You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

reCaptcha V2仍遭垃圾信息侵扰,急求解决方案

reCaptcha V2 无法拦截垃圾信息求助

此前日均仅1条垃圾信息,刚过去的周末突然收到75条,reCaptcha V2完全没拦住。翻了大量帖子也没找到解决办法,附上表单提交、PHP处理、JS交互的代码,求帮忙排查。

表单提交代码

<div class="form-group">
    <div class="g-recaptcha" data-sitekey="MYSITE-KEY" data-callback="verifyRecaptchaCallback" data-expired-callback="expiredRecaptchaCallback"></div>
    <input class="form-control d-none" data-recaptcha="true" required data-error="Please complete the Captcha">
    <div class="help-block with-errors"></div>
</div>

Contact PHP 代码

<?php

require('recaptcha-master/src/autoload.php');

$from = 'Contact form <EMAIL>';

$sendTo = 'Contact form <EMAIL>';

$subject = 'New message from Customer';

$fields = array('name' => 'Name', 'surname' => 'Surname', 'need' => 'Need', 'email' => 'Email', 'message' => 'Message', 'tel' => 'Telephone Number' , 'add' => 'Address' , 'comp' => 'Company Name', 'product' => 'Product'); 

$okMessage = 'Contact form successfully submitted. Thank you, I will get back to you soon! <br> You\'ll be redirected in about 5 secs. If not, click <a href="Return to site">Here.</a>.';

header( "refresh:5;url=http://www..php" );

$errorMessage = 'There was an error while submitting the form. Please try again later';

$recaptchaSecret = 'SECRET-KEY';

error_reporting(E_ALL & ~E_NOTICE);

try {
    if (!empty($_POST)) {

        if (!isset($_POST['g-recaptcha-response'])) {
            throw new \Exception('ReCaptcha is not set.');
        }
  
        $recaptcha = new \ReCaptcha\ReCaptcha($recaptchaSecret, new \ReCaptcha\RequestMethod\CurlPost());
        
        $response = $recaptcha->verify($_POST['g-recaptcha-response'], $_SERVER['REMOTE_ADDR']);

        if (!$response->isSuccess()) {
            throw new \Exception('ReCaptcha was not validated.');
        }
        
        $emailText = "You have a new message from your contact form\n=============================\n";

        foreach ($_POST as $key => $value) {
            // If the field exists in the $fields array, include it in the email
            if (isset($fields[$key])) {
                $emailText .= "$fields[$key]: $value\n";
            }
        }
    
$customerEmail = filter_var($_POST['email'] ?? null, FILTER_SANITIZE_EMAIL);


if (!filter_var($customerEmail, FILTER_VALIDATE_EMAIL)) {
    $customerEmail = null; // Invalid email, set to null
}


$headers = array('Content-Type: text/plain; charset="UTF-8";',
    'From: ' . $from,
    'Return-Path: ' . $from,
);


if ($customerEmail) {
    $headers[] = 'Reply-To: ' . $customerEmail;
}

        mail($sendTo, $subject, $emailText, implode("\n", $headers));

        $responseArray = array('type' => 'success', 'message' => $okMessage);
    }
} catch (\Exception $e) {
    $responseArray = array('type' => 'danger', 'message' => $e->getMessage());
}

if (!empty($_SERVER['HTTP_X_REQUESTED_WITH']) && strtolower($_SERVER['HTTP_X_REQUESTED_WITH']) == 'xmlhttprequest') {
    $encoded = json_encode($responseArray);

    header('Content-Type: application/json');

    echo $encoded;
} else {
    echo $responseArray['message'];
}

Contact JS 代码

$(function () {

    window.verifyRecaptchaCallback = function (response) {
        $('input[data-recaptcha]').val(response).trigger('change')
    }

    window.expiredRecaptchaCallback = function () {
        $('input[data-recaptcha]').val("").trigger('change')
    }

    $('#contact-form').validator();

    $('#contact-form').on('submit', function (e) {
        if (!e.isDefaultPrevented()) {
            var url = "contact-us.php";

            $.ajax({
                type: "POST",
                url: url,
                data: $(this).serialize(),
                success: function (data) {
                    var messageAlert = 'alert-' + data.type;
                    var messageText = data.message;

                    var alertBox = '<div class="alert ' + messageAlert + ' alert-dismissable"><button type="button" class="close" data-dismiss="alert" aria-hidden="true">&times;</button>' + messageText + '</div>';
                    if (messageAlert && messageText) {
                        $('#contact-form').find('.messages').html(alertBox);
                        $('#contact-form')[0].reset();
                        grecaptcha.reset();
                    }
                }
            });
            return false;
        }
    })
});

排查建议

  • 核对密钥有效性:确认MYSITE-KEY和SECRET-KEY是否匹配,Google reCaptcha控制台里的域名绑定是否正确,有没有误重置密钥。
  • 调严验证阈值:在Google控制台将reCaptcha V2的分数阈值设为0.7以上,过滤疑似机器人的请求。
  • 添加错误码排查:修改PHP里的验证逻辑,输出具体错误码,比如:
    if (!$response->isSuccess()) {
        $errors = $response->getErrorCodes();
        throw new \Exception('ReCaptcha验证失败: ' . implode(', ', $errors));
    }
    
    能快速定位是密钥错误、响应缺失还是其他问题。
  • 添加蜜罐字段:在表单里加一个隐藏的输入框(设置display: none),如果该字段有值则拒绝提交,拦截自动填充的机器人。
  • 更新reCaptcha库:替换成最新版本的reCaptcha PHP库,避免旧版本的兼容性漏洞。
  • 检查服务器IP状态:如果服务器IP被Google标记为可疑,会导致验证失效,可更换IP测试或查看控制台的验证日志。

内容的提问来源于stack exchange,提问作者Zeeba

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 03:17:03