Cloudflare Turnstile: CAPTCHA replacement is still a third party
Cloudflare Turnstile can check bots without classic CAPTCHA tasks. This makes the integration more user-friendly, but not a purely local function.
Prerequisites
Access to the protected form and turnstile configuration; Local spam protection measures should be checked beforehand.
Browser communicates with Cloudflare
The Turnstile widget is integrated via Cloudflare and generates a challenge or a token that is validated on the server side via Siteverify. This means that Cloudflare is technically involved in the test.
Only load where needed
Do not include turnstiles globally on every page if only a single form needs to be protected. For simple forms, consider local honeypot/time/rate limit methods first.
Correctly interpreting scanners
An actual Turnstile network connection is a third-party connection. It is something other than a mere text link to Cloudflare and should be treated separately by the scanner.
Basis
Before using an external challenge service, first check the local options from CAPTCHA and spam protection: first locally, then externally . Only use external services if honeypot, time check, server-side validation and rate limits are not sufficient.
Check
Use browser dev tools to check whether Turnstile is only loaded on the intended form pages and which requests arise before and after the interaction.
Dismantling
If local spam protection is not sufficient, re-enable turnstiles only on the affected forms and check third-party communications again.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
- Cloudflare Turnstile: Get started
- Cloudflare Turnstile: Siteverify
- Cloudflare Turnstile: Widget configurations
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.