Why this matters
Public forms attract bots that submit fake or junk sign-ups. Those fake addresses hurt your list quality, your deliverability, and your reporting. Adding reCAPTCHA v3 protection keeps your list clean by quietly filtering out automated submissions, without making real subscribers solve a puzzle.
reCAPTCHA on your forms uses your own Google reCAPTCHA keys, so you'll create them in Google first, then paste them into your form's settings.
Before you start
- You need a Google account.
- The form uses reCAPTCHA v3 (not v2). Make sure you create a v3 site in Google, or the keys won't work.
- Have your website domain ready (the domain where the form will be embedded).
reCAPTCHA needs the form on your own domain
reCAPTCHA only validates when the form runs on a domain you've registered in Google. Add it to a form you embed on your own website (Static HTML Code or Dynamic Embed Snippet), and register that domain in the Google console. The Self-Hosted Link is served on the platform's own domain, not yours, so your reCAPTCHA keys can't validate there. Use the Self-Hosted Link for testing or quick sharing, and embed the form on your site for a reCAPTCHA-protected sign-up.
Create your reCAPTCHA keys in Google
-
Go to the Google reCAPTCHA admin console and register a new site.
-
Choose reCAPTCHA v3 as the type.
-
Add the domain(s) where your form will appear.
-
Submit. Google gives you two keys: a Site Key and a Secret Key. Keep this page open, you'll copy both in the next step.
Add your keys to the form
-
In the left menu, go to Audience Building ▸ Forms and open your form.
-
In the form settings panel, expand Recaptcha (Recommended).
-
Paste your Site Key into the Site Key field and your Secret Key into the Secret field.
-
Publish the form. reCAPTCHA stays inactive until the form is published with valid keys.
"Recaptcha error" when a form is submitted
The most common reCAPTCHA problem is a submission that is rejected with a response like this:
Code
It means the submission reached the server but its reCAPTCHA check failed, so the contact is not added to your list. Here are the frequent causes and how to fix each one.
The submission carried no valid reCAPTCHA token
This is the usual cause. Only a real page load of the published form generates a reCAPTCHA token. You'll get the error if you:
- open the Submission URL (or the raw
form_submissionendpoint) directly in a browser to "test" it, or - post to that endpoint from a custom integration without first generating a reCAPTCHA v3 token.
Fix: submit through the published form instead (the Self-Hosted Link, the Dynamic Embed Snippet, or the Static HTML Code on your registered domain). For a custom integration, generate a reCAPTCHA v3 token on the page and send it with the submission.
The domain isn't registered in Google
If the page hosting the form isn't listed on your reCAPTCHA v3 site, Google won't issue a token that passes verification.
Fix: in the Google reCAPTCHA console, add the exact domain (and any subdomain) where the form runs. If you moved the form to a new domain, add that one too. Note that the Self-Hosted Link runs on the platform's domain, not yours, so your keys never match there; embed the form on your own site instead.
The reCAPTCHA script didn't load
Ad blockers, privacy extensions, a strict Content-Security-Policy, or simply being offline can block Google's script, so no token is generated.
Fix: test in a clean browser with extensions turned off, and allow the Google reCAPTCHA script in your site's Content-Security-Policy.
The token expired or was reused
reCAPTCHA v3 tokens are single-use and short-lived. A cached page, a very slow submission, or submitting twice can send a stale token.
Fix: reload the form and submit again right away.
The keys are wrong or mismatched
v2 keys on a v3 form, the Site Key and Secret swapped, or keys copied from a different reCAPTCHA site will all fail verification.
Fix: use v3 keys, re-copy them from the Google console (a missing or extra character breaks them), and confirm each key is in the correct field.
Other things to check
reCAPTCHA still shows as "inactive"
- Make sure you clicked Publish after entering the keys. Changes only take effect once the form is published.
- Confirm both the Site Key and Secret fields are filled in.
The form works in preview but not on your website
- In the Google reCAPTCHA console, confirm the domain where the form is embedded is listed for that site.
Bots are still getting through
- reCAPTCHA v3 scores traffic rather than blocking it outright. Combine it with double opt-in on your form for stronger protection.
If the submission still fails after checking all of the above, contact our Support team with the exact error message and the domain where the form is running.
Related articles
- Creating a form - Build and publish the form
- Configuring opt-in emails - Add double opt-in confirmation
- Create and manage a contact list - Where submissions go