DEV Community

Richard Smith
Richard Smith

Posted on

Traditional Bot Detection Is Broken. What's Actually Working Now?

Bot detection on a SaaS signup form used to mean a CAPTCHA plus a honeypot field. Most of what gets through now is a real browser driven by a script or an AI agent, often on a residential IP, and it fills the form the way a person would.

Cloudflare said this summer that automated traffic is now more than half of all web requests. On a signup form that shows up as spam signups that never activate, bounced welcome emails, free credits burned by accounts nobody owns, and an activation rate that looks worse than it is.

Here's where each standard fix breaks: CAPTCHA reliably stops your real users on a phone. Honeypot fields don't catch headless browsers that render the page properly. Rate limits by IP catch a university but miss a residential proxy service. Email verification proves someone controls an inbox, not that a person is behind the signup.

And there's a new wrinkle: not every bot is bad anymore. Some of these are AI agents a real customer sent to sign up or book something for them. "Block all bots" used to be the safe default. Now it can mean turning away a paying user who just delegated the task.

So, for anyone running a signup form: what finally cut spam signups for you, and what was the first sign bots were getting in? Do you add friction for everyone or only when something looks off? And do you let AI agents sign up on behalf of real users?

Top comments (0)