Domain allowlist
Restrict form submissions to your own domains
Add one or more domains to a form’s allowlist and FormSubmit rejects submissions whose Origin (or Referer) doesn’t match. It stops people from reusing your endpoint on other sites and blocks a lot of scripted abuse.
Simple patterns
example.com also matches www.example.com. *.example.com matches the apex and every subdomain. localhost works for development.
CORS done right
Browsers get Access-Control-Allow-Origin only for allowed origins, so fetch() from other sites fails cleanly.
Safe redirects
When an allowlist is set, _redirect URLs must also point at an allowed domain.
Frequently asked questions
Does the allowlist stop server-side scripts?
Scripts can forge headers, so treat the allowlist as one layer. Combine it with the honeypot, rate limiting and a captcha for stronger protection.
What if I leave it empty?
Submissions are accepted from any origin, which is convenient while you are building.
Related
Your form backend is 60 seconds away
Sign in with Google, create a form, paste the endpoint. Free forever for small sites — no credit card.