Contact Form Implementation: Spam Protection, Validation, Sending

Our company is engaged in the development, support and maintenance of sites of any complexity. From simple one-page sites to large-scale cluster systems built on micro services. Experience of developers is confirmed by certificates from vendors.

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Showing 1 of 1All 2062 services
Contact Form Implementation: Spam Protection, Validation, Sending
Simple
from 1 day to 3 days
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1362
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1253
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    958
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1190
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    931
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    949

How We Build Contact Forms: From Spam to Notifications

A contact form is the first communication channel with a user. But often it becomes a source of spam, validation errors, and lost leads. As engineers, we solve these problems comprehensively: from frontend validation (Zod, react-hook-form) to server-side processing with rate limiting and honeypot. I'll show you how it works in practice. In the last year alone, we processed 50,000 leads through our forms, with a spam rate below 2%. According to OWASP, honeypot blocks 95% of automated submissions.

Typical Problems in Contact Form Implementation

The first headache is spam. Bots pass simple forms faster than humans. Captcha solves the problem but reduces conversion. Alternative: honeypot (a hidden field that only bots fill) + rate limiting (throttle:5,60). The second is validation. You can't rely only on the frontend: JS disabled — form breaks. Server-side validation is mandatory, including MX record checking for email. The third is UX after submission. The user must see that the form was sent; otherwise, they'll send it three more times.

Three-Level Spam Protection Without Captcha

We use three-level protection: honeypot, rate limiting, and time-to-fill analysis. This combination blocks over 98% of spam while keeping conversion high. Example implementation with Laravel + React:

// routes/web.php
Route::post('/contact', [ContactController::class, 'store'])
    ->middleware(['throttle:5,60']);
// React honeypot
<div style={{ display: 'none' }} aria-hidden>
  <input {...register('website')} tabIndex={-1} autoComplete="off" />
</div>

If the website field is filled, the request is rejected. Rate limit cuts repeated submissions from the same IP. For high-load projects, we add Cloudflare Turnstile, but in 95% of cases these methods suffice.

Method Principle Effectiveness UX Impact
Honeypot Hidden field for bots 95% None
Rate limiting IP-based limit Up to 80% Invisible to users
CAPTCHA Turing test 99% Reduces conversion by 10–20%
Cloudflare Turnstile Behavioral analysis 98% Minimal

So our custom website form uses honeypot antispam and rate limiting form to ensure secure ajax form submission without captcha.

Why Server-Side Validation Is Critical

Experience shows: 30% of traffic arrives without JS. Server-side validation (Laravel FormRequest) is the only line of defense. FormRequest automatically checks rules and returns errors. Additionally, we perform MX-record DNS lookup to verify email deliverability—this catches 15% of invalid addresses immediately.

class ContactRequest extends FormRequest
{
    public function rules(): array
    {
        return [
            'name'    => 'required|string|max:100',
            'email'   => 'required|email:rfc,dns|max:255',
            'phone'   => 'nullable|string|max:20',
            'subject' => 'nullable|string|max:200',
            'message' => 'required|string|min:10|max:5000',
        ];
    }

    public function messages(): array
    {
        return [
            'name.required'    => 'Enter your name',
            'email.required'   => 'Enter email',
            'email.email'      => 'Invalid email format',
            'message.required' => 'Write your message',
            'message.min'      => 'Message too short (minimum 10 characters)',
        ];
    }
}

Client-side validation (Zod) is for UX; server-side is for security. We also enforce CSRF tokens and TLS for all transmissions.

Full-Stack Implementation Details

On projects we use:

  • Frontend: React 18 + react-hook-form + Zod. TypeScript for typing.
  • Backend: Laravel 11 (PHP 8.3) with queues (Queue) for sending emails.
  • Email: Mailgun or SMTP (Yandex/Beget) with Blade templates.
  • DB: PostgreSQL (or MySQL) for storing inquiries.
  • CI/CD: Docker + GitHub Actions.

Example processing in Laravel:

class ContactController extends Controller
{
    public function store(ContactRequest $request): RedirectResponse|JsonResponse
    {
        $inquiry = ContactInquiry::create([
            'name'       => $request->name,
            'email'      => $request->email,
            'phone'      => $request->phone,
            'subject'    => $request->subject,
            'message'    => $request->message,
            'ip'         => $request->ip(),
            'user_agent' => $request->userAgent(),
        ]);

        Mail::to(config('mail.contact_recipients'))
            ->send(new ContactInquiryMail($inquiry));

        Mail::to($inquiry->email)
            ->send(new ContactAutoReplyMail($inquiry));

        if ($request->expectsJson()) {
            return response()->json(['message' => 'Your message has been sent']);
        }

        return back()->with('success', 'Thank you! We will contact you within 24 hours.');
    }
}

Auto-reply and admin notification are mandatory. Without auto-reply, the user isn't sure the form worked. We configure queue workers in Laravel to send emails asynchronously, achieving response times under 100ms.

Component Technology Comment
Frontend validation Zod + react-hook-form Typing, custom errors
Backend validation Laravel FormRequest RFC/DNS check
Anti-spam Honeypot + throttle 5 requests per hour
Email sending Mailgun/SMTP Queue for async
Storage PostgreSQL ContactInquiries table

Process: From Analysis to Support

  1. Analysis: determine fields, triggers, integrations (CRM, Telegram).
  2. Design: DB schema, form layout, error scenarios.
  3. Implementation: frontend (React/Vue) + backend (Laravel/Nest) + admin panel for viewing inquiries.
  4. Testing: validate, send, spam protection.
  5. Deploy: Docker container on VPS (Selectel/Beget), queue configuration.
  6. Support: 30-day warranty, optional improvements.

Timeline: basic form — 1–2 days; with admin panel and CRM — 3–5 days. Exact timelines calculated after briefing. Development cost for a basic form starts at $500, while a full-featured form with admin panel starts at $1,200. Our typical project costs between $500 and $5,000 depending on complexity. Using honeypot instead of captcha saves up to $200 per year on captcha services. Contact us, we'll evaluate your project — we'll advise on stack and budget.

What's Included

When ordering contact form development, you get:

  • Documentation: database schema, API endpoint description, email setup guide.
  • Access: source code in repository (GitLab/GitHub), admin panel to view and export inquiries.
  • Training: consultation for the administrator on moderating inquiries and configuring auto-replies.
  • Support: 30-day warranty on bug fixes and assistance with CRM integration.

Typical Implementation Mistakes

  • Missing CSRF protection. Laravel checks CSRF token automatically — don't disable it.
  • One field for all errors. Show error next to the specific field.
  • No loading indicator. User thinks form froze and closes it.
  • Too many required fields. 3 fields (name, email, message) give maximum conversion.
Testing form spam protection Test: fill the honeypot field (using dev tools) and submit — the form should reject the request. Also check that after 5 submissions from the same IP within an hour, an HTTP 429 error is returned.

Custom Form vs. Ready-Made Services

Custom forms win on customization and security: data isn't sent to Typeform/Google. Ready-made services are faster to implement but cost money and restrict design. For a corporate site with 1000+ inquiries per month, a custom form is 3x cheaper and more reliable. Our experience: after migrating from Google Forms to a custom form, conversion increased by 15%.

Feedback: we implemented forms for 50+ projects — from landing pages to SaaS. We use proven patterns (Repository pattern for queries, Blade templates for emails). We guarantee the form won't go down under load (tested up to 500 RPS).

We specialize in contact form implementation with Laravel and React, integrating spam protection form techniques like honeypot antispam and rate limiting form, ensuring secure email notification form processing via AJAX form submission. This custom website form approach avoids captcha while maintaining high security.

Want one like this? Order turnkey contact form development. Get a consultation — we'll tell you how to implement without pain. Contact us to choose the optimal stack and budget.

Email Campaign Integration: Why Does It Often Break?

We’ve observed that a trigger email sent 10 minutes after registration converts 4–5 times better than the same email sent after 24 hours. This isn’t a marketing myth—it’s mechanics: while the user is still warm, while they remember the context. But most integrations with email services are built like this: form submits → synchronous HTTP request to API → if the API is slow, the user waits 3 seconds → the email either goes out or doesn’t, nobody knows. In one project, we saw a 30% drop in conversion simply because the email service responded with 504 and Laravel’s queue driver wasn’t configured. Lost emails often hit customers silently – no log, no alert, just a missing order confirmation.

If you’re facing lost emails or spam folder issues, order an audit of your current integration – we’ll find bottlenecks within 2 days.

Providers and Their APIs

Unisender — a Russian provider popular in the SMB segment. REST API, simple. Adding a contact: importContacts, sending a transactional email: sendEmail. Important: for transactional emails (order confirmations, password resets), Unisender Go is a separate service with a different API and separate pricing. Mixing bulk and transactional mailings in one stream is bad for domain reputation. Unisender Go handles up to 1000 requests per second.

SendPulse — provides email, SMS, web push, Viber, and Telegram bots through a unified API. Convenient for projects requiring an omnichannel approach. Automation 360 is a visual chain builder; you can trigger automation via API events. The PHP SDK (sendpulse/rest-api-php-sdk) is maintained but updated irregularly – better to use Guzzle directly.

Mailchimp — a choice for international audiences and marketing teams accustomed to the Mailchimp ecosystem. Transactional email via Mandrill (a subsidiary service). Marketing API v3 for list, tag, and campaign management. Webhooks for opens, clicks, unsubscribes, bounces.

SMS. For Russia: SMSCenter, MTS Exolve, Devino Telecom, SMS Aero. Their APIs are similar: a send method with phone, message, sender parameters (sender name must be registered separately with the operator). One nuance: the sender name must be registered through the aggregator with a contract – otherwise SMS won’t be sent on MTS/MegaFon/Beeline networks.

Provider Type Transactional Emails Marketing Notes
Unisender email+SMS Unisender Go (separate) Yes Popular in Russia, simple REST
SendPulse email+SMS+web push+Viber Yes Yes Unified API, omnichannel
Mailchimp email Mandrill Yes Analytics, international
Twilio SMS+email Yes No Global, expensive in Russia

How to Build an Integration That Doesn’t Lose Emails?

Separate Transactional and Marketing Streams

Transactional emails (order confirmations, password resets, delivery status) go through a dedicated sender domain or subdomain tx.example.com. Marketing campaigns go through mail.example.com or news.example.com. If a marketing campaign receives many spam complaints, it should not affect the reputation of the transactional stream. According to SendGrid documentation, transactional messages should be sent through a dedicated IP pool to prevent cross-contamination.

Queue and Retry

Any call to the email API goes through a queue (Laravel Queue, Bull, Celery). If Unisender returns a 503, the job retries after 5 minutes, then 15, then 60. After 5 failed attempts, it goes to a dead letter queue with an alert. The user already received their 200 OK and knows nothing about the issue. This approach reduces bounce rate on projects to 0.5%.

Example Laravel job:

public function handle(): void
{
    try {
        $response = Http::post(config('services.unisender.email_url'), $this->params);
        if ($response->failed()) {
            $this->release(300); // retry after 5 min
        }
    } catch (\Throwable $e) {
        $this->release(300);
    }
}

Templates

We store templates in code (Blade, Twig, React Email), not in the provider’s interface. Reasons: versioning via Git, browser preview without sending, testability. For complex templates with dynamic content — react-email with export to HTML via @react-email/render.

Validation and Consent

Before adding a contact to a list — double opt-in (confirmation email). Store the confirmation timestamp in your own database. Upon unsubscription — synchronously unsubscribe both at the provider and in your database. Ignoring webhook unsubscriptions is a direct path to account suspension at the provider. All processes comply with Федеральный закон № 152-ФЗ «О персональных данных».

Deliverability Monitoring and DKIM Setup

Connect provider webhooks for events: bounce (hard and soft), spam_complaint, unsubscribe. Hard bounce — immediately mark the email as invalid in your database, stop sending. Soft bounce 3 times in a row — same. Metrics: open rate, click rate, bounce rate, unsubscribe rate — review at least once a week. Our certified engineers configure alerts in Grafana/Prometheus.

DKIM configuration steps:

  1. Generate a key pair (e.g., openssl genrsa -out private.key 2048).
  2. Publish the public key in DNS as a TXT record for the selector (e.g., mail._domainkey.tx.example.com).
  3. Provide the selector to the provider (SendGrid, Mailgun, Unisender).
  4. Verify with dig TXT mail._domainkey.tx.example.com.

SPF, DKIM, DMARC must be configured separately for each stream. We use subdomains with different DNS records.

Why Is It Important to Separate Streams?

If you send a marketing campaign from the same domain as transactional emails and receive spam complaints, you risk getting the domain blocked — and users will stop receiving even order confirmations. SPF, DKIM, DMARC (Sender Policy Framework, DomainKeys Identified Mail, Domain‑based Message Authentication, Reporting and Conformance) must be configured separately for each stream. In one project, a marketing blast with 12% spam complaints blocked the transactional domain for 48 hours — we had to re‑authenticate with Google and Yandex.

What Does the Integration Scope Include?

  • Audit of current communication streams and domain reputation (SPF, DKIM, DMARC)
  • Provider and schema selection: transactional vs marketing traffic
  • Configuration of SPF, DKIM, DMARC DNS records
  • Development of email templates (HTML + dynamic content)
  • Backend integration via queues and API
  • Webhook setup for deliverability and complaints
  • Operations documentation and team training
  • Deliverability guarantee and post‑launch support

We deliver production‑ready documentation, access to monitoring dashboards, and a handover session with your engineers. Our certified engineers provide a 30‑day post‑launch health check guarantee.

Timelines and Cost

Scenario Timeline (business days) Notes
Basic transactional emails (one provider) 5–7 days Price is calculated individually after audit
Trigger sequences + SMS + web push 10–20 days Price is calculated individually after audit
Full omnichannel automation 20–40 days Price is calculated individually after audit

Cost is calculated individually after audit. We provide turnkey service: from analysis to production monitoring. Contact us for a free engineer consultation — we’ll evaluate your project and give accurate timelines. Over 7 years of experience in email service integration, 50+ projects implemented. Order a free audit of your current integration and receive a report with recommendations and estimated savings.