Last active January 20, 2023 07:22
PHP script for contact form
// Set the e-mail address that submission should be sent to.
$address = '[email protected]';
// Set the e-mail subject prefix.
$prefix = 'Website feedback';
$error = false;
$success = false;
// Check that the submission address is valid.
if ((bool) filter_var(trim($address), FILTER_VALIDATE_EMAIL)) {
// Also set sender/return path header to this address to avoid SPF errors.
$to = $sender = trim($address);
else {
$error = true;
// Check that referer is local server.
if (!isset($_SERVER['HTTP_REFERER']) || (parse_url($_SERVER['HTTP_REFERER'], PHP_URL_HOST) != $_SERVER['SERVER_NAME'])) {
exit('Direct access not permitted');
// Check that this is a post request.
if ($_SERVER['REQUEST_METHOD'] != 'POST' || empty($_POST)) {
$error = true;
// Check if fake url field is filled in, i.e. spam bot.
if (!empty($_POST['url'])) {
$error = true;
// Check that e-mail address is valid.
if ((bool) filter_var(trim($_POST['email']), FILTER_VALIDATE_EMAIL)) {
$email = trim($_POST['email']);
else {
$error = true;
if (!$error) {
// Construct the mail with headers.
$name = _contact_clean_str($_POST['name'], ENT_QUOTES, true, true);
$prefix = _contact_clean_str($prefix, ENT_NOQUOTES, true, true);
$subject = _contact_clean_str($_POST['subject'], ENT_NOQUOTES, true, true);
$subject = "[$prefix] $subject";
$message = _contact_clean_str($_POST['message'], ENT_NOQUOTES);
$lines = explode("\n", $message);
array_walk($lines, '_contact_ff_wrap');
$message = implode("\n", $lines);
$headers = [
'From' => "$name <$email>",
'Sender' => $sender,
'Return-Path' => $sender,
'MIME-Version' => '1.0',
'Content-Type' => 'text/plain; charset=UTF-8; format=flowed; delsp=yes',
'Content-Transfer-Encoding' => '8Bit',
'X-Mailer' => 'Hugo - Zen',
$mime_headers = [];
foreach ($headers as $key => $value) {
$mime_headers[] = "$key: $value";
$mail_headers = join("\n", $mime_headers);
// Send the mail, suppressing errors and setting Return-Path with the "-f" option.
$success = @mail($to, $subject, $message, $mail_headers, '-f' . $sender);
$status = $success ? 'submitted' : 'error';
$contact_form_url = strtok($_SERVER['HTTP_REFERER'], '?');
// Redirect back to contact form with status.
header('Location: ' . $contact_form_url . '?' . $status, TRUE, 302);
function _contact_ff_wrap(&$line) {
$line = wordwrap($line, 72, " \n");
function _contact_clean_str($str, $quotes, $strip = false, $encode = false) {
if ($strip) {
$str = strip_tags($str);
$str = htmlspecialchars(trim($str), $quotes, 'UTF-8');
if ($encode && preg_match('/[^\x20-\x7E]/', $str)) {
$str = '=?UTF-8?B?' . base64_encode($str) . '?=';
return $str;
frjo commented Feb 7, 2018

Updated to encode name and subject when needed.

ghost commented Jan 5, 2023

Hi man. Im sorry about my english. Your script works flawless but I would like to ask something. Is that possible that the script doesnt redirect to the page but instead show an popup like "your message has being sent" and erease all the form fields?

I dont know how to do it.

frjo commented Jan 5, 2023

The script redirects back to the form with a query string indicating success or error. Use that to show a message to the user. The form should clear on the redirect since it force a page reload.

See and

ghost commented Jan 5, 2023

tried the contact.js but no lucky. after updating index.html, contact.php and contact.js now the html shows the strings between > and < before form and between form elements.

ill try to figure how to just placehold the submit button, show the popup message and then just redirect to the main html that contains the form. dont know how but ill try it. I dont need to validate any form element, just the submit button to not redirect nor update the index without showing any info regardless the forum submited or not.

edit.: well, i cant figure it out. im not a dev. im just a diy dude... maybe its time to search for another script one that i can handle, one simplier :) anyway, thank you dude for your great work on this one.

ghost commented Jan 19, 2023

Ive being trying to acomplish this but without success.

Do you have this contact form with the codes that makes it work preventing the form submit button, send the e-mail via ajax and show the message on the form div without redirecting the page and ereasing the form fields? sorry dude, im a disaster at coding.

frjo commented Jan 20, 2023

If this script does not do what you want I suggest you find another solution that do. There are plenty of contact form solutions out there.

