggests starting at 0.5. More in reCAPTCHA v2 vs v3.
In April 2026 Google launched Google Cloud Fraud Defense, a broader fraud platform with reCAPTCHA as its bot-defense core. Existing site keys and integrations keep working with no migration and no price change.
Visitor friction and accessibility
Turnstile's three widget modes:
- Managed (recommended) runs the checks in the background and shows a checkbox only to riskier visitors. There are no images or text to decipher.
- Non-interactive shows a small widget with a spinner. Nobody has to click.
- Invisible shows nothing. Cloudflare requires your privacy policy to reference its Turnstile privacy addendum if you use it.
reCAPTCHA's three:
- v2 checkbox: tick the box, then an image challenge if Google isn't sure.
- v2 invisible: no checkbox; the check runs on your button, and a challenge can still appear.
- v3: no interaction. A badge shows on the page, which you may hide if the form says "This site is protected by reCAPTCHA."
Cloudflare states Turnstile meets WCAG 2.2 AA (its plans page says AAA). With no puzzle, screen reader users get the same flow as everyone else. reCAPTCHA v3 has nothing to solve either, but the friction moves to your code: when a real visitor scores low, v3 has no challenge to fall back on, so you have to build one, such as email verification. With v2, the fallback is the image puzzle people are trying to get rid of.
Privacy and data use
Turnstile. Cloudflare's privacy addendum lists what Turnstile processes: IP address, TLS fingerprint, user agent, and the sitekey and origin, used to detect bots rather than to identify or profile anyone. Cloudflare says Turnstile never uses cookies to collect or store information, and its docs say it doesn't access form entries.
reCAPTCHA. It sets a _GRECAPTCHA cookie, which Google calls necessary for its risk analysis. Since April 2, 2026, Google says it acts as a data processor for reCAPTCHA under the Google Cloud terms, with you as the sole controller; before, it treated itself as an independent controller. It also dropped the Privacy Policy and Terms links from the badge and recommends sites remove those references. If your privacy policy describes reCAPTCHA the old way, update it.
Both vendors still receive visitors' IP addresses and browser details. Whether either belongs behind your cookie banner depends on your setup and jurisdiction, so ask whoever owns your privacy policy. Turnstile gives you less to explain.
Pricing and free tier (checked October 2026)
Turnstile (plans):
- Free: unlimited challenges, up to 20 widgets, 10 hostnames per widget, 7 days of analytics.
- Enterprise: contact sales. Unlimited widgets, up to 200 hostnames per widget, any-hostname widgets, removable branding, 30 days of analytics.
reCAPTCHA (tiers):
- Free: 10,000 assessments per calendar month, shared by every site, key, and project in your organization.
- Premium (applied when you enable billing): $8 flat for 10,001 to 100,000 assessments a month, then $1 per 1,000.
- Enterprise: a 12-month commitment at $1 per 1,000.
The free tier has a catch that matters for spam. Without billing, once your organization passes 10,000 assessments in a month, Google's migration docs say the CreateAssessment API returns a 429 error, but legacy siteverify calls fail open: they return success: true with a score of 0.9, plus a quota error message. Code that reads only success and score lets everything through until the next month.
Do you need a Cloudflare account or proxy?
You need a free Cloudflare account to create the widget. You don't need Cloudflare DNS, the proxy, or the CDN; Cloudflare says Turnstile can be embedded in any website without sending traffic through it. On WordPress, Contact Form 7 has a built-in Turnstile integration and Gravity Forms has an official add-on.
reCAPTCHA keys now all live in Google Cloud projects. Google stopped issuing classic keys and finished moving them into Cloud projects in early 2026.
Setup: the minimal code for each
Both work the same way: a script puts a token in your form, and your server checks it with the vendor before accepting the submission. The server half is what protects the form. In Cloudflare's words, "The client-side widget alone does not protect your forms."
Turnstile
In the Cloudflare dashboard, open Turnstile, click Add widget, add your hostnames, choose Managed, and click Create. Copy the sitekey and secret key.
<script src="https://challenges.cloudflare.com/turnstile/v0/api.js" async defer></script>
<form action="/contact" method="POST">
<input name="email" type="email" required>
<textarea name="message" required></textarea>
<div class="cf-turnstile" data-sitekey="YOUR_SITE_KEY"></div>
<button type="submit">Send</button>
</form>
The widget adds a hidden cf-turnstile-response field. On the server (Node 18+, Express):
app.use(express.urlencoded({ extended: false }));
app.post("/contact", async (req, res) => {
const token = req.body["cf-turnstile-response"];
if (!token) return res.status(400).send("Verification missing");
const check = await fetch("https://challenges.cloudflare.com/turnstile/v0/siteverify", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
secret: process.env.TURNSTILE_SECRET_KEY,
response: token,
remoteip: req.ip, // optional
}),
});
const result = await check.json();
if (!result.success) return res.status(400).send("Verification failed");
// Valid: store or forward the submission here.
res.redirect("/thanks");
});
Siteverify accepts JSON or form-encoded bodies, POST only. A reused or expired token fails with timeout-or-duplicate.
reCAPTCHA (v2 checkbox)
Create a key on the reCAPTCHA page of the Google Cloud console. The classic siteverify endpoint uses the key's legacy secret key, also shown there.
<script src="https://www.google.com/recaptcha/api.js" async defer></script>
<form action="/contact" method="POST">
<input name="email" type="email" required>
<textarea name="message" required></textarea>
<div class="g-recaptcha" data-sitekey="YOUR_SITE_KEY"></div>
<button type="submit">Send</button>
</form>
app.post("/contact", async (req, res) => {
const token = req.body["g-recaptcha-response"];
if (!token) return res.status(400).send("Verification missing");
const check = await fetch("https://www.google.com/recaptcha/api/siteverify", {
method: "POST",
body: new URLSearchParams({
secret: process.env.RECAPTCHA_SECRET_KEY,
response: token,
remoteip: req.ip, // optional
}),
});
const result = await check.json();
if (!result.success) return res.status(400).send("Verification failed");
// v3: also require result.action === "contact" and result.score >= 0.5
res.redirect("/thanks");
});
Google's newer server API, CreateAssessment, is a POST to https://recaptchaenterprise.googleapis.com/v1/projects/PROJECT_ID/assessments?key=API_KEY with the token, site key, and expected action; you then check tokenProperties.valid and riskAnalysis.score. It fails closed when you're over quota, which is safer.
Migrating from reCAPTCHA to Turnstile
Turnstile has a reCAPTCHA compatibility mode. Load its script with ?compat=recaptcha and Turnstile registers itself as grecaptcha, renders reCAPTCHA markup, and fills a g-recaptcha-response field, so most front-end code keeps working.
- Create a Turnstile widget and copy its keys.
- Replace Google's script with
https://challenges.cloudflare.com/turnstile/v0/api.js?compat=recaptcha. - Swap in the Turnstile sitekey, in
data-sitekeyor eachgrecaptcha.render()call. - On the server, point verification at Turnstile's siteverify URL with the Turnstile secret, as a
POST. reCAPTCHA acceptsGETwith query parameters; Turnstile doesn't. - Remove any score threshold.
Compatibility mode covers reCAPTCHA v2, including invisible mode through execute(). v3 code needs rewriting around a pass or fail result.
Which one actually stops form spam?
Most comparisons stop at friction and privacy. What you care about is what reaches your inbox.
What both stop: bots that post without a valid token, as long as your server rejects them. A bot then has to run a real browser that passes the checks, or pay someone to pass them.
How both get bypassed. Each of these lets spam through with either widget installed:
- The server never checks the token. Bots skip your page and post straight to the endpoint.
- The endpoint accepts posts without a token. Code that verifies only "if a token is present", or a second handler nobody wired up, is a side door.
- Verify errors count as passes. A
catchthat accepts the submission when siteverify times out is a free pass. - v3 scores aren't enforced. Checking
successwithoutscoreandactionaccepts a bot's token too. - reCAPTCHA runs over quota without billing, and legacy siteverify returns 0.9 for everyone.
- Solves are for sale. 2Captcha's homepage lists reCAPTCHA v2, v3, and Turnstile, each under $3 per 1,000 solves (checked October 2026).
What neither stops: people. Turnstile never sees form entries, and reCAPTCHA scores the interaction, not the message. When an SEO agency, link seller, recruiter, or dev shop fills in your form by hand, they pass like any real visitor and the pitch lands in your inbox. So does a fake sign-up typed with a throwaway address. That's why reCAPTCHA often doesn't stop spam, and switching to Turnstile won't change it. Stopping it means screening the submission itself (how to stop sales pitches from your contact form).
Which should you choose?
Choose Turnstile for most sites: free with no request cap, no image puzzle, no Google Cloud project or billing, any host, and a compatibility mode that keeps most v2 code working.
reCAPTCHA still makes sense when:
- You use v3 scores to respond in steps, such as asking low scorers to verify their email. Turnstile is pass or fail.
- You want Google's fraud features, such as password defense, SMS defense, and carding detection on Premium and Enterprise.
- Your form tool only supports reCAPTCHA.
- It already works: verified on the server, well under 10,000 assessments a month. Since both stop the same spam, switching mostly changes what visitors go through, not what reaches your inbox.
Weighing other widgets too? See reCAPTCHA alternatives.
Or skip the widget and screen the submission
GoodInbound Lead Screen has no widget at all. Add one script tag to the form you already have (HubSpot, Marketo, Webflow, WordPress, Framer, or plain HTML), or use GoodInbound's hosted forms and headless endpoint. Each submission is checked in order: your own rules, then behavior (fill time, typing cadence, pastes, pointer or touch input, automation tells, a honeypot, all collected invisibly), network (datacenter IPs, VPNs, proxies, Tor, bursts from one IP), identity (the mail server, disposable and role addresses, domain age, gibberish), and context, the message check that reads the whole message against what you sell and catches sales pitches, recruiting, and link building.
Every submission gets a label (lead, review, spam, junk, or bot) and a one-line reason. Nothing is deleted, so a real lead screened out by mistake is one click from rescue, and corrections teach the screen. You choose which labels notify you, and only real leads sync on to your CRM and to Google Ads, Meta, and LinkedIn as conversions.
The free plan screens 500 submissions a month with rules, behavior, network, and identity; it doesn't read the message. The message check is part of Pro, $29 a month for 2,500 submissions (pricing). Paste a recent pitch into the free form spam checker to see its label. More in how to stop contact form spam without a CAPTCHA and the contact form spam guide.
FAQ
Is Turnstile better than reCAPTCHA?
For most websites, yes. It's free with unlimited challenges, never shows an image puzzle, and needs no Google Cloud project. reCAPTCHA fits better if you depend on v3 scores or Google's fraud features. Neither stops spam typed by a person.
Is Turnstile a CAPTCHA?
Cloudflare calls it a CAPTCHA alternative. It does the same job, telling browsers from bots, with background challenges instead of a puzzle. At most, a visitor ticks a checkbox.
Is Cloudflare Turnstile really free?
Yes. The Free plan has unlimited challenges, up to 20 widgets, and 10 hostnames per widget (checked October 2026). Enterprise adds more widgets and hostnames, branding removal, and longer analytics.
Can I use Turnstile without moving my DNS to Cloudflare?
Yes. You need a free Cloudflare account for the keys, but your DNS, hosting, and traffic stay where they are.
Do I need a cookie banner for Turnstile or reCAPTCHA?
Cloudflare says Turnstile doesn't use cookies to collect information. reCAPTCHA sets a _GRECAPTCHA cookie Google calls necessary, and Google has acted as a data processor for it since April 2, 2026. Whether your banner must cover either depends on your setup and jurisdiction.
Is reCAPTCHA outdated?
No, but it's changing. In April 2026 Google made it part of Google Cloud Fraud Defense, and existing keys kept working. What feels dated is the v2 image puzzle, which is why many sites move to v3, Turnstile, or screening with no widget.
What's the difference between CAPTCHA and reCAPTCHA?
CAPTCHA is the general term for a test that tells people from bots. reCAPTCHA is Google's product; Turnstile and hCaptcha are alternatives to it.