Turquoise abstract wavy W logo on a black background
Turquoise abstract wavy W logo on a black background
White WP PowerSuite logo on a black background
White WP PowerSuite logo on a black background

Summarize with AI:

On This Page
Last updated: 01/09/2026

Email Obfuscator

Automatically protects visible email addresses and mailto links from basic spam bots by safely encoding them while keeping them clickable for visitors.

Overview

Reduce basic email harvesting from your WordPress website without hiding addresses from real visitors.

Email Obfuscator automatically detects email addresses in supported frontend content and converts them into HTML-entity-encoded mailto: links. Existing email links are protected as well, while useful parameters such as subject, body, CC, and BCC are preserved.

There is no JavaScript to load, no external service, and no configuration required. Visitors can still read and click your email addresses normally, while simple scraping bots have a harder time collecting addresses directly from the page source.

Email Obfuscator is a Free module in WP PowerSuite.

Solid black square
Solid black square
Who is this for?
  • Business websites displaying public contact email addresses
  • Blogs and author websites publishing email addresses in content
  • Agencies protecting client contact details from basic email harvesting
  • WooCommerce stores displaying sales or support email addresses
  • Sites that want lightweight email protection without JavaScript or an external service

Features

Automatically Obfuscate Email Addresses
Detect valid email addresses in supported WordPress content and encode them automatically on the frontend.
Keep Emails Clickable
Plain email addresses become functional mailto: links, so visitors can still click them to open their preferred email application.
WordPress Content Coverage
Protect addresses appearing in posts, pages, excerpts, comments, widgets, blocks, navigation menus, and other supported WordPress content.
WooCommerce Support
Email addresses in WooCommerce short product descriptions are protected when WooCommerce is active.
Avoid Code & Form Content
Emails inside scripts, styles, code examples, forms, textareas, SVG, iframes, and other sensitive elements are deliberately left untouched.
No Configuration Required
Enable Email Obfuscator and supported frontend email addresses are processed automatically.

Reduce Email Harvesting From WordPress Pages

Keep Email Addresses Visible and Clickable

Protect Existing Mailto Links Too

Avoid Breaking Code, Forms and Embedded Content

Use Cases

  • Business Contact Emails
    Display sales, support, or general enquiry addresses while reducing their exposure to basic email-harvesting scripts.
  • Blog & Author Contact Information
    Keep public author or editorial email addresses readable and clickable while making plain-text harvesting less straightforward.
  • WooCommerce Stores
    Protect email addresses displayed in supported product short descriptions and other processed WordPress content.
  • Public Emails Alongside Contact Forms
    Use AI Forms as the primary contact method while obfuscating any direct email addresses that still need to remain visible.

Frequently Asked Questions

Related Modules

Keep a clear record of important dashboard activity—who logged in, what changed, and when—so you can investigate issues or stay audit-ready without...
Disabled
Tell modern browsers to enforce sensible safety rules—like blocking sneaky scripts and iframe tricks—with strong defaults you can tighten further for HSTS...
Disabled
Two-factor login for selected roles—extra proof beyond the password.
Disabled
Turn off public "forgot password" self-service for everyone. Use only when you reset passwords another way (manual admin password, WP-CLI, or admin-sent...
Disabled
Closes the old XML-RPC channel many password-guessing tools still target. Fine for most sites; skip if you rely on legacy apps or...
Disabled
Remove the dashboard screens that let anyone edit theme or plugin code from the browser—one less disaster if an account is compromised.
Disabled
Put your whole site behind one shared password—ideal for staging, client previews, or a soft launch before you go public.
Disabled
Stops old-style trackbacks and pingbacks that often bring spam or junk alerts.
Disabled
Disables WordPress application passwords site-wide: blocks REST/XML-RPC login with app tokens and hides the profile UI. Normal account passwords and logged-in REST...
Disabled
Removes WordPress version from public HTML generator tags, feed generator output, and the admin footer. Does not change ver= on script and...
Disabled