Web Designer & Technical SEO Specialist
  • Home
  • About Me
  • Services
    • Website SEO Audit
    • Technical SEO
    • WordPress Website Design
    • WordPress Speed Optimization
    • Landing Page Design & Development
    • WordPress Website Maintenance & Support
  • Portfolio
  • Free SEO Tools
    • Video Sitemap Generator
    • Schema Markup Generator
    • Meta Tag Generator
  • Case Studies
  • Blogs
  • Contact

Home » Blog » Tutorials » WordPress Tutorials

How to Add Cloudflare Turnstile to WordPress Forms (Contact Form 7 and Divi)

Posted: Sep 26, 2026 | WordPress Tutorials

5 min read

This is a spoke of my guide on how to stop contact form spam in WordPress. If you have decided Cloudflare Turnstile is the right layer for your site, this post walks through the setup itself: creating your Turnstile widget, getting your keys, and how to add Cloudflare Turnstile to WordPress forms (Contact Form 7 and Divi) without using reCAPTCHA.

You do not need to move your domain to Cloudflare or change your DNS to use Turnstile. A free Cloudflare account is enough.

Step 1: Create a Turnstile widget in Cloudflare

  1. Sign in to the Cloudflare dashboard and open Turnstile from the sidebar.
  2. Click Add widget and give it a name you will recognize later, such as your site name plus “contact form”.
  3. Under Hostname Management, add your site’s domain.
  4. Choose a widget mode:
    • Managed is the recommended default. Cloudflare decides the verification method based on risk, so most visitors see nothing at all.
    • Non-interactive shows a brief spinner for every visitor.
    • Invisible runs with nothing shown on screen.
  5. Save the widget. Cloudflare generates a Site key and a Secret key.

Copy both keys somewhere safe. The site key is public and goes in your form plugin’s front-end settings. The secret key is private and must never be pasted into a public page, a template, or a client-side script.

Step 2: Connect Turnstile to Contact Form 7

Contact Form 7 has included a native Turnstile integration since version 6.1, so no extra plugin is needed. If you are on an older version, update Contact Form 7 first.

  1. In your WordPress dashboard, go to Contact, then Integration.
  2. Find the Cloudflare Turnstile panel and click Setup Integration.
  3. Paste in your Site key and Secret key, then save.

Contact Form 7 embeds the widget automatically. You do not need to edit the form’s mail tags or template. Every contact form on the site is now protected.

Step 3: Connect Turnstile to a Divi contact form

Divi’s own form module does not have a native Turnstile option yet. Its built-in spam protection is Google reCAPTCHA, set under Divi Theme Options. To use Turnstile with a Divi form instead, you need a small connector plugin that hooks into the form submission.

  1. Install a WordPress plugin that supports Turnstile for forms (for example, plugins that support Divi or Elementor Pro forms), and activate it.
  2. In the plugin’s settings page, paste in the Site key and Secret key from Step 1.
  3. Turn on protection for the specific form location, such as the contact page, rather than every form site-wide if the plugin allows scoping.
  4. Save, then test the form in a private browser window while logged out.

Step 4: Test before you trust it

A saved integration is not proof that it works. Confirm all of the following:

  • Submit the form yourself, logged out, in a private or incognito window, and confirm the email arrives.
  • Re-test after enabling any caching or page-optimization plugin, since aggressive JavaScript minification or deferral can break the Turnstile script.
  • Check that the widget actually renders on the live page, not just in the plugin preview.
  • Check browser console for JavaScript errors if the form does not submit.
  • Watch your spam folder for a week afterward to catch any real enquiries that got blocked by mistake.

Common setup mistakes

  • Mixing up the two keys. The site key goes in the front-end widget settings; the secret key goes in the server-side verification field. Swapping them causes the widget to fail silently for visitors.
  • Forgetting to add the hostname. Turnstile checks the widget against the hostnames you listed in Cloudflare. Test and staging domains need to be added separately, or the widget will not load there.
  • Loading Turnstile on every page instead of just the form page. This does not cost you a shared quota the way reCAPTCHA does, but it is unnecessary weight on pages with no form.
  • Not testing after a caching plugin update. This is the most common reason a previously working form suddenly stops submitting.
  • JavaScript optimization conflicts. Tools like LiteSpeed Cache, WP Rocket, or Autoptimize can delay or combine scripts and break Turnstile. Exclude the Turnstile script if needed.

Why use Cloudflare Turnstile instead of reCAPTCHA?

  • No intrusive image challenges for most users.
  • Privacy-friendly, with less tracking compared to reCAPTCHA.
  • Works without moving your site to Cloudflare.
  • Lightweight and less likely to affect page speed.

Related reading

  • How to stop contact form spam in WordPress — the full layered approach, with a comparison of Turnstile against reCAPTCHA and hCaptcha.

Need a hand setting this up?

If you would rather not deal with API keys and plugin settings yourself, I can set up and test Turnstile on your forms as part of my WordPress Website Maintenance & Support service.

FAQs

Does Cloudflare Turnstile work without Cloudflare CDN?

Yes, you can use Turnstile without moving your DNS or enabling Cloudflare CDN. A free account is enough.

Is Cloudflare Turnstile better than reCAPTCHA?

Turnstile is more privacy-friendly and usually does not show image challenges, making it less intrusive for users.

Why is my Turnstile not showing on my form?

This is usually due to caching, JavaScript optimization, or missing hostname configuration in Cloudflare.

Can I use Turnstile with Divi contact forms?

Yes, but Divi does not support it natively. You need a plugin that integrates Turnstile with Divi forms.

Found this useful? Please share it with your network.
Website designer and Technical SEO specialist in India

ABOUT THE AUTHOR

Sangeetha M

Web Designer & Technical SEO Specialist

Sangeetha is a WordPress & SEO specialist with 15+ years of experience designing and building websites, sharing practical tutorials and beginner-friendly guides on WordPress, SEO, and website growth.

  • Follow
  • Follow
  • Follow
  • Follow
  • Follow

More on This Topic

How to Stop Contact Form Spam in WordPress: Honeypot vs CAPTCHA vs Turnstile

Explore Topics: Content Writing Conversion Strategy News SEO Tutorials Code Snippets Divi Tutorials WordPress Tutorials Website Basics Website Design WordPress WordPress Troubleshooting
Designing SEO-Friendly Websites That Convert

Sangeetha is a WordPress & SEO specialist with 15+ years of experience designing and building websites, sharing practical tutorials and beginner-friendly guides on WordPress, SEO, and website growth.

Explore more

Share:

Table of Contents

  • Step 1: Create a Turnstile widget in Cloudflare
  • Step 2: Connect Turnstile to Contact Form 7
  • Step 3: Connect Turnstile to a Divi contact form
  • Step 4: Test before you trust it
  • Common setup mistakes
  • Why use Cloudflare Turnstile instead of reCAPTCHA?
  • Need a hand setting this up?
  • FAQs

Blog | Privacy Policy

Copyright © 2026. All Rights Reserved.

  • Follow
  • Follow
  • Follow