How to use the Form Endpoint
Create an endpoint
Generate a POST URL. It is live immediately and needs no configuration.
Point your form at it
Set the form action attribute to the URL and the method to post. Every named input is captured, with no field configuration required.
Receive submissions
Read submissions in the browser or have them forwarded to an email address as they arrive.
The one dynamic feature a static site needs
Static sites are faster, cheaper and dramatically simpler to operate than the alternatives - right up to the contact form. A form needs somewhere to post, and suddenly the whole architecture is under pressure from one feature on one page.
The usual escapes are all worse than the problem. A serverless function means a deployment pipeline and a runtime to maintain. A third-party embed drags in scripts and an iframe that never matches your design. A mailto link fails for anyone without a configured desktop mail client, which is most people.
A form endpoint keeps the site static and the form native HTML. No JavaScript is required for it to work at all, which also means it keeps working for the visitors whose scripts failed to load.
Handling spam
A public form endpoint will receive spam - it is not a question of whether. The cheapest effective defence is a honeypot: a field hidden with CSS that humans never see and bots fill in reflexively. Any submission with that field populated is discarded.
A timing check is a useful second layer, since a form submitted a fraction of a second after loading was not filled in by a person. Both work without a CAPTCHA, which is worth avoiding: CAPTCHAs cost real conversions and are hardest for exactly the visitors least able to work around them.
What to do after submission
Send the visitor to a thank-you page rather than leaving them on a blank response. It confirms the message arrived, gives you something to measure as a conversion, and prevents the resubmission that happens when someone refreshes an unclear page.
Also decide what you will do with the data before you collect it. A contact form gathers personal information, so collect only what you need, say what it will be used for, and do not retain it longer than the conversation requires.
Frequently asked questions
- Do I need JavaScript for the form to work?
- No. A plain HTML form with an action and a post method works. JavaScript is optional if you want to submit without a page navigation.
- How are submissions delivered?
- They are captured at the endpoint and readable in the browser, and can be forwarded to an email address as they arrive.
- How do I stop spam without a CAPTCHA?
- A hidden honeypot field that bots fill and humans never see, combined with a minimum time between page load and submission, stops most automated spam without any friction for real visitors.
- Can I use this with a form on Netlify, GitHub Pages or S3?
- Yes. The endpoint is a plain URL, so it works from any host - static or otherwise - with no platform-specific setup.