A reCAPTCHA v3 score is a number from 0.0 to 1.0 that Google reCAPTCHA returns for each interaction on a website. A score of 1.0 means the interaction is very likely good, and 0.0 means it is very likely a bot. Google suggests 0.5 as a default threshold. The website decides what your score allows or blocks.
Google does not publish the signals behind the score. The causes of a low score described on this page are commonly reported factors. They are not a list documented by Google.
What is a good reCAPTCHA v3 score?
A good score is any score at or above the threshold the site has set. Google's reCAPTCHA v3 documentation says "By default, you can use a threshold of 0.5" (as of September 2026). On a site that uses the default, 0.7 or 0.9 passes and 0.3 fails.
No score is good everywhere. The scale only means something next to the threshold, and every site sets its own. A 0.6 passes a relaxed contact form and fails a login that requires 0.7.
A score on a test page does not predict your score anywhere else. Google's docs say scores in staging, or soon after a site adds reCAPTCHA, can differ from production because reCAPTCHA learns from the real traffic on that specific site. A quiet demo page lacks the production traffic a busy store has, so a high score there says little about that store.
What does a website do with your reCAPTCHA score?
The site's server sends your token to Google and gets back the score and the action name. The server then applies the site's own rule. Google tells sites to take variable action based on context and to act behind the scenes rather than blocking outright. A low score can therefore lead to several outcomes:
- an extra verification step
- a checkbox or image challenge
- a comment held for moderation
- a silent flag you never see
Sites also name each place reCAPTCHA runs, such as login, checkout or homepage. Google uses those names in two ways:
- The admin console shows a per-action breakdown for the site's top ten actions.
- Risk analysis adapts to each action.
As a result, your score on a login form can differ from your score on the homepage you loaded a few seconds earlier.
Tokens expire two minutes after they are issued. Suppose a page generates its token when it loads and you take five minutes to fill in the form. Verification then fails whatever your score was. From your side it can look the same as being rejected for a low score, which is why some "low score" reports are really expired tokens.
Why is my reCAPTCHA score low?
Google keeps the inputs private. The factors below are the ones people commonly report and observe. Treat them as likely contributors, not as confirmed weights.
Shared VPN or datacenter IP
Commercial VPN exits and cloud server ranges carry traffic from many unrelated users, and some of those users run automation. Reputation systems tend to rate those ranges poorly. The Scamalytics fraud score and the IPQualityScore fraud score are related scores that grade the IP itself. They are separate from reCAPTCHA, which grades the whole interaction. To see how your current address is classified, the IP Type Checker shows whether it reads as mobile, residential, datacenter or VPN.
A fresh browser with no history
A new profile, a private window or a cleared browser has no cookies and no signed-in Google state. It is widely reported to score lower than a long-used browser that is signed in to a Google account. Nothing is wrong with a fresh browser. It simply has less history for the system to go on.
Blocked scripts or cookies
Strict tracker blocking, script blockers and extensions that break Google domains can stop reCAPTCHA from collecting what it expects. The result is often a low score, or a token that never arrives. The Browser Fingerprint Test shows what your browser exposes: canvas, WebGL, fonts and more.
Automation
Headless browsers, driver flags, instant form fills and perfectly regular timing are the patterns bot detection is built to find. A clean IP does not reliably offset them.
Does a mobile proxy raise a reCAPTCHA v3 score?
A mobile proxy can improve the IP input, but it does not fix a fresh browser profile or automation patterns, because reCAPTCHA v3 scores the whole interaction. VoidMob provides mobile proxies on real 4G/5G devices, non-VoIP SMS verification and eSIM. Every VoidMob proxy exit is a real device on a consumer carrier connection. Its public IPv4 address sits behind the carrier's CGNAT, so it is shared with that carrier's ordinary subscribers. IP databases usually classify such an address as mobile rather than as a VPN or hosting range, though no reputation system is guaranteed to rate any IP well.
A mobile proxy does not give a browser any history, cookies or signed-in state. A fresh profile still looks fresh. A scripted session still behaves like a script. If you run automated collection, the mobile proxies for web scraping page covers the IP side. Pages protected by reCAPTCHA v3 score the whole session, not just the address it comes from.
How can you check your own reCAPTCHA v3 score?
Google runs a demo site at recaptcha-demo.appspot.com with a "Request scores" page. It returns a score and the full verification response, but Google notes on the page that the score "is not a reflection on your Google account or type of traffic." Third-party v3 test pages work the same way. Use them for side-by-side comparisons, never as a verdict.
Read the result as a relative measure, because the test page's traffic model is not the model of the site you care about. Useful comparisons:
- The same browser with the VPN on and then off.
- Your everyday profile against a private window.
- Extensions enabled against extensions disabled.
If the score only drops under one condition, you have found your likely cause. For a combined check of IP, fingerprint, WebRTC and location in one pass, run the Platform Trust Score.
How should site owners pick a reCAPTCHA v3 threshold?
Start with Google's 0.5 default, then set thresholds for each action instead of one site-wide number. Follow these steps:
- Name every action.
- Collect production traffic before you enforce anything.
- Read the per-action breakdown in the admin console.
Do not tune thresholds in staging, since Google says those scores may differ from production.
| Action | Cost if a bot gets through | Starting approach |
|---|---|---|
| Homepage or page view | Low | Log the score only; no threshold |
| Contact or signup form | Medium (spam) | 0.5; send low scores to moderation |
| Login | High (account takeover) | Low score triggers an extra verification step |
| Checkout or payment | High (fraud losses) | Low score goes to review, not a hard block |
Two configuration details prevent most false rejections:
- Request the token when the user submits, not when the page loads. Tokens last two minutes, and long forms outlast them.
- Check the returned action name against the action you expected. A token issued for
homepageshould not verify alogin.
What is a good score for reCAPTCHA v3?
Any score at or above the threshold the site sets. Google's documented default is 0.5, so scores around 0.5 and above pass a site using the default. Sites with high-risk actions such as logins may set a stricter bar, so an acceptable score on one site can fail on another.
What does a low CAPTCHA score indicate?
A low reCAPTCHA v3 score means Google rated the interaction as more likely automated. Google does not publish the reasons. Commonly reported causes include a VPN or datacenter IP, a fresh browser with no cookies, blocked scripts and automation patterns.
Which reCAPTCHA is better, v3 or v2?
reCAPTCHA v2 asks the user to tick a box or solve an image challenge. reCAPTCHA v3 runs with no challenge and returns a score. v3 keeps friction off legitimate users but leaves the decision to the site. A common pattern is to run v3 first and show a challenge only when the score is low.
What happens if you fail a CAPTCHA test?
With reCAPTCHA v3, Google returns a score, not a human-or-bot verdict; its success field only says whether the token was valid. The site decides what happens next. You might see a challenge or an extra verification step, have a post held for review, or be flagged with no visible change. An expired token, which lasts two minutes, can fail verification regardless of your score.
Browse from a real carrier IP
Mobile proxies on real 4G/5G devices behind carrier CGNAT: dedicated devices or pay-per-GB from $2.50/GB.