The allowlist restricts which websites can submit to a form. FormSubmit checks the request's Origin header (falling back to Referer) against your list and rejects mismatches with domain_not_allowed.
Pattern rules
| Pattern | Matches |
|---|---|
example.com | example.com and www.example.com |
*.example.com | example.com and every subdomain (app.example.com, a.b.example.com) |
localhost | localhost on any port — handy while developing |
You can paste full URLs — https://www.example.com/contact is normalised to www.example.com.
Behaviour
- Empty list — every origin is accepted.
- Non-empty list — requests with no Origin/Referer, or a non-matching one, are rejected.
- CORS —
Access-Control-Allow-Originis only returned for allowed origins, so browserfetchcalls from other sites fail. - Redirects — the
_redirectfield must point to an allowed domain.