TechnicalCollectible prompt
Contact form with spam protection and email alerts
Add a contact form to {{page_or_feature}} in my {{tech_stack}} project. Read the existing code first, reuse its components and patterns, and show me a short plan before changing files.
Fields: name, email, optional phone, and message.
Spam protection in layers, with no puzzles for real people:
- A hidden honeypot field that people and screen readers never encounter
- Reject submissions sent less than three seconds after the page loads
- Server-side validation with length limits, and at most five submissions per hour from one visitor
- Accept and quietly discard spam, so bots learn nothing
- Room for an invisible challenge such as Cloudflare Turnstile if spam still gets through
Delivery:
- Send each message from the server via a transactional email service, from our own domain, with the visitor as the reply-to
- The recipient address and API key come from environment variables, never the browser
- Also save each submission to the database, protected by access rules
Experience: labels above fields, errors beside each field and announced to screen readers, typed text kept after an error, a Send message button that shows progress, and a clear thank-you message. Meet WCAG 2.2 AA.
When you're done, list the files changed, how to test it, and anything you assumed.
Technicalnvoka.com/library/nvoka-contact-form-with-spam-protectionScan to open
Technical
Contact form with spam protection and email alerts
Add a contact form that stops bots without puzzles, emails you each message and keeps a copy.
Curated by Nvoka
CursorClaude CodeLovableCodex
Make it yours
Fill in the blanks and change any word. Only your copy changes, never the card.
Fill in the blanks
0 of 2 filledYour prompt
Add a contact form to {{page_or_feature}} in my {{tech_stack}} project. Read the existing code first, reuse its components and patterns, and show me a short plan before changing files.
Fields: name, email, optional phone, and message.
Spam protection in layers, with no puzzles for real people:
- A hidden honeypot field that people and screen readers never encounter
- Reject submissions sent less than three seconds after the page loads
- Server-side validation with length limits, and at most five submissions per hour from one visitor
- Accept and quietly discard spam, so bots learn nothing
- Room for an invisible challenge such as Cloudflare Turnstile if spam still gets through
Delivery:
- Send each message from the server via a transactional email service, from our own domain, with the visitor as the reply-to
- The recipient address and API key come from environment variables, never the browser
- Also save each submission to the database, protected by access rules
Experience: labels above fields, errors beside each field and announced to screen readers, typed text kept after an error, a Send message button that shows progress, and a clear thank-you message. Meet WCAG 2.2 AA.
When you're done, list the files changed, how to test it, and anything you assumed.