联系表单持续发送空白邮件问题技术求助
Let's break down why you're getting those annoying blank submissions and fix them step by step.
The Root Cause
Your current code only checks if the honeypot field (firstname) is empty—it doesn't validate that the actual required fields (name, phone, email, text) have content. Bots can easily send a POST request to sendform.php with all fields blank (including the honeypot), which slips past your existing check and triggers the blank email.
Plus, frontend required attributes are easy to bypass—bots don't care about HTML5 validation rules.
Step-by-Step Fixes
1. Add Backend Validation for Required Fields
Update your PHP code to check that all user-facing required fields are not empty before sending the email. Here's the revised sendform.php:
<?php // Sanitize and retrieve form data $userName = trim($_POST['name'] ?? ''); $userPhone = trim($_POST['phone'] ?? ''); $userEmail = trim($_POST['email'] ?? ''); $userMessage = trim($_POST['text'] ?? ''); $honeypot = trim($_POST['firstname'] ?? ''); $to = "your-email@example.com"; $subject = "New Email From Contact Form"; $body = "Information Submitted:\n"; $body .= "Name: " . $userName . "\n"; $body .= "Phone: " . $userPhone . "\n"; $body .= "Email: " . $userEmail . "\n"; $body .= "Message: " . $userMessage; // Validate honeypot AND required fields if (!empty($honeypot)) { // Bot filled the honeypot—abort header('Location: thanks.html'); exit; } elseif (empty($userName) || empty($userPhone) || empty($userEmail) || empty($userMessage)) { // Required fields are blank—abort header('Location: thanks.html'); // Or redirect to an error page if preferred exit; } else { // Send email only if all checks pass mail($to, $subject, $body); header('Location: thanks.html'); exit; } ?>
2. Strengthen the Honeypot
Your current hide-robot class might not be enough to fool smarter bots. Make it more hidden with CSS that removes it from the page entirely:
.hide-robot { position: absolute; left: -9999px; top: -9999px; opacity: 0; pointer-events: none; }
This way, humans can't see or interact with it, but many bots will still try to fill it out—triggering your honeypot check.
3. Optional: Add a Simple Math CAPTCHA
For extra protection against persistent bots, add a basic math question that bots can't easily solve. Update your form:
<form method="post" name="myForm" action="sendform.php"> <!-- Honeypot --> <input name="firstname" type="text" id="firstname" class="hide-robot"> <!-- Required fields --> <input id="name" class="form-control" name="name" placeholder="Name..." required /><br /> <input id="phone" class="form-control" name="phone" placeholder="Phone..." required /><br /> <input id="email" class="form-control" name="email" placeholder="E-mail..." required /><br /> <textarea id="text" class="form-control" name="text" placeholder="How can we help you?" style="height:150px;" required></textarea><br /> <!-- Math CAPTCHA --> <div class="form-group"> <label>What is 3 + 2?</label> <input type="text" name="captcha" class="form-control" required /> </div><br /> <input class="btn btn-primary" type="submit" value="submit" id="submit"/><br /><br /> </form>
Then add this check to your PHP code before sending the email:
$captcha = trim($_POST['captcha'] ?? ''); // ... elseif ($captcha != 5) { header('Location: thanks.html'); exit; }
Why This Works
- Backend validation ensures that even if a bot bypasses frontend checks, it can't send a blank submission.
- A stronger honeypot catches bots that automatically fill all form fields.
- CAPTCHA (optional) adds an extra layer for bots that don't handle simple logic.
内容的提问来源于stack exchange,提问作者craig mackenzie

