Skip to content
View in the app

A better way to browse. Learn more.

Web Designer Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

How to stop spamming of a mail to form?

Featured Replies

Hello, so this is my site:

 

Website

 

As you can see under the header i have a suggestions box.

 

However there is nothing to stop people just clicking send etc and ill recieve emails all day long.

 

Whats the best way around this?

 

Im not sure how to not allow empty fields?

 

And what other measures can i take?

 

Heres the code:

 

<?php
if(isset($_POST['submit'])) {
$to = "myemail";
$subject = "Suggestion";
$email_field = $_POST['email'];
$message = $_POST['message'];

$body = "From: $name_field\n E-Mail: $email_field\n Message:\n $message";
echo '<div id="submitmessage">', "Suggestion sent! If chosen, you will receieve and email shortly!", '</div>';
mail($to, $subject, $body);
}
?>

 

Thanks!

Edited by Lovelock

Hello, so this is my site:

 

Website

 

As you can see under the header i have a suggestions box.

 

However there is nothing to stop people just clicking send etc and ill recieve emails all day long.

 

Whats the best way around this?

 

Im not sure how to not allow empty fields?

 

And what other measures can i take?

 

Heres the code:

 

<?php
if(isset($_POST['submit'])) {
$to = "myemail";
$subject = "Suggestion";
$email_field = $_POST['email'];
$message = $_POST['message'];

$body = "From: $name_field\n E-Mail: $email_field\n Message:\n $message";
echo '<div id="submitmessage">', "Suggestion sent! If chosen, you will receieve and email shortly!", '</div>';
mail($to, $subject, $body);
}
?>

 

Thanks!

 

um i'd suggest a professional built form, u can try mine by downloading it here RizoContact i never have had a problem with spam using my form

If it's people manually sending you're worried about, could you put some sort of session variable which say only allowed them to send a certain number of messages? Or a timer which only allowed them to send a message every 30 seconds or so, similar to the flood control on the search facility on WDF.

  • Author

I think a session variable may be the best bet...

 

as for checking if fields are empty, is just field validation im guessing?

I think a session variable may be the best bet...

 

as for checking if fields are empty, is just field validation im guessing?

 

$name = (isset($_POST['name'])) ? $_POST['name'] : false;

if(!$name){
//Name field is empty
}

 

you also may wanna sanitize your fields, but i still suggest just using a prebuilt form spammers are patient, a session will not stop them from spamming ur inbox 5 or 10 times a day

Hello, so this is my site:

 

Website

 

As you can see under the header i have a suggestions box.

 

However there is nothing to stop people just clicking send etc and ill recieve emails all day long.

 

Whats the best way around this?

 

Im not sure how to not allow empty fields?

 

And what other measures can i take?

 

Heres the code:

 

<?php
if(isset($_POST['submit'])) {
$to = "myemail";
$subject = "Suggestion";
$email_field = $_POST['email'];
$message = $_POST['message'];

$body = "From: $name_field\n E-Mail: $email_field\n Message:\n $message";
echo '<div id="submitmessage">', "Suggestion sent! If chosen, you will receieve and email shortly!", '</div>';
mail($to, $subject, $body);
}
?>

 

Thanks!

 

 

One way as has been mentioned on here is to place a time limit between sending messages which irritates the hell out of idiots trying to send spam via your contact us form. Time yourself filling out the form to see how long it takes you, then use this as a benchmark.

 

Another route used by forum registration forms is to generate a randomly pulled Question/answer field which is unique to your website which will stop the automated spammers in their tracks. On forums you can make up as many questions & answers as you like which are then randomly pulled. Change or edit the questions from time to time.

 

The list of randomly pulled questions and answers is unique to your website or forum, this makes it incredibly difficult to be answered by an automated script, and any cheap foreign labourers employed abroad to break the captcha method may not even be able to read English let alone write down the answer!

 

Examples being:

 

Add up the two numbers 2+7:9

Name a Italian supercar manufacturer beginning with F:Ferrari

What is the colour of a UK mobile phone company beginning with O:Orange

What's the name of a well known computer company in the US that is also a fruit:Apple

What is the christian name of the footballer married to Victoria Beckham:David

 

The questions could be related to your site and don't actually have to be too hard.

 

The problem with the captcha method is that text automated recognition systems are getting very good at reading these methods, sometimes better than mere mortals trying to genuinely fill out the form!

 

Am sure there are some knowledgeable coders on here who could compile the code for you if you ask nicely.

@OP: if you;re worried at all about conversions, ignore all the advice about the having the user answer questions or other silly anti spam measures.

So people cant figure out simple math questions? lol

 

EDIT: also i'd like to point out all those missing conversions could also very well be spammers/spam bots,

Edited by webdesigner93

So people cant figure out simple math questions? lol

 

So if you were visiting a foreign website with the intention of spamming it and encountered this registration question, would it be simple for you to answer or would you move onto the next easier site to spam.

 

Here's the question: Beantworten Sie folgende Frage. Was ist zwei und sieben addiert

 

The maths question is only an example, but it demonstrates how difficult even the simplest of questions can stop a human spammer who doesn't speak the language of that country.

Edited by richwdf

  • Author

Thanks for the replys.

 

Ill be looking into santization and validation later.

 

I think the best way for me is to check for a valid email and only allow say 1 suggestion a day or something.

Thanks for the replys.

 

Ill be looking into santization and validation later.

 

I think the best way for me is to check for a valid email and only allow say 1 suggestion a day or something.

yes this is a good way as well

Thanks for the replys.

 

Ill be looking into santization and validation later.

 

I think the best way for me is to check for a valid email and only allow say 1 suggestion a day or something.

But then I could just input something like this "ajnjana@kanan.naa" and that'll validate as a real email.

...Ill be looking into santization and validation later...

 

You need to do it ASAP. These things are huge problems. Sanitization needs to be done to prevent people from blowing up your database and validation needs to be done to provide a positive user experience.

 

Then you worry about preventing spam, since that's a problem that only affects the person who receives the e-mail. And, keep in mind, you should never put the burden on the user to prevent spam.

Edited by porkchops

  • Author

You need to do it ASAP. These things are huge problems. Sanitization needs to be done to prevent people from blowing up your database and validation needs to be done to provide a positive user experience.

 

Then you worry about preventing spam, since that's a problem that only affects the person who receives the e-mail. And, keep in mind, you should never put the burden on the user to prevent spam.

 

:) Only just started with PHP and didn't even know what sanatization was until this thread. But now i see exactly why its needed.

 

This form doesn't write to a database, although i may do it in the future and just make it store as a simple page that i can check instead of receiving emails.

 

Either way, im all for learning and getting into good habits!

 

The reason i use the email address isn't to stop spam as such, but its so that i can contact the user afterwards.

 

I shall get my thinking cap on!

:) Only just started with PHP and didn't even know what sanatization was until this thread. But now i see exactly why its needed.

 

This form doesn't write to a database, although i may do it in the future and just make it store as a simple page that i can check instead of receiving emails.

 

Either way, im all for learning and getting into good habits!

 

The reason i use the email address isn't to stop spam as such, but its so that i can contact the user afterwards.

 

I shall get my thinking cap on!

 

No worries, just make sure you get those two things down. People always forget validation, and there is nothing more frustrating than trying to fill out a form only to get an error without any idea what's wrong or how to resolve it.

  • Author

No worries, just make sure you get those two things down. People always forget validation, and there is nothing more frustrating than trying to fill out a form only to get an error without any idea what's wrong or how to resolve it.

 

:) we have all been there a few times before.

 

So in terms of validation, im looking for ideally...

 

- Check if forms are empty.

- Check for @ sign in email.

 

Then sanatize illegal chars etc within the fields.

 

And finally make it only allowed once over a certain time. Or possible 3 a day.

 

Think i have my learning schedule for tomorrow worked out!

But then I could just input something like this "ajnjana@kanan.naa" and that'll validate as a real email.

 

I don't think there is any real way around this.

 

Regex for "Something @ something dot something" is usually the way it is (roughly). No way of really checking whether that email really exists. Well, there might be, but I can imagine it'd be quite intrusive and maybe not that reliable.

 

Fact is, if someone wants to manually spam you, there's not really much you can do about it, apart from making it as frustrating as possible for them.

Regex for "Something @ something dot something" is usually the way it is (roughly). No way of really checking whether that email really exists. Well, there might be, but I can imagine it'd be quite intrusive and maybe not that reliable.

 

You can look up the mx record with getmxrr() - that'll confirm the domain. To confirm the address itself: handshake, identify and send "rcpt to: ajnjana@kanan.naa" to the MX server's Telnet port. Response 250 indicates valid address, 550 and it doesn't exist. All hinges on how important your email address data is. Probably wise to exclude the major free webmail providers though, as it's a spam signal.

Edited by Renaissance-Design

  • Author

That doesn't matter :) It's possible to inject headers into an email. For example, I could inject additional emails into the message to spam to as many emails as I wanted. This could bring your mail server down and worse case scenario, get your server blacklisted.

 

Christ, so much malicious stuff out there!

 

Well, i have just started working on the new suggestions method now.

 

Have sorted writing to the database / reading from it. Am now making sure i can truncate it with a button.

 

Then ill start sorting out all the validation and santization.

 

Am rather enjoying PHP actually. HTML and CSS is all good and fun, but with php you really get the feeling your 'creating' .

You can look up the mx record with getmxrr()...

 

Dude, how do you know SO MUCH and still have time to post here o_O

  • Author

Right, need a bit of direction...

 

Bare with me! If searched across the web but struggling to find what i need.

 

So, this is my basic code for writing to the database:

 

<?php
$con = mysql_connect("localhost","username","password");
if (!$con)
 {
 die('Could not connect: ' . mysql_error());
 }

mysql_select_db("dbname", $con);

$sql="INSERT INTO suggestions (Suggestion, Email)
VALUES
('$_POST[suggestion]','$_POST[Email]')";

if (!mysql_query($sql,$con))
 {
 die('Error: ' . mysql_error());
 }
echo "Suggestion Added!";

mysql_close($con)
?>

 

Right, so what i now want to do. Is if either field is blank, or contains illegal chars etc, then do not post to database but im just a bit confused with how things work.

 

So heres my attempt (if statements written in plain english)

 

<?php
$con = mysql_connect("localhost","username","password");
if (!$con)
 {
 die('Could not connect: ' . mysql_error());
 }

mysql_select_db("dbname", $con);

//IF STATEMENTS HERE TO VALIDATE AND SANATIZE THE INPUT...


$sql="INSERT INTO suggestions (Suggestion, Email)
VALUES
('$_POST[suggestion]','$_POST[Email]')";

if (!mysql_query($sql,$con))
 {
 die('Error: ' . mysql_error());
 }
echo "Suggestion Added!";

mysql_close($con)
?>

 

Is that the correct place where i have commented? there i put the if statements? Just not sure how i return the insert to database true / false etc.

Probably wise to exclude the major free webmail providers though, as it's a spam signal.

 

Yeah that's the reason I figured it may be unreliable. However, I guess according to your method, you could write something to say check if it's a major supplier like yahoo or gmail or whatever, then if it isn't then look it up.

 

So - validate the format of the email address. Let it through if it's gmail, yahoo, hotmail, or any of the major suppliers, and if it isn't then use your method to establish whether it really exists.

 

I guess that would filter some stuff out, although spamming using the major supplier names would still kind of be possible.

 

So if someone's going to enter "gjghfk@dksifn.com" it wouldn't get let through. However "gdfhfdjfh@yahoo.com" would.

Also Lovelock - perhaps you might want to look into using PDO?

 

It might come in useful in making it easier to write securely and sanitise stuff...

Create an account or sign in to comment

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.