reCaptcha V2仍遭垃圾信息侵扰,急求解决方案
reCaptcha V2 无法拦截垃圾信息求助
此前日均仅1条垃圾信息,刚过去的周末突然收到75条,reCaptcha V2完全没拦住。翻了大量帖子也没找到解决办法,附上表单提交、PHP处理、JS交互的代码,求帮忙排查。
表单提交代码
<div class="form-group"> <div class="g-recaptcha" data-sitekey="MYSITE-KEY" data-callback="verifyRecaptchaCallback" data-expired-callback="expiredRecaptchaCallback"></div> <input class="form-control d-none" data-recaptcha="true" required data-error="Please complete the Captcha"> <div class="help-block with-errors"></div> </div>
Contact PHP 代码
<?php require('recaptcha-master/src/autoload.php'); $from = 'Contact form <EMAIL>'; $sendTo = 'Contact form <EMAIL>'; $subject = 'New message from Customer'; $fields = array('name' => 'Name', 'surname' => 'Surname', 'need' => 'Need', 'email' => 'Email', 'message' => 'Message', 'tel' => 'Telephone Number' , 'add' => 'Address' , 'comp' => 'Company Name', 'product' => 'Product'); $okMessage = 'Contact form successfully submitted. Thank you, I will get back to you soon! <br> You\'ll be redirected in about 5 secs. If not, click <a href="Return to site">Here.</a>.'; header( "refresh:5;url=http://www..php" ); $errorMessage = 'There was an error while submitting the form. Please try again later'; $recaptchaSecret = 'SECRET-KEY'; error_reporting(E_ALL & ~E_NOTICE); try { if (!empty($_POST)) { if (!isset($_POST['g-recaptcha-response'])) { throw new \Exception('ReCaptcha is not set.'); } $recaptcha = new \ReCaptcha\ReCaptcha($recaptchaSecret, new \ReCaptcha\RequestMethod\CurlPost()); $response = $recaptcha->verify($_POST['g-recaptcha-response'], $_SERVER['REMOTE_ADDR']); if (!$response->isSuccess()) { throw new \Exception('ReCaptcha was not validated.'); } $emailText = "You have a new message from your contact form\n=============================\n"; foreach ($_POST as $key => $value) { // If the field exists in the $fields array, include it in the email if (isset($fields[$key])) { $emailText .= "$fields[$key]: $value\n"; } } $customerEmail = filter_var($_POST['email'] ?? null, FILTER_SANITIZE_EMAIL); if (!filter_var($customerEmail, FILTER_VALIDATE_EMAIL)) { $customerEmail = null; // Invalid email, set to null } $headers = array('Content-Type: text/plain; charset="UTF-8";', 'From: ' . $from, 'Return-Path: ' . $from, ); if ($customerEmail) { $headers[] = 'Reply-To: ' . $customerEmail; } mail($sendTo, $subject, $emailText, implode("\n", $headers)); $responseArray = array('type' => 'success', 'message' => $okMessage); } } catch (\Exception $e) { $responseArray = array('type' => 'danger', 'message' => $e->getMessage()); } if (!empty($_SERVER['HTTP_X_REQUESTED_WITH']) && strtolower($_SERVER['HTTP_X_REQUESTED_WITH']) == 'xmlhttprequest') { $encoded = json_encode($responseArray); header('Content-Type: application/json'); echo $encoded; } else { echo $responseArray['message']; }
Contact JS 代码
$(function () { window.verifyRecaptchaCallback = function (response) { $('input[data-recaptcha]').val(response).trigger('change') } window.expiredRecaptchaCallback = function () { $('input[data-recaptcha]').val("").trigger('change') } $('#contact-form').validator(); $('#contact-form').on('submit', function (e) { if (!e.isDefaultPrevented()) { var url = "contact-us.php"; $.ajax({ type: "POST", url: url, data: $(this).serialize(), success: function (data) { var messageAlert = 'alert-' + data.type; var messageText = data.message; var alertBox = '<div class="alert ' + messageAlert + ' alert-dismissable"><button type="button" class="close" data-dismiss="alert" aria-hidden="true">×</button>' + messageText + '</div>'; if (messageAlert && messageText) { $('#contact-form').find('.messages').html(alertBox); $('#contact-form')[0].reset(); grecaptcha.reset(); } } }); return false; } }) });
排查建议
- 核对密钥有效性:确认
MYSITE-KEY和SECRET-KEY是否匹配,Google reCaptcha控制台里的域名绑定是否正确,有没有误重置密钥。 - 调严验证阈值:在Google控制台将reCaptcha V2的分数阈值设为0.7以上,过滤疑似机器人的请求。
- 添加错误码排查:修改PHP里的验证逻辑,输出具体错误码,比如:
能快速定位是密钥错误、响应缺失还是其他问题。if (!$response->isSuccess()) { $errors = $response->getErrorCodes(); throw new \Exception('ReCaptcha验证失败: ' . implode(', ', $errors)); } - 添加蜜罐字段:在表单里加一个隐藏的输入框(设置
display: none),如果该字段有值则拒绝提交,拦截自动填充的机器人。 - 更新reCaptcha库:替换成最新版本的reCaptcha PHP库,避免旧版本的兼容性漏洞。
- 检查服务器IP状态:如果服务器IP被Google标记为可疑,会导致验证失效,可更换IP测试或查看控制台的验证日志。
内容的提问来源于stack exchange,提问作者Zeeba
相关产品推荐
相关产品推荐

