Contact forms without spam or a backend
A website contact form does not have to mean spam or a server of your own. Learn how many fields you really need, how to stop bots without an annoying CAPTCHA, what GDPR requires, and how to handle submissions without a backend.
A contact form looks like the simplest part of a website, yet it causes plenty of trouble: submissions land in spam folders, bots flood the inbox with offers, and handling submissions needs a server and a script someone has to maintain. A contact form is a set of fields on a web page that lets visitors send a message to a business without opening their email client. This guide shows how to design a contact form that collects useful enquiries, blocks spam effectively and works without a backend of your own.
Key takeaways
- Every extra field in a contact form reduces the number of submissions, so only collect data you actually need to reply.
- Cloudflare Turnstile combined with a honeypot field blocks most bots without making people retype distorted characters.
- A form built into your CMS stores submissions in the admin panel and sends email notifications, so you need no server or script.
- Keep submissions in the panel, not only in an inbox, because an email notification can fail to arrive.
- Show a privacy notice under the form and collect marketing consent with a separate checkbox that is unticked by default.
What makes a good contact form
A good form has four layers. The first is the fields and labels visitors see. The second is validation that explains what to fix before the message is sent. The third is spam protection. The fourth is what happens after submission: storage, notification, reply and export. Most problems arise because someone polished the first layer and forgot the other three.
How many fields should a contact form have?
The rule is simple: fewer fields, more messages. That does not mean two fields are always enough. If you cannot give a useful reply without a particular piece of information, ask for it up front rather than running a three-round email exchange.
| Field | When to use it | Notes |
|---|---|---|
| Name | Almost always | One field instead of separate first and last name |
| Always | Validate the format; use the email input type for mobile keyboards | |
| Phone | Local services, urgent matters | Preferably optional; a required number puts people off |
| Topic (dropdown) | Several departments or services | Routes each enquiry to the right person |
| Message | Always | Add a hint such as "Briefly describe what you need" |
| Attachment | Quotes, recruitment, complaints | State allowed formats and maximum size |
Give every field a visible label rather than relying on placeholder text that disappears on click. Write error messages like a human: "Enter your email so we can reply" works better than "Required field".
Spam protection that does not annoy users
An unprotected form usually starts attracting bots soon after the site goes live. A classic image CAPTCHA stops spam, but it also stops some real customers. Fortunately there are better methods, and they work best combined.
| Method | Effectiveness | User friction | Notes |
|---|---|---|---|
| Honeypot (hidden field) | Good against simple bots | None | Easy for advanced scripts to bypass |
| Classic image CAPTCHA | High | High | A barrier for people with disabilities |
| reCAPTCHA v3 | High | Usually invisible | Google's service must be covered in your privacy policy |
| Cloudflare Turnstile | High | Usually no interaction at all | No puzzles to solve |
| Rate limiting per address | Supplementary | None | Protects against submission floods |
In practice, the best setup pairs invisible verification such as Turnstile with server-side validation. Checking only in the browser is not enough, because a bot can submit data without ever loading the page.
Mobile usability and accessibility
A large share of enquiries comes from mobile devices, so test the form on a real phone, not just a narrow browser window. A few details have a real impact on how many messages get sent:
- full-width fields and buttons big enough to hit with a thumb;
- correct input types (
email,tel) so the phone shows the right keyboard; - labels properly linked to fields so screen readers announce them;
- error messages next to the specific field rather than one generic alert at the top;
- keeping entered data after a validation error so nobody has to retype their message.
Label the submit button clearly. "Request a quote" says more than "Send" and tells people what happens next.
Contact forms without a backend: your options
A form has to send its data somewhere. A static site or a modern front end has no server waiting to receive it by default. These are the most common approaches:
| Approach | Pros | Cons |
|---|---|---|
| Your own server script | Full control | Maintenance, updates, mail delivery setup |
| Third-party form service | Quick to set up | Another account, data outside your system, separate fee |
| Plugin in a traditional CMS | Lots of choice | Updates, conflicts, a separate anti-spam plugin |
| Form built into the CMS | Submissions, notifications and anti-spam in one place | Less flexibility for very unusual logic |
For a typical business website, a form built into the CMS is the most sensible choice: no extra services, and submissions land where the team already works.
Contact forms and GDPR
You are collecting personal data, so you need a legal basis and clear information for the user. The minimum for a typical contact form:
- a privacy notice under the form (who the controller is, why you process the data, a link to the privacy policy);
- replying to an enquiry usually does not require separate consent, because processing is needed to act on the person's request;
- marketing consent, if you need it, as a separate checkbox that is unticked by default;
- a defined retention period and regular deletion of old submissions.
Details depend on your industry, so have the wording reviewed by a lawyer.
Handling submissions
Even the best form is useless if messages sit in an inbox nobody checks. Decide who replies and how quickly. After submission, show a clear confirmation such as "Thank you, we will reply within one business day". Keep submissions in the panel so you do not rely on email alone, and send a test message from time to time to confirm notifications still arrive. If you get a lot of enquiries, export them to a spreadsheet each month to see which pages generate the most messages and which topics come up again and again.
Common contact form mistakes
- A required phone number, even though the business replies by email anyway.
- No confirmation after sending, so users click "Send" several times.
- Notifications going to the personal inbox of someone who has left the company.
- A form that is awkward on phones: tiny fields, no @ key on the email keyboard.
- No testing after site changes or a domain move.
How LessCMS handles it
In LessCMS you add a contact form without any backend of your own:
- The form builder is one of the 78 widgets available on every plan; you set up fields and layout in the visual editor.
- Submissions go to the admin panel and to the email address you choose; you can reply to them, export them and accept file attachments.
- Forms are protected by Cloudflare Turnstile, so visitors never retype characters from images.
- In headless mode you can submit forms from your own front end through the public LessCMS API.
Frequently asked questions
How do I add a contact form to my website without coding?
The easiest way is to use a form built into your CMS. You add a widget, set up the fields and the notification address, and the system stores submissions and sends emails without any server scripts.
How do I stop spam on my contact form?
Combine invisible verification such as Cloudflare Turnstile with a hidden honeypot field and server-side validation. That combination stops most bots without getting in the way of real users.
Does a contact form need GDPR consent?
Usually not, if the data is used only to reply to the enquiry. You do need a privacy notice, and marketing consent must be collected with a separate, unticked checkbox.
Why are contact form emails not arriving?
The usual causes are the recipient's spam filter, a wrong notification address or misconfigured mail sending. That is why it pays to store submissions in the panel as well and to send a test message regularly.
How many fields should a contact form have?
Three are usually enough: name, email and message. Add fields such as phone or topic only when you cannot reply properly without them.
Want a contact form with submissions in your panel and built-in spam protection, without writing code? Sign up without a card and pick a plan on the LessCMS pricing page.