Docs · Getting started
Quick start
Point a form at holdmyform and receive your first submission. You need a form on a website and an address that should get the enquiries.
1Create a form
In the dashboard, choose New form, name it, and add the address that should receive enquiries. Each form gets its own endpoint:
2Point your form at it
Set the endpoint as the form's action. Every field with a name is stored and sent on.
3Or send JSON
From JavaScript, post JSON and ask for JSON back. A stored submission answers with "ok": true.
Special fields
Four field names change what happens to a submission. All are optional.
| Field name | What it does |
|---|---|
| email or _replyto | The sender's address. Replies to the notification go there. |
| _subject | The subject line of the notification email. |
| _next | The address of your thank-you page, shown after sending. |
| _gotcha | A hidden trap for spam robots. Keep it empty and hidden. |
Protect your form
A form address is public: anyone who views your page can read it. Five things stop others from misusing it. The first three are always on.
| Protection | What it does |
|---|---|
| Fixed recipients | The receiving address is set in the dashboard, never in the form. Nobody can use your form to send email to someone else. |
| Rate limit | One sender can submit a form 5 times in 10 minutes. After that we answer "try again later". |
| Spam trap | A submission that fills the hidden _gotcha field is stored as spam and not emailed. |
| Allowed sites | List the sites that may post to the form, such as https://example.fi. Submissions from any other site are refused. |
| Human check | Turn on Cloudflare Turnstile for a form that attracts robots. It runs without puzzles for most visitors. |
What "Allowed sites" does not do. It stops another website from using your form. A program can still fake the site name, so the rate limit and the human check are there for robots.