Allow FormTester 365 through CAPTCHA and bot protection

CAPTCHA and bot-protection tools can mistake an automated FormTester 365 test for unwanted traffic. Use the guide for the protection active on your form:

FormTester 365 testing IP addresses

  • IPv4: 45.56.67.77
  • IPv6: 2600:3c00::f03c:92ff:fef9:6b3b

These fixed addresses are visible to your website only when FormTester 365 is not using its proxy.

  1. Open the website in FormTester 365 and open its settings.
  2. In Proxy settings, override the account default and turn the proxy off for that website.
  3. To change the default for every website, open Settings → Proxy settings, turn off Use proxy for scans and tests, and save.

Prefer the website-level override when only one site needs an exception.

Apply the narrowest safe exception

  • Limit the exception to the page containing the form and its submission endpoint.
  • Skip only the CAPTCHA, bot, or rate-limit rule causing the failure.
  • Keep all other firewall and validation rules active.
  • Never turn off CAPTCHA protection for every visitor.
  • Test from a normal connection afterward to confirm other visitors are still protected.

Verify the change

  1. Confirm the FormTester 365 proxy is off for the website.
  2. Run a manual test from the FormTester 365 dashboard.
  3. Review the test details for detected, solved, or failed CAPTCHA information.
  4. Submit the form from a normal browser connection and confirm the CAPTCHA still protects regular traffic.
  5. Remove the exception if you stop using FormTester 365 on the website.

If the test is still blocked, note the CAPTCHA provider, form plugin, security plugin, failed URL, and screenshot before contacting support.

Was this helpful?