Email obfuscation that actually stops the bots

Publish your email or phone number and spam bots harvest it within weeks. Contact Encoder hides email addresses and phone numbers from scrapers, keeps them clickable for real people, and - unlike every other obfuscator - filters the smart bots too. Free and open source.

Get it on GitHub Start free trial

One dependency: the CleanTalk anti-spam client • Works with any framework or plain HTML • Open source (GPL-3.0)

Contact Encoder decoding a hidden email after verifying the visitor

We*****@*******lk.org - This address is hidden from scrapers. When clicked, a request is sent to the CleanTalk cloud, which decides whether or not to display it.

A real visitor clicks → CleanTalk verifies them → the contact is revealed. A bot never gets that far.

Most "email protectors" only fool the dumb bots. They scramble the address in JavaScript and rebuild it in the browser - so any scraper that runs JavaScript reads it instantly. Contact Encoder checks who is asking before it reveals anything. That is the difference between hiding an address and protecting it.

Obscurity vs. real protection

Plain JS & Cloudflare obfuscation

  • Only stops bots that do not run JavaScript
  • Modern scrapers decode it instantly
  • Email only - ignores phone numbers
  • Cloudflare's version is tied to Cloudflare and publicly decoded

Contact Encoder

  • Verifies the visitor against the CleanTalk anti-spam cloud
  • Filters smart, JavaScript-executing bots
  • Protects email, phone, and custom text
  • Works on any stack - open source, one dependency

What you get

Email + phone + text

One library covers every contact, not just email addresses.

Cloud-verified

The decode step checks the visitor, so smart bots are filtered out.

Drop-in library

Install with Composer and use it in plain HTML, React, Vue or Astro.

Stays clickable

mailto: and tel: links keep working for real people.

Battle-tested

The same tech protects contacts on thousands of WordPress sites.

Free & open source

GPL-3.0 licensed, auditable, yours to keep.

How it works

1

Wrap the contact

Mark the email or phone you want to protect. It is stored encoded in the page.

2

Visitor is verified

On interaction, the request is checked against the CleanTalk anti-spam cloud.

3

Revealed to humans

A real person sees the clickable contact. A bot is filtered out.

How Contact Encoder compares

Feature / Function Plain JS obfuscators Cloudflare obfuscation Contact Encoder
Protects email Yes Yes Yes
Protects phone numbers No No Yes
Encodes custom text No No Yes
Stops smart / JS-executing bots No No Yes (cloud check)
Works on any host / stack Varies Cloudflare only Yes
Open source, self-hosted control Varies No Yes (GPL-3.0)

Anti-spam since 2012 • Battle-tested on thousands of WordPress sites • Free & open source (GPL-3.0)

For developers

Install with Composer, wrap the contact, and initialize. The address is stored encoded and revealed only after the CleanTalk check passes. Full docs and the current API are on GitHub.

View Contact Encoder on GitHub →

On WordPress?

No code needed. The same Contact Encoder ships inside the CleanTalk Anti-Spam plugin - enable it in the settings and encode email and phone globally or with a shortcode.

Frequently Asked Questions (FAQ)

1. What is email obfuscation?

Email obfuscation is the practice of hiding an email address on a web page so automated bots cannot read it, while real visitors still see and can click it. It stops harvesting bots from scraping your address and selling it to spammers.

2. How is Contact Encoder different from other email obfuscation tools?

Most tools only scramble the address in JavaScript, which stops crude bots but not modern scrapers that run JavaScript. Contact Encoder verifies each visitor against the CleanTalk anti-spam cloud before revealing the contact, so it also filters smart bots. It protects phone numbers and custom text too, not only email.

3. Does Contact Encoder work outside WordPress?

Yes. Contact Encoder is a standalone, framework-agnostic library. It works with plain HTML or any framework and on any host, and it requires only the CleanTalk anti-spam client, installed together with it through Composer. For WordPress sites, the same feature is built into the CleanTalk Anti-Spam plugin.

4. Is it free?

Yes. Contact Encoder is free and open source under the GPL-3.0 license. The cloud verification behind it runs on CleanTalk Anti-Spam: a free 7-day trial, then from $12 per site per year.

 

Protect your email and phone from bots

Contact Encoder is free and open source. Start a CleanTalk trial to power the cloud verification that stops smart bots - free for 7 days, then from $12 per site per year.

Get it on GitHub

CleanTalk Account

Your temporary password will be sent by email • No credit card required • License agreement