Does anyone here have an email address (or web form address) for Cloudflare support?
I’m asking because increasingly often, Cloudflare-protected sites give me an endless loop:
Performing security verification This website uses a security service to protect against malicious bots. This page is displayed while the website verifies you are not a bot.
Verifying …
After a few seconds, a “Privacy” and “Help” link are shown next to the word “Verifying”. Then they all get replaced with a spinner icon, and the cycle starts again.
The help link goes to this page, which says:
You may encounter a challenge loop where the challenge keeps reappearing without being solved. This is in very specific cases where we detect strong bot signals. If you are a legitimate human, you can follow the troubleshooting guide below to resolve the issue or submit a feedback report.
Well, I am a human - even if my legitimacy is debatable.
The troubleshooting guide takes me here, which says:
Turnstile Failed Despite Passing All Checks All diagnostics passed, but Turnstile still couldn’t complete successfully. This is unusual and may indicate an edge case. … Since the local diagnostics did not find a clear cause, this may require investigation by Cloudflare.
- Copy your Session ID from the top of this page
- Click “Copy Full Results” in Technical Details below
- Share both with Cloudflare support
But it gives no contact details for Cloudflare support.
A web search turned up this page, but it only lists contact methods available for Cloudflare customers. I am not a customer.
Hence my question at the top of this post.
I’m surprised they still haven’t started selling cloudflare passes that let you browse the web without constant captchas.
They consider you a bot if you have not typical signals from
- referer (there was a time, where even Firefox’ referer trimming was a problem)
- request header
- js-fingerprint, including cookies and DOM-storage
So yeah, surveillance state of the internet.
Do you maybe have a extension/settings that interferes with those signals for increased privacy?
I’ve had websites (not cloudflare in this case) block me recently because I had a slightly out of date Firefox version

“We take your security seriously”
spoiler
by making the mess even more messy
I’ll steal this smiley, ok?
I think @edie@lemmy.encryptionin.space made a browser addon that let’s you use Hexbear emotes on other Lemmy instances.
https://addons.mozilla.org/en-US/firefox/addon/lemmy-emojis/
Thanks. What’s your source for that list? I think you’re right that those measurements are factors in the final “bot score”, but I expect there are many other measurements also factored in.
If you look at my OP, though, you’ll see my browser passed the checks but was still blocked, which Cloudflare said shouldn’t happen.
are you using vpn or tor? sometimes they just hate privacy, and there probably aren’t enough vpn/tor users for them to care about them
i haven’t been having issues atm besides getting challenges more frequently than what used to be the norm.
that said, i find cloudflare, recaptcha and others easier and scarcer when using all default chrome(ium). they might not like something about your browser or what it reports to them.
i don’t think they will change this behavior from user reports.
I’ve been having this same problem for like 3 weeks now!! Are you using Firefox? That’s where I experience the issue, if I try in Chromium it works.
I ended up going to their contact sales page, had the captcha fail there too. But this time it offered me a feedback form. It was ridiculous, but I finally reported it.
I also found if it fails and it gives you a troubleshoot link, you can go to that page and once it fails there it gives you the feedback form too
I’m getting this issue in Chromium.
Like you, I’ve encountered it especially often in the last 3 weeks or so. Thanks for confirming it’s not just me!
Do you have a link to that feedback form, by any chance?
It just pops up inline on the page. Grey box with a text link to open the feedback form at the bottom
I’ve found that the simplest way to get around this is just pick a different VPN exit node
No VPN present in this particular case.

Cloudflare is already wrongly flagging this Linux box as a bot when it connects from an ordinary domestic ISP.
Surely it would be more likely to flag it if it was connecting from a VPN exit node.
I’m telling you the one button solution for this issue that works for me. When their garbage bots don’t like the IP you’re using, simply use a different one.
You’re not going to get any help from cloudflare, obviously. The only thing to do is work around their bullshit.
I eventually managed to find contact details for the webmaster for the site on which I most recently encountered this. Hopefully they’ll fix it in their Cloudflare configuration.
Failing that, I’ll try User-Agent spoofing. Failing that, another ISP, or VPN.




