What CAPTCHA, Bot Checks & Human Verification covers
This section covers the checks websites use to establish that a visitor is a person rather than an automated program: CAPTCHA puzzles, the “I am not a robot” tickbox, image grids and the invisible checks that run without you noticing.
A CAPTCHA exists to protect the site rather than to inconvenience you, even though the inconvenience is what you experience. Without them, automated programs would create accounts in bulk, post spam, scrape content, buy up limited stock, and attempt stolen username and password combinations against login forms at enormous speed. The check is a speed bump that costs a person a few seconds and costs an automated attack far more.
Modern versions increasingly do not ask you to do anything at all. Rather than a puzzle, they assess signals — how the mouse moved, how the page was loaded, the reputation of the network address — and only present a challenge when something looks unusual. That is why the same site sometimes asks and sometimes does not.
Which explains the most common frustration: repeated CAPTCHAs usually say something about your connection, not about you. A VPN, a shared or corporate network, mobile data on an address used by many people, or an older browser all raise the score that triggers a challenge.
Browse individual used-for guides
Most searched questions in this topic
How the guides in this section differ
Challenge type. Distorted text, image grids, a simple checkbox and fully invisible checks are all CAPTCHAs, differing in what they measure and how much they interrupt.
Bot check or identity check. A CAPTCHA establishes that you are a human being. It does not establish which human being. Proving identity is a different process covered elsewhere in this category.
Site protection or account protection. Some challenges guard a public form against spam. Others appear at login specifically because credential-stuffing attacks are being attempted, which is a different signal entirely.
| What you see | What it is doing | Why it appeared |
|---|---|---|
| “I am not a robot” tickbox | Assessing behaviour around the click | Routine check |
| Image grid | Escalated challenge | Something looked unusual |
| Distorted text | Older style challenge | Older site implementation |
| Nothing visible | Invisible scoring in the background | You passed without noticing |
| Repeated challenges | Your connection scores poorly | VPN, shared network, unusual traffic |
Related topics and alternatives
- Explore Security & Verification Basics
- Explore OTP, 2FA & Authentication Codes
- Explore Security, Privacy & Access Tools
Safety, accuracy and next-step checks
These guides explain what these checks are for and follow official service-provider documentation.
Points worth carrying:
- A CAPTCHA never asks for personal information. A “verification” step requesting your ID number, card details, banking password or a one-time PIN is not a CAPTCHA. It is a phishing page using the appearance of a security check to seem legitimate.
- Check the address bar before completing any check on a login page. Fake login pages carry convincing CAPTCHAs precisely because they make a page feel official.
- Never pay to “remove” CAPTCHAs. Services claiming to do so are not legitimate, and CAPTCHA-solving services exist to serve automated abuse rather than ordinary users.
- Do not install a browser extension that promises to bypass verification. These commonly carry malware or harvest browsing data.
- Repeated challenges are usually your connection. Turning off a VPN, switching networks or updating your browser typically resolves it.
- Accessibility alternatives exist. Most implementations offer an audio challenge for visually impaired users; if a site offers no alternative at all, that is a fault worth reporting to the site.
- Being asked repeatedly on one site only may mean that site has flagged your address. Contacting the site is more effective than repeating attempts.
One last point that catches people out. Because these checks have become so familiar, they have also become a convincing disguise. A page that looks like a routine verification step is an effective way to make a fraudulent site feel official, and criminals use that deliberately. The rule that resolves it is simple and absolute: a genuine bot check asks you to click, tick or identify images. It never asks for an ID number, a card number, a password or a code. The moment a “verification” step asks for any of those, you are not being verified — you are being phished.
Frequently asked questions
Why do I keep getting CAPTCHAs? Usually because of how your connection looks rather than anything you did — a VPN, a shared or corporate network, mobile data on a busy address, or an outdated browser.
What is a CAPTCHA actually for? Preventing automated programs from abusing a site: bulk account creation, spam, scraping, and high-speed attempts at stolen passwords.
A verification page asked for my ID number and card details. Is that normal? No. That is not a CAPTCHA and it is not legitimate. Close the page and go to the organisation’s site directly.
Can I turn CAPTCHAs off? Not as a visitor — the site controls them. Avoiding a VPN and keeping your browser updated reduces how often they appear.
Does passing a CAPTCHA prove who I am? No. It only suggests you are a person. Confirming identity is an entirely separate process.