Fields whose names start with _ configure behaviour and are not stored as submission data.
| Field | Example | What it does |
|---|---|---|
_gotcha | hidden empty input | Honeypot. If it has any value the submission is treated as spam and dropped. The name is configurable per form. |
_redirect / _next | https://example.com/thanks | Where to send the visitor after an HTML submission. Ignored if the form has a redirect URL in settings. Must match the allowlist if one is set. |
_subject | New enquiry from pricing page | Overrides the notification email subject. |
_replyto | jane@example.com | Sets the Reply-To of the notification email. By default we use any email field. |
_ts | 1759052100000 | Timestamp (ms or s) when the form was rendered. Enables the time-to-submit spam check. |
_format | json | Forces a JSON response even without an Accept header. |
_files | [{"field":"resume","url":"…"}] | JSON array of files uploaded directly to storage. See file uploads. |
Examples
hidden-fields.html
<input type="hidden" name="_subject" value="New lead from the landing page">
<input type="hidden" name="_redirect" value="https://example.com/thanks">
<input type="text" name="_gotcha" style="display:none" tabindex="-1" autocomplete="off">Setting _ts with a line of JavaScript:
timestamp.html
<input type="hidden" name="_ts" id="fs-ts">
<script>document.getElementById("fs-ts").value = Date.now();</script>Captcha tokens
The captcha widget fields g-recaptcha-response, h-captcha-response and cf-turnstile-response are also treated as control fields: they're verified and then discarded. See captcha.