This Website at Family Search.org
Answers
-
Hello @Gone But Not Forgotten
Which part of the site are you having problems with? The aspects I have tried today have all been performing normally.
Does the problem occur on all devices/with all browsers?
Are you using a VPN? If so, I would suggest you try again with the VPN switched off.
Are your operating system and browser at levels supported by FamilySearch? See https://www.familysearch.org/en/help/helpcenter/article/which-internet-browsers-are-compatible.
If none of that helps, please post again.
1 -
@Gone But Not Forgotten Also try clearing all cookies, cache, history, etc. and reboot the computer.
https://www.familysearch.org/en/help/helpcenter/article/how-do-i-delete-cookies-from-familysearch
3 -
For the three weeks, I've had the same problem. If it's taking a long time for the page to show up, I click the refresh button, a window pops up wanting me to verify I'm human.
I'm using a recent MacBook Pro, running the latest OS. I'm not running a VPN, I have no extensions installed. It doesn't matter if I clear the cache, cookies, history, reboot the computer, it still happens. I even checked my internet speed with speedtest.net, and it's fine.
For the past few year's I've been using the Chromium based browser, Brave, with no problems. Now it's every other record I'm having to re-login or verify I'm human. I switched to Safari and still have the same problem. It's really annoying to have keep doing this over and over and over and….
And it's also annoying that if I accidentally close the browser FS logs me out. I understand logging me out at the end of the day, but really.
I have no problems with Ancestry or Wikitree, or any other website I regularly use.
I'm at my wits end with what use to be a fun project.
0 -
@TeresaWilson95 The few times I have had this problem I've been using my 'phone as a wifi hotspot. Are you perhaps using a cellular network of some sort? That's really all that comes to mind - you've answered the other questions I would have asked.
0 -
Not using a hotspot, I'm on my home internet. If it were an internet connection problem any website I visited would have the same problem. I can access any other website without a problem. I even reset my modem and the problem still exists.
It's more likely the backend (FS) has added more bot protections, so it's going overboard in checking every time a page is accessed.
Frustrating - it's taking twice as long to research and I have a long way to go.
0 -
@TeresaWilson95 the rules for the use of the 'verify human' thing seem to be very FS-specific - there has been a lot of discussion of this topic here on Community over a considerable period of time, but we've never really got to the bottom of it. Perhaps not surprisingly, given FS may not wish to expose the rules for loads of possible reasons - contractual, security, etc.
@sc woz can you help at all please?
0 -
I'm sharing what a friend told me (I know a little about computers, not so much this side of the computing world), in simple terms:
- it could be the website is running Cloudflare for data protection against bots, etc. Apparently Cloudflare has become more aggressive in checking to make sure humans are trying to access the website.
- possibly something is amiss with the Captcha configuration on the website,
- And it could be that those of us who have to keep re-logging in because FS terminates the connection — whatever safety mechanisms FS has set up looks at our numerous logins in a short period as suspicious activity and asks for human confirmation, which also flags our IP service as suspicious, and then it's a crazy merry-go-round. Which is what Cloudflare does.
0 -
Yes, it definitely uses Cloudflare (see Cookie Preferences>Advanced Settings>Required Cookies list).
We won't be able to tell whether the Captcha thing is configured correctly, because FS won't (understandably) tell us what its specific rules are (and they will no doubt change over time).
One thing that has been discussed before, as a possible driver for some of these seemingly quite aggressive controls, is the potential impact of contractual rules re which countries certain FS data (Historical Records, etc.) can be viewed from. Maybe your ISP makes it hard for Cloudflare to locate your IP address geographically. Try https://www.iplocation.net/.
0 -
Simply to add an anecdote of experience to the topic, I'm logged in using the InPrivate mode of Edge, and I haven't had "Verify That You Are Human" checkboxes come up for FamilySearch.
Using InPrivate is about like always clearing your cookies and cache, but it also means that I have to log in each time.
2 -
The only time I've seen the "prove you are human" recently has been on the rare occasion I fail to turn off my VPN before accessing FS.
There was a thread, not long ago, from another FS user who mentioned that the issue was with his ISP hiding his location.
1 -
The “Verify Human” challenge is part of FamilySearch’s automated‑abuse mitigation layer. It is not a standalone feature but an integrated control within several backend systems, including rate‑limiting, access‑control enforcement, and contract‑restricted image delivery. Because these systems interact, the exact trigger conditions are intentionally not published.
From a technical standpoint, the CAPTCHA appears when the platform detects activity patterns that resemble automated access, high‑volume scraping, or repeated requests against sensitive or contract‑restricted endpoints. These patterns are evaluated by internal heuristics that FamilySearch does not disclose for security and contractual reasons.
The triggering logic is tied to:
- Security models that protect the platform from automated harvesting
- Contractual obligations with record custodians that require strict access controls
- Internal rate‑limiting algorithms that adjust dynamically based on system load
- Anti‑abuse heuristics that cannot be exposed without weakening their effectiveness
Because these systems are adaptive, FamilySearch does not publish the criteria, thresholds, or decision logic.
While the underlying rules are not documented, long‑term user observation shows consistent patterns:
- Session anomalies (expired tokens, long idle periods, rapid reauthentication)
- High‑frequency requests to indexed or restricted collections
- Parallel tab activity that generates simultaneous API calls
- Browser extensions that modify scripts, block cookies, or interfere with page execution
- Network instability (VPNs, proxies, cellular hotspots, rotating IP addresses)
- Automated tools or scripts, even benign ones, that mimic non‑human access patterns
These factors do not guarantee a CAPTCHA, but they increase the likelihood of triggering one.
These steps reduce the probability of triggering the system but cannot disable it:
- Maintain a stable session and avoid long idle periods
- Use one active FamilySearch tab rather than multiple parallel tabs
- Avoid rapid, repeated page loads or high‑volume navigation
- Disable script‑blocking or privacy‑filtering extensions
- Use a consistent network connection without VPNs or proxies
- Avoid any automated interaction, including browser macros or scraping tools
These mitigations reduce noise in the access‑pattern heuristics but do not override them.
FamilySearch does not provide a method to disable CAPTCHA.
The system is designed to err on the side of caution, and the triggering logic is intentionally opaque. Users can reduce the frequency through stable, predictable browsing behavior, but the CAPTCHA cannot be removed or bypassed.I will pass this along to the engineers to allow them to see the complaint, but can not advise of when or if they will respond.
2 -
@sc woz thank you very much for this very clear explanation which will I am sure come in very useful in the future too.
@TeresaWilson95 this will hopefully also answer your post above.
1



