A dev initially suggested in the Lemmy GitHub to remove captchas from future releases altogether because "they're easy to bypass".
Here's the thing though, the lemmy.world instance avoided the daily 10k+ bot signups per day the other instances are currently experiencing simply by activating captchas.
Yes basic OCR easily bypasses them, but the whole point is that you're forcing the spammer to use it, and it costs CPU resources, meaning that for the same budget the spammer will be able to create LESS bot accounts, or none at all if he doesn't know how to automate the use of an OCR. Compare that with the current situation where anyone who followed a Python crash course can easily write a small script doing tens of thousands of automated signups using just the requests
module.
Please enable captchas by default in future releases. You can try out other proposed solutions like hashcash too but IMO focus on the low hanging fruit first and make captchas a default in 0.18 already. One barrier, no matter how weak it is, is much better than no barrier at all.
And to those who maintain websites that list instances and rank them by size, you are also contributing to this problem by adding an incentive for bad actors to inflate their own instances. Please either remove that ranking, or remove the spammy looking instances by hand.
Also, maybe change the user count such that only users having clicked on the verification link are counted.
Barriers are relative. Everything that makes it slightly harder will stop a large chunk of bots, since bots aren't able to easily adapt like humans can. Plenty of very basic bots are in fact stopped by lack of emails.
But yeah, email verification is heavily more so that you can verify they have access to the email, and thus the email is safe to use for things like password resetting. Without it, webmasters can get swamped with complaints about people getting locked out of accounts or the likes because they signed up with the wrong email.
In theory, you can also go further by only allowing email providers that have anti bot mechanisms, but it's difficult to maintain that and it will always exclude some legitimate users.