A reCAPTCHA alternative that blocks bots without making your visitors prove they aren't one
Every CAPTCHA puzzle you put in front of a real visitor is a tax on your conversion rate. Google's own reCAPTCHA v3 leaks every visitor's browsing context back to Google — a GDPR nightmare. SecureSMTP stops bots invisibly with 5 protection layers (honeypot, time-check, signed nonce, optional Cloudflare Turnstile, AI classifier) — your visitors never see a challenge, you don't send data to Google, and bots don't get through. Free forever for 100 submissions/month.
Free forever for 100 submissions / month · no credit card.
Why you should stop using reCAPTCHA
- reCAPTCHA v2 drops conversion by 3–10% per study — every visitor who clicks "I'm not a robot" is a visitor who almost left
- reCAPTCHA v3 sends every visitor's session fingerprint to Google for scoring — illegal under GDPR without explicit consent
- Bots have learned to solve image challenges (puzzle-mill APIs cost less than $1 per 1,000 solves)
- Accessibility: image CAPTCHAs are unreadable for blind users, deaf users can't use the audio fallback
Zero CAPTCHA friction
No checkboxes, no puzzles, no "find the traffic lights". Real visitors never see anything.
No Google handoff
Your forms don't send anything to google.com. GDPR-friendly by default — no consent banner needed for forms.
Better-than-reCAPTCHA bot blocking
Five layers stack: honeypot + timing + signed nonce + optional Cloudflare Turnstile + AI classification. Catches things reCAPTCHA misses, like social-engineering pitch spam.
Questions, answered
How does invisible spam protection work?
Honeypot fields trick bots into filling fields humans never see. Time-checks reject submissions that arrive in under 2 seconds. Signed nonces prove the form was actually rendered. The AI classifier reads the actual content of borderline submissions and decides if it's a real lead or a pitch.
What if a real bot gets through?
We silently respond "success" to the bot (so it can't probe what triggered blocking) and discard the submission. Your inbox stays clean.
Do I need to install Cloudflare Turnstile?
No — it's an optional 5th layer if you want belt-and-suspenders. The other 4 layers handle 99%+ of spam on their own.
Can I migrate from a reCAPTCHA-using form?
Yes — install SecureSMTP, paste API key, replace your old form. You can usually remove the reCAPTCHA plugin entirely once you switch.
Is this GDPR-compliant?
Yes. We don't set cookies on the visitor, don't share data with Google, and we publish a full data inventory at securessmtp.com/privacy.
Related
A no-CAPTCHA contact form that still blocks 99% of spam
Want a contact form with no CAPTCHA — and no spam either? SecureSMTP uses 5 layers of invisible protection. Real visitors submit in one click. Bots get filtered. Free forever for 100/month.
How to remove reCAPTCHA from WordPress without opening the spam floodgates
Step-by-step: how to remove reCAPTCHA from your WordPress site without losing spam protection. Replace it with SecureSMTP — 5 invisible protection layers. Free forever for 100/month.
A modern Contact Form 7 alternative for WordPress sites that actually want their leads
Tired of Contact Form 7's spam, weak deliverability, and no built-in dashboard? SecureSMTP is the drop-in alternative — 5 layers of spam protection and reliable email, free forever for 100 submissions/month.
Ready in five minutes.
Free forever for 100 submissions / month. No credit card, no trial expiry.