What Is a CAPTCHA and Why Do You Keep Failing It
Short answer
A CAPTCHA is a challenge a website uses to decide whether you are a person or an automated script. Modern ones score your browser, IP address and behaviour before showing anything, and the image puzzle only appears when that score is low. Failing repeatedly usually means a VPN, a privacy browser or blocked cookies, not a wrong answer.
On this page
A CAPTCHA is a test designed to be easy for a person and expensive for a script. That is the whole idea, and it explains most of its odd behaviour: the test is not really measuring whether you can identify a traffic light.
If you are failing them repeatedly, you almost certainly are not answering wrongly. Something about how you are connecting has put you in a bucket the site treats as suspicious, and the puzzles get harder until you either give up or the system changes its mind.
What the acronym hides
CAPTCHA stands for Completely Automated Public Turing test to tell Computers and Humans Apart. The original version, from the early 2000s, was the warped text image. It worked because optical character recognition at the time was poor at distorted letters while people were reasonably good at them.
That gap closed. Machine vision got better at reading warped text than most people, which is why distorted-text CAPTCHAs have largely disappeared from serious sites. Image grids followed the same path a few years later.
So the industry changed what it measures. Current systems, among them reCAPTCHA v3, Cloudflare Turnstile and hCaptcha, are primarily risk scoring engines. The puzzle, when it appears, is a fallback for sessions the scoring could not resolve.
What the scoring engine actually looks at
From the moment the page loads, the CAPTCHA script collects signals. None of them is conclusive on its own; the score is a weighted combination.
| Signal | What raises suspicion |
|---|---|
| IP address reputation | VPN exit nodes, data-centre ranges, shared mobile carrier NAT |
| Browser fingerprint | Unusual user agent, missing fonts, headless browser markers |
| Cookie history | No prior cookies, blocked third-party cookies, fresh profile |
| Pointer and timing behaviour | Perfectly straight cursor paths, instant form fills |
| Account state | Not signed in to the provider’s own services |
A residential connection running stock Chrome, signed into a Google account, with cookies enabled and a few years of history is the easiest possible case to classify. That person gets waved through invisibly and may genuinely believe CAPTCHAs have been solved.
Someone on a VPN, in a privacy browser, with third-party cookies blocked and anti-fingerprinting enabled, looks statistically similar to automated traffic. Not because they are doing anything wrong, but because they have deliberately removed the signals the engine uses to tell them apart.
Why the puzzle gets harder when you fail
This is the part that feels punitive. It is not quite.
When the score is borderline, the system shows a single image grid. Solve it quickly and cleanly and you pass. Solve it slowly, or hesitate, or get one tile wrong, and the score drops further, so the next challenge is longer, or uses the fading-tile variant where correct answers are replaced with new images you must also classify.
There is a second reason the grids keep coming. Some image CAPTCHAs are doing double duty as labelling tasks for machine-learning datasets. When a grid asks about bicycles or crosswalks, part of the answer is already known and part is being collected. A session that looks low-risk may be asked for more tiles simply because it is a cheap source of labels.
Why you specifically keep failing
Work through these in order. The first two account for most cases.
You are on a VPN. VPN exit addresses carry traffic from thousands of people including the automated kind, so their reputation is poor by construction. Disconnecting the VPN for the duration of the sign-up or checkout is the single most effective fix, and it is worth understanding what an IP address does and does not reveal before deciding whether that trade bothers you.
You block cookies or use strict tracking protection. Without a cookie, the engine has no history for you and every visit is a first visit. Allowing cookies for the specific site, rather than globally, usually resolves it.
You are on shared or carrier-grade NAT. Office networks, university networks, hotel Wi-Fi and some mobile carriers put hundreds of users behind one public address. One compromised machine on that network degrades the score for everyone sharing it. Switching between Wi-Fi and mobile data is a quick test. If the CAPTCHA behaves differently, the network was the problem.
Your browser is unusual. Hardened Firefox configurations, niche browsers and anything reporting a non-standard user agent all score lower. Keeping one stock browser profile for sites that fight you is a pragmatic compromise.
You answered too fast. Under about a second for a nine-tile grid reads as scripted. This is rare but real.
What actually helps
- Disconnect the VPN for the specific transaction, then reconnect.
- Allow cookies for that site rather than disabling protection everywhere.
- Switch networks, mobile data instead of office Wi-Fi, or the reverse.
- Use the audio challenge. It is often shorter, and it is the accessibility route the site is obliged to offer.
- Wait and retry. Scores are partly time-based. Ten minutes later the same session frequently sails through.
What does not help: clearing your cache, reinstalling the browser, or changing your password. None of those touch the signals being scored. Clearing cookies specifically makes it worse, because it discards the history that was vouching for you.
The honest limitation
If you care about privacy, you are going to see more CAPTCHAs, and there is no configuration that gives you both. The scoring engine works by recognising you across sessions and sites. Every measure that stops it recognising you also stops it clearing you.
Some browsers have negotiated attestation schemes with CAPTCHA providers — a cryptographic token that says “this is a real device” without identifying which one. Those help where supported, and they are not supported everywhere.
What a normal experience looks like
On a stock browser on home broadband, most CAPTCHAs resolve invisibly or with one checkbox click. Seeing a grid occasionally on banking, ticketing or sign-up pages is normal, because those pages are attacked constantly and run at a stricter threshold deliberately.
Seeing grids on ordinary pages several times a day is a signal about your connection, not your behaviour. If it started suddenly, check whether a VPN, browser extension or new tracking-protection setting arrived around the same time. For the related question of why reCAPTCHA in particular behaves this way, the image grids have their own logic.