Skip to main content
New: 190 SEO checks now available. See what's new
lowSecuritySENSITIVE_DATA_EXPOSED

Contact details are scrapable in plain text — the fix

Email addresses or phone numbers appear as plain text on the page, where scraper bots can collect them. On a contact page that is usually intentional; the point is to know it is happening.

Where this fits: security in SEO

Security issues erode both rankings and trust. HTTPS has been a ranking signal since 2014, and browsers actively warn users away from insecure or mixed-content pages — a warning interstitial is a 100% bounce rate. Missing security headers rarely block indexing, but they widen your attack surface, and a hacked site (injected spam, malicious redirects) can be removed from results entirely. Security is the SEO work you do so you never have to do recovery work.

Why contact details are scrapable in plain text hurts your rankings

Addresses published in plain text are harvested by scrapers and sold into spam lists, so an inbox that was quiet gets noisy. That is the whole cost — it is not a vulnerability, nothing is exposed that you did not choose to publish, and for many sites the reachability is worth more than the spam.

This is a low-severity issue: a polish item. Fix it in batches during scheduled maintenance; the win is cumulative quality, not a step change.

How to fix it

If the address is meant to be public, nothing needs doing. If the spam is a problem, put the address behind a contact form, or render it with JavaScript so a plain HTTP fetch does not see it. Obfuscation tricks like entity-encoding buy very little against a modern scraper.

Security best practices

  • Serve everything over HTTPS and redirect HTTP with a single 301.
  • Send HSTS, X-Content-Type-Options, and a Content-Security-Policy on every response.
  • Eliminate mixed content — one insecure asset breaks the padlock.
  • Keep dependencies and CMS plugins patched; most site hacks are known-CVE exploits.
  • Monitor Search Console's security section — Google often knows you're hacked before you do.

The full library: SEO best practices, by category.

Frequently asked questions

What does "Contact details are scrapable in plain text" mean?

Email addresses or phone numbers appear as plain text on the page, where scraper bots can collect them. On a contact page that is usually intentional; the point is to know it is happening.

Why does contact details are scrapable in plain text matter for SEO?

Addresses published in plain text are harvested by scrapers and sold into spam lists, so an inbox that was quiet gets noisy. That is the whole cost — it is not a vulnerability, nothing is exposed that you did not choose to publish, and for many sites the reachability is worth more than the spam.

How do I fix contact details are scrapable in plain text?

If the address is meant to be public, nothing needs doing. If the spam is a problem, put the address behind a contact form, or render it with JavaScript so a plain HTTP fetch does not see it. Obfuscation tricks like entity-encoding buy very little against a modern scraper.

How serious is this issue?

This is a low-severity issue: a polish item. Fix it in batches during scheduled maintenance; the win is cumulative quality, not a step change. It belongs to the security family of checks.

How do I find every page affected by this on my site?

Run a free Dr Urls audit: it crawls your site, detects contact details are scrapable in plain text on every affected page, shows example URLs, and generates a ready-to-use fix task. Re-scan after fixing to verify the issue is gone.

Does your site have this issue?

A free Dr Urls audit crawls your site, finds every page affected by contact details are scrapable in plain text, and hands you a ready-made fix task.

Check my site free

Related security guides