Hacker News new | ask | show | jobs
by spartanatreyu 775 days ago
> If you build a contact form, please at least make it respond automatically with a "we've received your message" email.

I don't think that's such a good idea.

What would stop a bad actor from putting in someone else's email on a whole bunch of sites with this kind of form to spam them?

And what would stop a bad actor from putting in a bunch of randomly generated emails into such a form to DDOS the site?

And what would prevent the form spam being seen as spam by email clients causing real (and arguably more important) messages from also being thrown out and automatically deleted with the rest of the spam?

1 comments

> What would stop a bad actor from putting in someone else's email on a whole bunch of sites with this kind of form to spam them?

What would stop a bad actor from doing the same on the register, forgot password or newsletter forms?