GoDaddy静态PHP联系表单真实邮箱无法提交的技术问询
问题解决:GoDaddy环境下PHP联系表单真实邮箱提交失败的绕过方案
问题背景
部署在GoDaddy静态环境的PHP联系表单,使用伪造邮箱(如bob@fizz.pizz)可正常提交,但真实邮箱(如bob@gmail.com、bob@aol.com)提交失败。需求是通过临时修改用户输入的邮箱字符串绕过FILTER_VALIDATE_EMAIL验证,之后再还原真实邮箱,确保收件人能看到正确信息。
解决方案思路
- 前端拦截修改:表单提交时,给用户输入的真实邮箱添加一个不破坏邮箱格式规则的特殊字符,构造出能通过PHP邮箱验证的伪邮箱。
- 后端还原真实邮箱:PHP验证通过后,移除伪邮箱中的特殊字符,还原为用户真实邮箱,再用于邮件发送和内容展示。
具体修改步骤
1. 修改前端表单(index.html)
添加提交事件的JavaScript,临时修改邮箱字段值:
<form action="forms/contact.php" method="post" role="form" class="php-email-form" onsubmit="modifyEmail()"> <div class="row"> <div class="col-md-6 form-group"> <input type="text" name="name" class="form-control" id="name" placeholder="Your Name" required> </div> <div class="col-md-6 form-group mt-3 mt-md-0"> <input type="email" class="form-control" name="email" id="email" placeholder="Your Email" required> </div> </div> <div class="form-group mt-3"> <input type="text" class="form-control" name="subject" id="subject" placeholder="Subject" required> </div> <div class="form-group mt-3"> <textarea class="form-control" name="message" rows="5" placeholder="Message" required></textarea> </div> <div class="my-3"> <div class="loading">Loading</div> <div class="error-message"></div> <div class="sent-message">Your message has been sent. Thank you!</div> </div> <div class="text-center"><button type="submit">Send Message</button></div> </form> <script> function modifyEmail() { const emailInput = document.getElementById('email'); // 在@符号前插入#,构造可通过验证的伪邮箱(如bob@gmail.com → bob#@gmail.com) emailInput.value = emailInput.value.replace('@', '#@'); } </script>
2. 修改后端验证逻辑(php-email-form.php)
在邮箱验证通过后,移除特殊字符还原真实邮箱:
// 原第124行后新增还原代码 124 $from_email = filter_var( $this->from_email, FILTER_VALIDATE_EMAIL); // 移除添加的#字符,还原真实邮箱 124.1 $real_from_email = str_replace('#@', '@', $this->from_email); // 验证通过后替换为真实邮箱 124.2 if ($from_email) { 124.3 $from_email = $real_from_email; 124.4 } // 原错误判断逻辑保持不变 134 if( ! $from_email ) 135 $this->error .= $this->error_msg['invalid_from_email'] . '<br>'; // 确保回复邮箱使用真实地址 191 $mail->addReplyTo( $from_email, $from_name );
3. 优化contact.php的消息内容
确保收件人看到的是真实邮箱:
<?php $receiving_email_address = 'my-gmail account'; if( file_exists($php_email_form = '../lib/php-email-form/php-email-form.php' )) { include( $php_email_form ); } else { die( 'Unable to load the "PHP Email Form" Library!'); } // 提前还原真实邮箱 $real_email = str_replace('#@', '@', $_POST['email']); $contact = new PHP_Email_Form; $contact->ajax = true; $contact->to = $receiving_email_address; $contact->from_name = $_POST['name']; // 提交伪邮箱用于验证 $contact->from_email = $_POST['email']; $contact->subject = $_POST['subject']; $contact->add_message( $_POST['name'], 'From'); // 消息中插入真实邮箱 $contact->add_message( $real_email, 'Email'); $contact->add_message( $_POST['message'], 'Message', 10); echo $contact->send();
关键说明
- 选择的
#字符不会破坏邮箱格式,bob#@gmail.com可正常通过FILTER_VALIDATE_EMAIL验证。 - 后端必须在验证通过后再还原邮箱,避免无效邮箱绕过校验。
- 同时修改邮件回复地址和消息内容中的邮箱,确保收件人能直接回复真实地址。
内容的提问来源于stack exchange,提问作者Rich
相关产品推荐
相关产品推荐

