Three methods
- HTML entities — every character is written as a code like a. Browsers show it normally; basic scrapers miss it.
- Reversed CSS text — the address is stored backwards and displayed the right way with CSS. Not clickable, but very effective.
- JavaScript — the address is assembled only when clicked.
None of these stop a determined scraper, but they block most automated harvesting. A contact form with spam protection is the most robust option.
Frequently asked questions
Do obfuscated links still work?
Yes, the entity and JavaScript versions are clickable; the reversed CSS version is display-only.
Is obfuscation bad for accessibility?
Entity encoding is read normally by screen readers; reversed text may not be, so prefer entities.
Does it stop all spam?
No, it reduces harvesting by simple bots. Use spam filtering as well.

