Is CAPTCHA costing you customers? What the research actually shows
Many businesses add a CAPTCHA to their contact form to stop spam, and never find out how many real customers it turns away. A customer who gives up leaves no trace: no error, no email, no complaint. Here is what independent research has actually measured.
The short answer
Yes, measurably. In a 2023 study of 1,400 people, participants solved image CAPTCHAs correctly only 71–81% of the time, and in a follow-up test 30% of the people who started gave up before finishing [1]. Meanwhile, bots solve the same kinds of CAPTCHA with 85–100% accuracy [1]. A CAPTCHA can turn away real customers while stopping fewer bots than you expect.
The problem nobody sees
A CAPTCHA looks like a success from the inside. Spam goes down, and your form keeps working when you test it yourself. What you can't see is the customer on a phone who got "select all squares with traffic lights" wrong twice, gave up, and called a competitor instead.
Your website doesn't record that moment. Analytics count the messages that were sent, not the people who tried and failed. That is why the cost of a CAPTCHA is so easy to underestimate, and why the research below matters.
What the research found about real people
People get them wrong
In the largest recent study, run by researchers from UC Irvine, ETH Zürich and Microsoft and published at USENIX Security 2023, 1,400 people solved 14,000 real CAPTCHAs taken from popular websites. They picked the right images in Google's reCAPTCHA about 81% of the time, and in hCaptcha between 71% and 81%, getting worse on the harder setting. For distorted-text CAPTCHAs, participants agreed on the answer only 50–84% of the time [1]. A Stanford study back in 2010 found the same pattern: three people agreed on a text CAPTCHA only 71% of the time, and on an audio CAPTCHA only 31% of the time [3].
They take time, at the worst possible moment
Image CAPTCHAs took people 15–26 seconds, hCaptcha 18–32 seconds and slider puzzles around half a minute, compared with 3–5 seconds for a simple checkbox [1]. Cloudflare, which sees a large share of the world's web traffic, measured an average of 32 seconds per CAPTCHA [4]. For a customer who has just written you a message, that is 30 seconds of being asked to prove they aren't a machine.
They give up
The 2023 team ran a separate test to measure abandonment. Of 574 people who started, 174, or 30%, did not finish. In some groups, between 18% and 45% gave up as soon as the first CAPTCHA appeared, and people were 120% more likely to quit when the CAPTCHA appeared during a realistic task, creating an account, than when solving CAPTCHAs was the task itself [1]. These participants were being paid to finish. A customer on your website has no such reason to persist.
Some customers are hit harder than others
- Older visitors: solving time rose with age, by 0.09 seconds per year of age on average across all CAPTCHA types [1].
- People outside the US: in the Stanford study, participants outside the US took longer on English-language CAPTCHAs [3]. That matters in the UAE and the wider region, where many customers read English as a second language.
- People with disabilities: W3C states that every type of CAPTCHA will be impossible to solve for users with certain disabilities [5]. See CAPTCHA and accessibility.
Meanwhile, bots are better at it than your customers
CAPTCHAs were designed in 2003 as tasks easy for people and hard for computers. Twenty years of machine learning have reversed that. The 2023 study compared its human results with the best published attacks on each CAPTCHA type [1]:
| CAPTCHA type | People | Bots |
|---|---|---|
| Distorted text | 50–84% correct, 9–15 seconds | 99.8% correct, under 1 second |
| reCAPTCHA checkbox | 71–85%, 3–5 seconds | 100%, 1.4 seconds |
| reCAPTCHA images | 81%, 15–26 seconds | 85%, 17.5 seconds |
| hCaptcha | 71–81%, 18–32 seconds | 98%, 15 seconds |
And when software can't solve a CAPTCHA, spammers pay people to. Researchers at UC San Diego found CAPTCHA-solving services selling solutions for around one dollar per thousand [6]. The authors of the 13-month reCAPTCHA study concluded that it offers little real security for its cost, and that it should be retired [2].
Put the two together and the result is uncomfortable: a CAPTCHA stops cheap, simple bots, which invisible checks stop just as well, while determined spammers pay their way past it, and your real customers are the ones left solving puzzles.
An older real-world test on business websites
In 2009, Moz published a test across its clients' websites comparing periods with a CAPTCHA switched on and off [7]. With the CAPTCHA on, spam fell by 88%, from 91 spam messages to 11. But 159 submissions failed, against none with the CAPTCHA off. Spam plus failed submissions made up 7.3% of all submissions with the CAPTCHA, against 4.1% spam without it.
Two honest caveats: that test used the old distorted-text CAPTCHAs, and some of the 159 failures may have been bots. It is still one of the few published tests on real business forms, and its direction matches every study since.
What this means for your contact form
Nobody can tell you exactly how many enquiries your own CAPTCHA costs. That depends on your customers, your form and the CAPTCHA's settings, which is why you should measure it on your own website. What the research makes clear is the direction and the scale: some real people fail, some give up, and the ones who give up leave no trace.
A simple way to think about it: if your form brings 40 enquiries a month and the CAPTCHA turns away even 1 in 20 people who would have written to you, that is two lost enquiries every month, 24 a year, each one a customer who had already decided to contact you. For most businesses, one of those is worth more than a year of any spam protection.
What to do instead
You don't have to choose between spam and customers. Invisible checks on your own server stop automated spam without asking your visitors anything:
- A hidden trap field that bots fill in and people never see.
- A minimum time before sending, because bots send instantly.
- A signed one-time token, so the form only accepts submissions started on your page.
- Link rules and a rate limit against link spam and floods.
If you want one visible step, make it one a person can't fail, like a slide to send with a keyboard alternative. The 2023 study found people generally preferred slider and game-style checks over image grids [1]. More in the best alternatives to CAPTCHA and how CAPTCHA works, and why bots beat it.
Common questions
Are these studies really about contact forms?
Not exactly. The large studies measured CAPTCHAs on account creation, password recovery and CAPTCHA tasks [1][2]. A contact form is the same situation: a person who has already decided to act meets a puzzle at the moment of sending. The one business-website test we know of, Moz’s, points the same way [7].
Does reCAPTCHA v3, the invisible one, avoid the problem?
Partly. Version 3 shows no puzzle and gives each visitor a score instead; the website decides what to do with low scores. It still loads Google’s scripts, around 400 KB on a first visit in one measurement [2], sends visitor data to Google, and researchers have shown attacks that obtain high "human" scores [2]. Real visitors with low scores can still be blocked without knowing why.
Why don’t I see lost customers in my analytics?
Because nothing is recorded when someone gives up. Analytics count messages sent. To see the gap, compare how many people start your form with how many send it. Our guide on checking if your CAPTCHA is losing you enquiries shows how.
Do I need a CAPTCHA at all to stop spam?
For a contact form, usually not. Invisible server-side checks (a trap field, a time check, a signed token, link rules and a rate limit) stop almost all automated spam without asking your customers anything.
Sources
Numbers in this guide come from these studies and publications. Links open the original.
- An Empirical Study & Evaluation of Modern CAPTCHAsSearles, Nakatsuka, Ozturk, Paverd, Tsudik, Enkoji (UC Irvine, ETH Zürich, Microsoft). USENIX Security Symposium, 20231,400 participants solved 14,000 CAPTCHAs; 200 popular websites inspected. Participants were paid online workers.
- Dazed & Confused: A Large-Scale Real-World User Study of reCAPTCHAv2Searles, Prapty, Tsudik (UC Irvine), 202313 months, more than 3,600 real users who did not know they were being studied.
- How Good Are Humans at Solving CAPTCHAs? A Large Scale EvaluationBursztein, Bethard, Fabry, Mitchell, Jurafsky (Stanford University). IEEE Symposium on Security and Privacy, 2010More than 1,100 participants, 318,000 CAPTCHAs.
- Humanity wastes about 500 years per day on CAPTCHAs. It’s time to end this madnessCloudflare blog, May 2021Average of 32 seconds per CAPTCHA from Cloudflare’s data; the 500-years figure is Cloudflare’s own rough estimate.
- Understanding Success Criterion 1.1.1: Non-text Content (CAPTCHA)W3C Web Accessibility Initiative (WCAG 2.1)
- Re: CAPTCHAs – Understanding CAPTCHA-Solving Services in an Economic ContextMotoyama, Levchenko, Kanich, McCoy, Voelker, Savage (UC San Diego). USENIX Security Symposium, 2010
- CAPTCHAs’ Effect on Conversion RatesCasey Henry, Moz blog, 2009An older test with text CAPTCHAs; figures as reported by Moz.