If your website features Google reCAPTCHA on its forms, as a preventative to spam and bot attacks, these changes may affect you.
Google has recently announced that all Google reCAPTCHA keys will need to be migrated to a Google Cloud project by the end of 2025, bringing a number of updates with it.
Important Changes to Google reCAPTCHA
In this article, we will provide you with a clear understanding of Google’s reCAPTCHA and what these upcoming changes mean for you as the owner of a website that is using it.
What is Google reCAPTCHA?
reCAPTCHA’s purpose is to protect your website from spam and attacks from bots. It is a popular security tool by Google that helps to prevent spam, fraud, and abuse on-site.
reCAPTCHA is a Google product, and is one of several CAPTCHA tools that are available on the market. CAPTCHA stands for ‘Completely Automated Public Turing test to tell Computers and Humans Apart‘.
reCAPTCHA verifies that traffic to your website on your form submissions are human, and not a bot or otherwise illegitimate, and does its best to prevent spam submissions.
What are reCAPTCHA keys?
They are unique codes that must be used to connect your website to Google’s system. They have always been stored on the reCAPTCHA Admin Console, however this is changing from Q4 2025.
What should I expect in 2025?
The upcoming changes relate to reCAPTCHA keys. These ‘keys’ are essentially the validators generated in the background in order for your website to be able to use the tool.
Below is a synopsis of the changes to them and what you should expect.
Mandatory migration
Google will automatically migrate a website’s reCAPTCHA keys to a Google Cloud Project, however as we require your keys to be migrated to a Google Cloud Project in your ownership, you will need to contact us in order to perform this function for you to continue with reCAPTCHA.
A new pricing model
Google has indicated that it will be introducing a pricing model, though minimal costs will only be incurred if reCAPTCHA is triggered more than 10,000 times in any given month.
i.e. reCAPTCHA is usually only triggered once per one form submission.
Do I need to do anything ahead of the migration?
We will require that our clients host their own reCAPTCHA keys to their accounts, or to secure another viable alternative by the deadline, as we will be unable to continue hosting them to our own accounts after the end-of-2025 deadline.
Ahead of the deadline, we will be removing all Google reCAPTCHA keys from our own Google account, which may put your forms at risk of becoming inoperable unless you migrate them to your own Google account or opt for an alternative to Google reCAPTCHA. To ensure your forms continue operating as normal, please get in touch.
Vitamin can assist in migrating your reCAPTCHA keys, or helping you to setup an alternative CAPTCHA to Google’s. Please get in touch with us as soon as possible, and we can provide you with a quote for doing so, to ensure uninterrupted performance of your web forms.
What options are available to me?
Vitamin continues to monitor these and upcoming changes, and will work with current and previous clients towards a workable solution throughout the course of the year.
At present, we have identified the following options to address the change for our clients:
![]()
Reinstall Google reCAPTCHA
You can reinstall Google reCAPTCHA, using your own Google account or the one pertaining to your business, with your own billing details. Please note that by retaining Google reCAPTCHA for your website, you will need a Gmail or Google-hosted email account. If you require our help for this, we may need access to your Gmail account to set this up on your behalf.
For GDPR: Friendly Captcha (starts from €9 p/m per site*)
Avoids collecting extensive user data and relies on risk signals and cryptographic puzzles to protect against bots – with data from EU users processed and stored within the EU.
*Please be aware – the Friendly Captcha cost may be ex-VAT. Free non-commercial plan available for charities/NGOs.
For Spam Protection: Cloudflare Turnstile (free plan available)

Very effective in blocking unwanted bots, without slowing down the web experience for real users. It also integrates seamlessly with many form builders, including Gravity Forms and Contact Form 7.
(Your site must be running through Cloudflare. If unsure, we can check this for you.)
Other Honourable Mentions
The following alternatives, based on our online research, come highly recommended in the online business community, however have their own caveats which may not make them an attractive option for your business. We will link them, with reasoning below:
- hCAPTCHA (US-based; data not stored in the EU)
- Prosopo (UK-based; however data is stored in the EU. It collects minimal data and uses decentralised data storage)
- CaptchaFox (no free plan available)
- TrustCaptcha (500 verifications for free, paid thereafter)
Standardised protection
While not optimal for security best practice, it is also possible to perform a standardised bot protection on your website with basic math functions and general questions (e.g. ‘what colour is grass?’) through a selection of simple WordPress plugins.
This is better than no protection, but is not likely to protect your website to the same level as the previously outlined options would. Depending on the form plugin you use, we can set up one of the many free options on your WordPress website such as Akismet.
Continue without CAPTCHAs
If you do not wish to have any kind of spam, fraud and abuse protection on your website following the Google reCAPTCHA migration, this is possible, however we do not advise taking this approach, as it exposes your website to significantly increased vulnerabilities.
Does Vitamin offer support for the Google reCAPTCHA migration?
Yes. Throughout the year we will be working with our currently retained clients to support in migrating your reCAPTCHA keys to Google Cloud project on their own Google accounts or alternative solutions as listed above.
We can also offer this service to previous clients upon request. Please do get in touch with us to discuss, and we would be happy to provide a quote for our support for the migration.
We will require that current and past clients host their own reCAPTCHA keys to their accounts, or to secure another viable alternative by the deadline, as we will be unable to continue hosting them to our own accounts after the end-of-2025 deadline.
Ahead of the deadline, we will be removing all Google reCAPTCHA keys from our own Google account, which may put your forms at risk of becoming inoperable unless you migrate them to your own Google account or opt for an alternative to Google reCAPTCHA. To ensure your forms continue operating as normal, please get in touch.
What next?
Please get in touch with us as soon as possible, confirming whether you wish to remain with Google reCAPTCHA and migrate your account, or opt for a different CAPTCHA provider, such as Friendly Captcha.
If remaining with Google reCAPTCHA, please advise us of the Google account/Gmail address that you wish to tie to your reCAPTCHA, to ensure uninterrupted service before the expiry deadline.
If you instead wish to use a different CAPTCHA provider, whether that be one of the ones listed above, or any other you have investigated, please let us know and we will revert to discuss the next steps.