The email address was there, but AI assistants couldn't see it. Obfuscation hid it from anything that doesn't run JavaScript.
On our site the email address was there, written plainly on every page. But an AI assistant opening the contact page couldn't find it.
Cloudflare's obfuscation hides the email address from anything that doesn't run JavaScript. With Email Address Obfuscation switched on, Cloudflare replaces addresses in the HTML with “[email protected]” and restores them with a script in the browser, as its documentation explains.
AI assistants' crawlers don't run JavaScript. Vercel measured this across about 1.3 billion requests in a month: none of the major AI crawlers, including those of OpenAI, Anthropic and Perplexity, runs a page's JavaScript. They read the HTML exactly as it arrives.
On 25 September 2026, the served code of itria.io's contact page contained no address at all. We fixed it by excluding the address from obfuscation. In Itria's study of 121 food producers' websites, 7 obfuscate their email address and 7 don't put it in the code at all.
This is part of Itria's lab: things measured on our own site, with the real numbers, to understand how search engines and assistants read it. The service that grows out of it is visibility in search engines and AI assistants.
How Cloudflare's email obfuscation works
Cloudflare's Email Address Obfuscation protects email addresses from programs that harvest them to send spam. When it's on, Cloudflare rewrites every address it finds in the HTML as a link with the text “[email protected]”, and adds a script that restores the real address in the browser.
“When Email Address Obfuscation is enabled, Cloudflare replaces visible email addresses in your HTML with links like [email protected].” (Cloudflare, Email Address Obfuscation documentation)
For a person with a browser, nothing changes: the script runs and the address appears. For a program that reads the HTML without running the script, the address isn't there. In its place, it finds the text “[email protected]” and a link pointing to an internal Cloudflare path.
Why an AI assistant can't see an obfuscated email address
When AI assistants read a page, they take the HTML exactly as the server delivers it. Vercel measured AI crawler traffic on its own network over a month, about 1.3 billion requests, and reported that none of the major ones runs JavaScript: not OpenAI's, ChatGPT-User included, not ClaudeBot, not PerplexityBot.
“none of the major AI crawlers currently render JavaScript” (Vercel, “The rise of the AI crawler”, 17 December 2024)
The consequence is direct. Anyone asking an assistant “what's this company's email address?” gets an answer built on the HTML it read: if the address is obfuscated there, the assistant can't find it, and answers with a form, a phone number, or nothing. Protection against spam becomes a barrier against the people trying to get in touch.
| Who reads the page | Does it run JavaScript? | Does it see the obfuscated address? |
|---|---|---|
| A person, with a browser | Yes. | Yes: the script restores it. |
| An AI assistant's crawler | No, according to Vercel's measurements. | No: it finds “[email protected]”. |
| A program that reads the HTML, such as curl | No. | No: it's how you check it yourself. |
Our case: a contact page without an email address
On 25 September 2026, during the site's hygiene audit, we read the served HTML of itria.io's contact page the way an assistant reads it: no address, because obfuscation was on. The fix is the one Cloudflare itself documents: wrap the address between two email_off comments, which exclude it from obfuscation.
<!--email_off-->info@example.com<!--/email_off-->
Measured the same evening: the contact page contains the address in plain text twice, and no sign of obfuscation. It's a choice, not an oversight: exposing the address also makes it readable to programs that harvest addresses for spam. For a contact address meant to be found, it's worth it; for the site's other addresses, decide case by case.
We're not the only ones: 14 sites out of 121
In Itria's study of the websites of 121 food producers listed in the directory of ICE, the Italian Trade Agency, for foreign buyers, measured on 26 September 2026, 7 sites obfuscate their email address and another 7 don't put it in the code of the three pages read. For a buyer asking an assistant for a supplier's contact details, 14 sites out of 121 have no email address to give.
The five-minute check, on your own site
Read the contact page's HTML the way an assistant reads it, without JavaScript, and look for the at sign. If you get the text “email protected” or no address at all, then for assistants the address isn't there. The command below does it from a terminal, on any site.
curl -s https://yoursite.com/contact | grep -o "[A-Za-z0-9._%+-]*@[A-Za-z0-9.-]*\.[a-z]*\|email-protection"
Questions and answers
Why can't ChatGPT or Claude find a website's email address?
Often because the address is obfuscated. Cloudflare's Email Address Obfuscation replaces addresses in the HTML with [email protected] and restores them with a script in the browser, and AI assistants' crawlers don't run JavaScript.
Vercel measured this across about 1.3 billion requests: none of the major AI crawlers runs a page's JavaScript.
How does Cloudflare's email obfuscation work?
When it's on, Cloudflare rewrites every email address in the HTML as a link with the text [email protected] and adds a script that restores the address in the browser. For a person nothing changes; for a program that doesn't run the script, the address isn't there.
It's meant to protect addresses from programs that harvest them for spam.
How do you exclude an email address from Cloudflare's obfuscation?
By wrapping it between the comments email_off and /email_off in the page's HTML, as Cloudflare's documentation explains. The address between the two comments stays in plain text.
It's a trade-off: an exposed address can also be read by programs that harvest addresses for spam, so it makes sense for the contact address that's meant to be found.
How do you check whether your site's email address can be read by an AI assistant?
Read the contact page's HTML without running JavaScript, for example with curl, and look for an address with an at sign. If you get the text email protected or no address at all, then for assistants the address isn't there.
It's the same way an AI assistant reads the page.
How many websites have an email address invisible to AI assistants?
In Itria's study of 121 websites of food producers listed in the ICE directory for foreign buyers, measured on 26 September 2026, 7 obfuscate their email address and 7 don't put it in the code at all: 14 out of 121, or 11.6%.
On Itria's own site, the contact page had no address in the served code until the fix made the same day.
Notes on sources
- Cloudflare, Email Address Obfuscation: how obfuscation rewrites addresses and how to exclude them with email_off. The quotation is word for word.
- Vercel, The rise of the AI crawler, 17 December 2024: about 1.3 billion AI crawler requests in a month on Vercel's network, and none of the major crawlers runs JavaScript. The quotation is word for word.
- Itria measurements: itria.io hygiene audit of 25 September 2026 and the check on the same evening; study of the websites of 121 food producers in the ICE directory, measured on 26 September 2026 (method and data).
See your own site the way search engines and assistants read it.
An email address that isn't in the code, an address that returns 200 where there's nothing: these are flaws you can't see from the browser. Drop us a line about what's slowing you down: we'll make the first move, even if we never end up working together.