You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

IONOS主机环境下网站联系表单自发发送垃圾邮件问题求助

Fixing the Spam Issue from Your IONOS-Hosted Contact Form Script

I’ve dealt with exactly this kind of spam problem on IONOS servers before—let’s get to the root of it and fix your script so you stop getting those meaningless server-generated emails.

First, let’s diagnose why your current script is causing spam:

  • No CSRF protection: Bots can directly hit your send mail PHP script without even loading your form, sending garbage requests that trigger the mail() function.
  • Weak input validation: Your injection check is basic, and you’re not verifying if the email address is actually valid, or if the request comes from a real user interaction.
  • Native mail() risks: The built-in PHP mail() function is prone to header injection if not handled perfectly, and IONOS’s server setup might be amplifying this issue.

Here’s a step-by-step fix with a secure, updated script:

1. Add Anti-Bot Measures to Your Form

First, update your feedback_form.html to include these bot-blocking features:

<form method="POST" action="send_mail.php">
    <!-- CSRF Token (prevents direct script calls) -->
    <?php 
    session_start(); 
    $csrf_token = bin2hex(random_bytes(32)); 
    $_SESSION['csrf_token'] = $csrf_token; 
    ?>
    <input type="hidden" name="csrf_token" value="<?php echo $csrf_token; ?>">
    
    <!-- Honeypot (invisible to real users; bots fill this out) -->
    <div style="display:none;">
        <label for="honeypot">Leave this blank:</label>
        <input type="text" name="honeypot" id="honeypot">
    </div>

    <!-- Your existing form fields -->
    <input type="text" name="first_name" required>
    <input type="email" name="email_address" required>
    <textarea name="comments" required></textarea>
    <button type="submit">Send</button>
</form>

2. Replace Your Script with a Hardened Version

Swap out your old send_mail.php with this secure update. I’m using PHPMailer (far safer than native mail())—download the PHPMailer files and upload them to your server directory first:

<?php
session_start();
require 'PHPMailer/src/PHPMailer.php';
require 'PHPMailer/src/SMTP.php';
require 'PHPMailer/src/Exception.php';

use PHPMailer\PHPMailer\PHPMailer;
use PHPMailer\PHPMailer\Exception;

// Configuration
$webmaster_email = "legion@naturalblood.co";
$feedback_page = "feedback_form.html";
$error_page = "error_message.html";
$thankyou_page = "thank_you.html";

// Block direct access to the script
if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
    header("Location: $feedback_page");
    exit;
}

// Validate CSRF token
if (!isset($_POST['csrf_token']) || $_POST['csrf_token'] !== $_SESSION['csrf_token']) {
    header("Location: $error_page");
    exit;
}

// Reject requests from bots that filled the honeypot
if (!empty($_POST['honeypot'])) {
    exit; // Silently reject to avoid alerting bots
}

// Sanitize and validate form inputs
$first_name = trim($_POST['first_name']);
$email_address = trim($_POST['email_address']);
$comments = trim($_POST['comments']);

if (empty($first_name) || empty($email_address) || empty($comments)) {
    header("Location: $error_page");
    exit;
}

// Verify email format is valid
if (!filter_var($email_address, FILTER_VALIDATE_EMAIL)) {
    header("Location: $error_page");
    exit;
}

// Prepare sanitized email content
$msg = "First Name: " . htmlspecialchars($first_name) . "\r\n" .
       "Email: " . htmlspecialchars($email_address) . "\r\n" .
       "Comments: " . htmlspecialchars($comments);

// Send email via IONOS SMTP (authenticated, spam-resistant)
$mail = new PHPMailer(true);
try {
    // IONOS SMTP settings (find these in your IONOS control panel)
    $mail->isSMTP();
    $mail->Host = 'smtp.ionos.co.uk'; // Use your region's SMTP server
    $mail->SMTPAuth = true;
    $mail->Username = 'your-ionos-email@yourdomain.com'; // Your IONOS email
    $mail->Password = 'your-email-password'; // Your IONOS email password
    $mail->SMTPSecure = PHPMailer::ENCRYPTION_STARTTLS;
    $mail->Port = 587;

    // Recipients
    $mail->setFrom($email_address, $first_name);
    $mail->addAddress($webmaster_email);

    // Content
    $mail->isHTML(false);
    $mail->Subject = "Message from amatoria.com";
    $mail->Body = $msg;

    $mail->send();
    header("Location: $thankyou_page");
    exit;
} catch (Exception $e) {
    error_log("Mail Error: " . $mail->ErrorInfo); // Log errors for debugging
    header("Location: $error_page");
    exit;
}
?>

3. IONOS-Specific Tips

  • Use SMTP, not local mail: IONOS’s spam filters prioritize authenticated SMTP sends over unauthenticated local mail() calls—this is the biggest fix for server-generated spam.
  • Check your IONOS control panel: Ensure "open relay" is disabled (it should be default, but double-check).
  • Add rate limiting (optional): If spam persists, track IP addresses in sessions to block repeated requests from the same source.

Why This Works

  • The CSRF token ensures only requests from your actual form are processed.
  • The honeypot traps bots that auto-fill all form fields.
  • PHPMailer handles email headers safely, eliminating injection risks.
  • SMTP authentication adds a security layer that stops unauthorized mail sends from your server.

Test this on one site first, then roll it out to the other two—you should stop seeing those spam emails within 24 hours.

内容的提问来源于stack exchange,提问作者khtdoutyfr vp

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 12:12:28