Skip to content
FormSubmit

Protection

Domain allowlist

Only accept submissions that come from your own domains.

The allowlist restricts which websites can submit to a form. FormSubmit checks the request's Origin header (falling back to Referer) against your list and rejects mismatches with domain_not_allowed.

Pattern rules

PatternMatches
example.comexample.com and www.example.com
*.example.comexample.com and every subdomain (app.example.com, a.b.example.com)
localhostlocalhost on any port — handy while developing

You can paste full URLs — https://www.example.com/contact is normalised to www.example.com.

Behaviour

  • Empty list — every origin is accepted.
  • Non-empty list — requests with no Origin/Referer, or a non-matching one, are rejected.
  • CORS — Access-Control-Allow-Origin is only returned for allowed origins, so browser fetch calls from other sites fail.
  • Redirects — the _redirect field must point to an allowed domain.