Get a free website with any plan

See how
WORDPRESS

Adding reCAPTCHA to a contact form

Last updated

IN SHORT

Google reCAPTCHA stops bot submissions on WordPress contact forms hosted on Flashcloud. Generate a site key and secret key from Google, paste them into your form plugin settings, and enable the CAPTCHA field. Choosing the version matters most: v2 provides a visible checkbox challenge, while v3 scores traffic invisibly in the background.

The fastest way to stop bot submissions on a contact form is Google reCAPTCHA. Get a free site key and secret key from google.com/recaptcha/admin, then drop them into your form plugin's settings. No code required for most setups. Contact Form 7, WPForms, and Gravity Forms all have a built-in reCAPTCHA integration field you enable per form.

reCAPTCHA comes in two flavors that behave very differently, and picking the wrong one is a common mistake.

v2 vs v3: which to use

reCAPTCHA v2 is the "I'm not a robot" checkbox, or the image-grid challenge if Google's risk score is uncertain. It's visible and it interrupts the user, but it's simple to set up and gives a clear pass/fail. Good default if you want obvious spam blocking with no tuning.

reCAPTCHA v3 runs invisibly in the background and returns a score from 0.0 to 1.0 instead of a checkbox. You set a threshold (commonly 0.5) below which the submission is rejected or flagged. There's no user friction, but it needs a bit more configuration. If your threshold is too strict you'll start blocking real visitors with no explanation on the form. If you go this route, log scores somewhere for the first few weeks so you can see what real traffic looks like before you tighten the threshold.

For most small business contact forms, v2 checkbox is the practical choice. It's visible enough to deter casual bots, doesn't require score tuning, and if it's blocking a real person they at least see why.

Setup in Contact Form 7

  1. Install the separate reCAPTCHA integration under Contact → Integration in wp-admin (CF7 doesn't bundle it in the core plugin).
  2. Paste your site key and secret key there.
  3. CF7 applies reCAPTCHA automatically to all forms once the keys are saved. You don't add a shortcode manually in most versions.

Setup in WPForms or Gravity Forms

Both plugins have a dedicated reCAPTCHA settings page (WPForms → Settings → CAPTCHA; Gravity Forms → Settings → reCAPTCHA). Enter the site key and secret key, choose v2 or v3, then add the CAPTCHA field to the specific form from the form editor. Unlike CF7, these plugins apply it per-form, not site-wide. Double check you've actually added the field if submissions are still coming from bots after setup.

If you're not using a form plugin

Custom PHP forms need to call reCAPTCHA manually. Load the client-side script:

<script src="https://www.google.com/recaptcha/api.js" async defer></script>
<div class="g-recaptcha" data-sitekey="YOUR_SITE_KEY"></div>

Then on form submit, verify the token server-side before processing the mail:

$response = wp_remote_post('https://www.google.com/recaptcha/api/siteverify', [
    'body' => [
        'secret'   => 'YOUR_SECRET_KEY',
        'response' => $_POST['g-recaptcha-response'],
    ],
]);
$result = json_decode(wp_remote_retrieve_body($response), true);
if (empty($result['success'])) {
    // reject the submission
}

Never trust the token client-side only. The checkbox rendering in the browser proves nothing by itself. The siteverify call is what actually confirms the submission with Google.

If the form still isn't reaching you after adding reCAPTCHA

reCAPTCHA only stops the submission from being accepted as spam. It doesn't fix delivery. If real submissions pass the CAPTCHA but the email never lands in your inbox, that's a separate mail delivery problem, usually WordPress's default wp_mail() getting filtered by the receiving server. See Contact form emails not arriving (WordPress SMTP fix) for the authenticated SMTP fix.

When to contact support

reCAPTCHA setup itself is on the WordPress and plugin side. If you're not sure whether a delivery issue is a reCAPTCHA misconfiguration or a server-side mail problem, open a ticket from the portal (Support → New ticket) and a real person can help you narrow it down.

Common questions

Should I use reCAPTCHA v2 or v3 on my contact form?

Choose reCAPTCHA v2 for most small business forms. It gives visitors a clear checkbox pass-fail test and needs no score tuning. Version 3 runs invisibly, but it requires testing and traffic logging to avoid blocking real visitors.

Why am I still getting bot submissions in WPForms or Gravity Forms?

The CAPTCHA field is missing from that specific form. WPForms and Gravity Forms do not apply protection site-wide, unlike Contact Form 7. You must open the form editor and add the CAPTCHA field directly to each form.

Why are my contact form emails not arriving after adding reCAPTCHA?

reCAPTCHA stops spam, but it does not manage mail delivery. If valid submissions pass the test but never reach your inbox, WordPress default wp_mail is likely getting filtered by the receiving server. You need to set up authenticated SMTP to fix delivery.

Can I protect a custom PHP form using only the frontend reCAPTCHA script?

No, browser rendering alone does not secure a form. You must verify the token server-side with Google using the siteverify API endpoint before processing the mail. Skipping that backend check leaves the form open to bot submissions.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.