What is CAPTCHA?
CAPTCHA is a small test that tells humans and bots apart. It may ask you to type distorted letters or tick a box. Bots fail the test, so they cannot fill in your forms.
Magento is an online store platform. Its menus differ a little between versions, so look for the names below. If you cannot find them, your version may be different.
Option 1: Built-in image CAPTCHA
This option shows letters in an image. It is available in many Magento versions.
- Log in to your Magento admin panel.
- Click Stores, then Configuration.
- Open Customers, then Customer Configuration.
- Open the CAPTCHA section.
- Set Enable CAPTCHA in Admin to Yes if you want it on the admin login.
- Set Enable CAPTCHA on Storefront to Yes.
- In Forms, select the forms to protect. Examples are Create user, Login and Forgot password.
- Choose how many characters and which symbols the image uses. Short and simple is friendlier for visitors.
- Click Save Config.
- Clear the cache. Go to System, then Cache Management, and click Flush Magento Cache.
Option 2: Google reCAPTCHA
Newer Magento 2 versions (2.4 and later) support Google reCAPTCHA. It often only asks the visitor to tick a box.
- Sign in to the Google reCAPTCHA website with a Google account.
- Register your site. Pick the type your Magento version supports, such as v3 or v2 checkbox.
- Add your domain name. Google gives you a site key and a secret key.
- In Magento, go to Stores, then Configuration, then Security.
- Open Google reCAPTCHA Storefront.
- Paste your keys into the key fields.
- Under Storefront, choose which forms use reCAPTCHA.
- Click Save Config and flush the cache.
Test it
- Open your store in a private browser window.
- Go to the login or contact form you protected.
- Check that the CAPTCHA shows up and works.
If it does not appear, flush the cache again. If it still fails, check for a clash with another extension. You can also open a support ticket.
Quick recap
- CAPTCHA stops bots from filling in your forms.
- Built-in CAPTCHA is under Stores, Configuration, Customers.
- Google reCAPTCHA is under Stores, Configuration, Security in newer versions.
- Always save and flush the cache.