Forms and Spam Protection
Contact forms, inquiries on product pages, callback services, and custom forms: This guide explains where to enable forms, where inquiries are routed, when they become tickets, and how to curb spam using reCAPTCHA, required logins, and limits.
At a Glance
- Store forms: You can enable or disable the contact form, “Inquiry” and “Price Quote” on the product page, “Request a Quote,” “Inquiry About Cart,” and the callback service individually.
- Recipients: The contact form sends inquiries to the selected department; the other forms send them to specific addresses or to the shop operator’s email address.
- Tickets Instead of Email: Contact, product, and price inquiries from registered customers can be converted into tickets upon request. Inquiries from guests are sent as emails.
- Custom Forms: Go to CMS → Create Forms and embed them in CMS pages or categories using the xoContentEditor.
- Spam: Set up reCAPTCHA v3, require login, and use a daily limit; disable unused forms.
In this guide
Forms at a Glance
The store comes with these forms. Each has its own button, its own recipients, and its own email template.
| Form | In the Store | Enable under |
|---|---|---|
| Contact Form | "Contact" page | Settings → General → Basic Settings → Contact Form: Status (new stores: on) |
| Inquiry about the item | "Inquiry" button on the product page | Settings → Design → Product Detail View → “Questions About This Item” on/off (new stores: on) |
| Price Suggestion | "Price Suggestion" button on the product page | Settings → Design → Product Detail View → Price Suggestion on/off (new stores: off) |
| Request a Quote | "Request a Quote" button on the product page | Settings → Design → Product Detail View → “Request a Quote” button (new stores: off) |
| Cart Inquiry | "Inquiry about the shopping cart" button below the product list in the shopping cart | Settings → Checkout → Shopping Cart → Show “Add to Cart” button (new stores: off) |
| Callback Service | "Free Callback" box | Box under CMS → Box Manager; settings under Settings → Design → CallBack |
| Custom Forms | CMS Pages and Categories | CMS → Forms |
Additional forms are described in separate guides: the newsletter sign-up under “Newsletter,” the cancellation form under “Cancellation Button,” the availability alert under “Product Notification, ” and the ticket form in the customer account under “Tickets & Tasks.”
Set Up the Contact Form
The contact form is the “Contact” page. Customers select a department, describe their request, and provide an email address or phone number.
The contact page with two departments: As long as the privacy policy checkbox is unchecked, the “Continue” button remains disabled. Click to enlarge.
Departments and Recipients
Under Settings → General → Basic Settings → Contact Page Data, create a “Department” with an “Email Address” for each line, for example, “General Questions” and “Orders.” In the store, the departments appear as buttons, with the first one preselected. The inquiry is sent to the email address of the selected department.
Use the “Language” column to display a department in only one language. Rows with “---” appear in all languages. If no entries are made, the inquiry is sent to the “Shop Owner’s Email Address.”
Required Information
The subject and at least one contact method—email address or phone number—are required. The name is optional. The subject must be a complete sentence; the form rejects nonsensical phone numbers and names.
If you want the phone number to always be required, set Settings → Checkout → Customer Details → Phone Number to “ mandatory.” This setting also applies to registration. Logged-in customers do not see these fields: name, email, and phone number are retrieved from the customer’s account.
“Data for Contact Page”: one department per line with a recipient address; the language “---” displays it in all languages. Click to enlarge.
Texts and Notes in the Form
The contact form does not have a separate field for a note. You have three options:
- Editing text: Under Tools → xoLanguage, select “Framework” Frontend and “Section”
store-contact. There, you can edit the heading “Contact Request,” “Contact Information,” or the note “To contact us, you must…,” which is visible only to guests. If you enter your text as a “custom value,” it will be preserved during updates. - “Contact Information” box: This displays Settings → General → Basic Settings → Store Address and Contact Information. This information also appears in the footer of your emails; see CMS Manager & Emails.
- Additional field with note: Using the Form Builder, you can add custom fields to the contact form, each with its own “note text”; see Expanding Store Forms.
Disable the contact form
Set Settings → General → Basic Settings → Contact Form: Status to false. Anyone who visits the page will then be redirected to the home page. Afterward, remove any links to the contact page, such as those in the footer; see CMS Manager & Emails. Often, requiring a login is sufficient instead of disabling the form; see Login Required.
Inquiries on the Product Page and in the Shopping Cart
Four forms are associated with products. All open as pop-up windows above the page. The form specifies the product; for the shopping cart form, it lists all items in the shopping cart.
Product Inquiry
The “Inquiry” button opens the “Product Inquiry” window. The customer writes their question and, as a guest, provides their name, email, and phone number. The store includes any selected product attributes in the request. Enable or disable this feature via Settings → Design → Product Detail View → Product Inquiry “Questions About the Product” on/off.
The same window opens for “Price Upon Request” (see Prices & Customer Groups) and for items with the “Click-to-Call Product” toggle, which can only be purchased via inquiry. If you use one of these features, keep the product inquiry enabled; otherwise, the inquiry will not be received.
Price Suggestion
With “Price Proposal,” the customer specifies a price at which they would be willing to purchase the item. To enable this, go to Settings → Design → Product Detail View → Price Proposal On/Off. The button appears only for items with a visible price. For individual items, you can disable it within the item by selecting “Lock for Price Proposal.”
Request a Quote
The request results in a quote: an order with “Quote” status that you can edit in the “Quotes” tab of the order overview; see Orders. Even guests without a customer account can submit requests.
- “Request Quote” button: Located below the shopping cart button, below the product options, or among the other actions.
- “Quote Status IDs”: At least one order status. Without it, the button will not appear.
- “Quote Form: Active Fields”: Which information the form requests. The email address is always included.
- “Send Quote Emails” (customer, store owner) and “Quote Email with PDF.”
Cart Inquiry
Under Settings → Checkout → Shopping Cart → Show “Shopping Cart Inquiry” Button, a button appears in the shopping cart below the item list. The customer uses this to ask a question about their entire shopping cart. The “Shopping Cart Inquiry” email contains all items from the shopping cart. Shopping cart inquiries are always sent as emails, never as tickets.
The settings for “Request a Quote” are all located under Settings → Design → Product Detail View. The “Recipients and Emails” section shows where the requests are sent.
Callback Service
Through the callback service, a customer can request a phone call by providing their name, phone number, email address, preferred date, time slot, and reason for the call.
- Under CMS → Box Manager, enable the “Free Callback” box. It links to the callback page.
- Under Settings → Design → CallBack → Email Departments CALLBACK (Callback), enter the departments along with their email addresses. If no departments are listed, the request will be sent to the store owner’s email address.
- Under “Business Hours for CALLBACK (Callback),” add a note, such as your phone hours. It will appear on the callback page.
- Set weekdays and time slots: “Callback: Selectable Weekdays,” “Callback: Time Slots” with your own times and order, and “Callback: Offer ‘Any Time’ option.” At least one weekday must remain selectable.from 4.9.10
Callback requests arrive as an email titled “Callback Request,” not as a ticket.
Where Requests Go
Each form has its own recipients. If no specific address is entered, the request goes to the “Shop operator’s email address” under Settings → Interfaces → Email Marketing / CRM → Email Options.
| Form | As an email to | As a ticket |
|---|---|---|
| Contact Form | Selected department from “Contact Page Data” | Ticket, notification sent to the department’s email address |
| Inquiry about the item | “Different email address (product inquiry and shopping cart inquiry)” | Ticket, notification sent to the same address |
| Price quote | “Different email address (price quote)” | Ticket, notification sent to the same address |
| Shopping Cart Inquiry | “Different email address (product inquiry and shopping cart inquiry)” | No ticket |
| Callback service | Selected department from “Email Departments CALLBACK (Callback)” | No ticket |
| Request a quote | Copy to the store operator if “Send quote emails” includes them | A quote is included in the orders |
| Custom forms | "Recipient Email (for Email Destination)" in the form | Destination “Create Ticket” or “Ticket + Email” |
The two “alternate” addresses are also listed in the email options. If your own address is missing from a ticket, the notification goes to “Infomail Tickets” under Settings → General → Tickets & Tasks.
Reply Directly
The email sent to you includes the customer’s name and email address as the reply-to address. Use “Reply” in your email program to write to them directly.
Confirmation to the Customer
If a request arrives as an email, the customer receives an “Request Confirmation” email with your privacy policy as a PDF. If it becomes a ticket, they’ll see the ticket number in the store and can track the ticket in their customer account.
Email Templates
You can edit the templates “Contact Inquiry,” “Product Inquiry,” “Price Inquiry,” “Shopping Cart Inquiry,” “Callback Request,” “Inquiry Confirmation,” and “Quote Email” can be edited under CMS → Emails & Marketing / Automations; see CMS Manager & Emails.
Ticket Instead of Email
Contact, product, and price inquiries can be routed to the ticket system upon request. There, your team can process them with assigned responsibilities, status updates, and a history.
Ticket delivery, required login, and daily limit are located in the “Tickets & Tasks” group; the dotted line marks omitted rows. Click to enlarge.
- Settings → General → Tickets & Tasks → Ticket System On/Off set to true.
- In the same group, set “Contact Inquiries as Tickets,” “Product Inquiries as Tickets,” and “Price Inquiries as Tickets” to true. In new stores, all three are enabled by default.
- A ticket is created only for logged-in customers. Inquiries from guests are still sent as emails. Guests see a note in the form stating that their inquiry will be recorded as a ticket once they log in.
Login Required
With “Contact Form: Login Required,” “Product Inquiry: Login Required,” and “Price Inquiry: Login Required,” you allow only logged-in customers to submit inquiries. Guests see a message with a link to log in; the form is disabled for them. In new stores, all three options are enabled by default.
Notification to Your Team
For every new ticket generated from one of these forms, the store sends an email with a link to the ticket to the address specified in the “Recipient” and “Emails” fields. The template is called “New Support Ticket Request.”
Daily Limit
“Maximum Number of Tickets per Day” limits how many tickets an email address can create within a 24-hour period. New stores have a limit of 10; leaving this field blank removes the limit. If the limit is reached, a notification is sent instead of a ticket.
The Tickets & Tasks guide explains how to process tickets, assign them to responsible parties, and respond to them.
Finding Incoming Requests
Where a request appears depends on whether it was received via email, as a ticket, or through a custom form.
| Request | Here’s where you’ll find them |
|---|---|
| Created as a ticket | Tools → Tickets & Tasks → Tickets & Tasks |
| Sent as an email, including all shopping cart and callback requests | in the recipient’s inbox. The store does not maintain a separate list of these emails. |
| Custom forms | CMS → Forms, “Inbox” tab, regardless of the form’s destination |
| Additional fields in the store’s forms | also in the inbox, in addition to tickets or emails |
| Quote Requests | Order Overview, “Quotes” tab |
| Consents | Tools → Data Protection Management, only the record without the content of the request |
The forms inbox
Under CMS → Forms, you can switch between “Administration” and “Inbox” at the top. The inbox counts unread submissions and filters by “All” and “Unread.” A row expands to show all details under “Submitted Data.” Options include “Open in Ticket” if the submission has been converted into a ticket, as well as “Mark as Read” and “Delete.”
The Inbox collects every submission from your own forms, expanded to show all details and the path to the ticket. Click to enlarge.
Who Can View the Inbox
- Users who are allowed to edit the settings can create, modify, and delete forms, as well as delete submissions.
- The Inbox and uploaded files can be shared with a specific user group: Under Settings → Administrators → User Groups, read access to “Forms” is sufficient. This allows, for example, a vacation substitute to process inquiries without access to the other settings.from 4.10
Create Your Own Forms with the Form Builder
Under CMS → Forms, you can create forms without programming—for example, for sample orders, appointment requests, or inquiries about custom products. A live preview shows the form as you build it.
- Under CMS → Forms, click “New Form” in the “Administration” tab.
- In the “Settings” tab, assign the “Form Key,” such as
musteranfrage: only lowercase letters, numbers, and underscores. It cannot be changed after creation. The keyscontact,product_inquiry,price_inquiry, andticketare reserved for the Shop Forms extension. - Select the “Destination” (table below) and, for email, enter the “Recipient Email (for Email Destination).”
- Fill in the “Title,” “Introductory Text,” “Success Message,” and “Subject (Email/Ticket)” for each language. You can switch the language at the top.
- In the “Fields” tab, click “Field” to add fields. For each field, set the field type, “Label,” “Help Text,” “Placeholder in Field,” and “Required Field.” You can change the order by dragging the fields.
- Toggle “Active” on at the top and save by clicking “Save and Close” or “Refresh.” The store will not display an inactive form. The “CSRF” toggle next to it (enabled by default) verifies a security token from the visitor’s session when the form is submitted; leave it enabled.
In the “Fields” tab, select a field on the left, configure it in the middle, and immediately see a preview on the right. Click to enlarge.
Field Types
| Field Type | Purpose |
|---|---|
| "Text," "Text Area" | Single-line or multi-line input, with “Min. characters” and “Max. characters” |
| “Email,” “Phone” | Contact information. The “Email” field checks for correct spelling. |
| “Numbers” | Quantities and measurements, with “Minimum,” “Maximum,” and “Increment” |
| “Dropdown,” “Multiple Selection (Radio)” | Selection from options. Each option has a value and a label for each language; one can be preselected as “Default.” In “Text Mode,” you enter multiple options line by line. |
| “Switch” | Yes/No, as a required field, for example, for confirmation. The “tooltip” appears next to the switch. |
| “Date” | Date selected from the calendar. Works reliably starting with version 4.10; in older versions, use a text field. |
| “Color” | Color selection |
| “File Upload” | Allow users to upload files; see FileUpload.from 4.10 |
For required fields, use “Custom Error Message” to specify the text the customer sees if a field is left blank. Custom messages for each rule—such as “too short” or “too large”—are also available for optional fields.from 4.10
The Purpose of a Submission
| Purpose | What happens |
|---|---|
| “Collect Only (Inbox)” | The submission is stored only in the inbox; no one receives an email. |
| “Send Email” | Email is sent to the “Recipient Email.” If this field is left blank, the email is sent to the shop operator’s email address. |
| “Create Ticket” | Creates a ticket in the ticket system without sending an email to your team. Default setting for new forms. |
| “Ticket + Email” | Creates a ticket and also sends an email to the “Recipient Email.” |
Every submission also appears in the inbox. The subject line is “Subject (Email/Ticket),” otherwise it’s the title of the form.
In the “Settings” tab, you can specify the key, destination, recipients, and the form’s text for each language. Click to enlarge.
email. A text field with the field key name provides the name. If the email field is missing, your own address will appear as the sender.Embedding Forms
A custom form appears in the store as soon as you embed it in a page. In contrast, you can add your own fields directly to the store’s forms.
In a CMS page or category
Enable the xoContentEditor in the page content, add the “Form / Embedded Form” block, and select your form under “Select Form.” This can be done on CMS pages (CMS → CMS Manager) and in the category description (Products → Categories / Products); see xoContentEditor.XONIC Premium: Content Editor
- Embed a form only once per page.
- Do not copy the block as HTML into a normal text field. When you save, the store removes the necessary script, and the form gets stuck at “Form is loading…”
- The selection shows only active, standalone forms.
Extend Shop Forms
In the overview under CMS → Forms, you’ll find the “Integrations” tab with “Contact Form,” “Product Inquiry,” “Price Inquiry,” and “Ticket Form.” Click “Create” to add custom fields to the respective shop form, such as a customer number or a batch number.
The fields appear in the shop form. The shop form handles shipping, tickets, and spam protection, so the destination is set to “Collect Only (Inbox)” by default. The information appears in the ticket or email and additionally in the inbox. Exception: For the contact form, the additional fields appear only in the ticket and in the inbox, not in the email.
Allowing File Uploads
Using the “File Upload” field type, customers can submit drawings, photos, or documents—for example, for a custom order.from 4.10
Allowed Formats
Under “Allowed Formats,” select groups. At least one group must remain selected; new fields will support CAD drawings and documents by default.
- “CAD Drawings”: dxf, dwg, step, stp, iges, igs, stl
- “Documents”: pdf, txt, csv, doc, docx, xls, xlsx
- “Images”: jpg, jpeg, png, gif, webp
- “Archives”: zip, 7z. Disabled by default because the store cannot verify the contents of an archive.
Size and Number
For each field, you can set the “Max. Size (MB)” and “Max. Files” (up to 10 files). The following setting applies to the entire store : Settings → Privacy → General → Form Upload: maximum file size (MB), set to 10 by default.
The server’s limits also apply. If they are lower, the smaller value takes precedence. If the store cannot save a file, the customer receives an error message instead of a confirmation.
Delivery as a Link
Emails and tickets contain a link to each file. This link opens the file in the backend, but only after logging in and with the appropriate permissions for the forms. If you are not logged in, the link will open the file directly after you log in. In the ticket, the files remain as links; they do not become ticket attachments.
Additionally as an attachment
“Send files additionally as attachments” appears under “Recipient Email” if the destination is “Send Email” or “Ticket + Email” and the form has a file field. Disabled by default. Intended for recipients without backend access. The email is sent only to you, never to the customer.
The total size of all attachments in a single submission must not exceed the value set in Settings → Privacy → General → Form Email: Maximum Attachment Size (MB); the default is 7. Larger files remain as links. If your mail server rejects the email, the store will resend it without the attachment, including a notification. Do not increase this value until your mail server accepts larger emails.
Retention Period
Under Settings → Privacy → General → Form Upload: Retention (days), default 365, the shop deletes uploaded files when you log in to the backend. Setting this to 0 disables this feature. The submission in the inbox and the proof of consent remain. If you delete a submission from the inbox, the store deletes its associated files as well.
Privacy Checkboxes and Proof of Consent
Whether customers must consent to the processing of their information is determined by Settings → Privacy → General → Privacy Consents for General Forms, which applies to all store forms collectively.
| Value | In the form | Proof |
|---|---|---|
opt-in (new stores) | A checkbox that the customer must check. Until then, the submit button is disabled. | Yes, confirmation type “Checkbox” |
advise | A note stating that the customer agrees by submitting the form | Yes, confirmation type “Note” |
false | No notice | No |
This setting applies to the contact form, product inquiry, price quote, request a quote, shopping cart inquiry, callback service, ticket form, and the newsletter page. The notice text links to your privacy policy.
The Record
Before sending the message, the store creates an entry under Tools → Privacy Management: type of request (e.g., “Contact Request (Email)”), confirmation type, date, IP address, and deletion date after ten years. The email address is not stored in plain text, but as a hash value. Therefore, search for the full address. The content of the inquiry is not stored there.
Custom Forms
Custom forms automatically check the data protection box according to the same settings and generate a record stating “Form submission (Form Builder).” A previously custom-created consent checkbox is then nolonger necessary.from 4.10
In older versions, you create a “Switch” field as a required field for this purpose and include the consent text in the “Note text.” This switch does not generate a record in the data protection management system.
There is a separate setting for sharing the email address with shipping service providers at checkout: “Data Protection Consent for Shipping: Mode.” If set to “ inherit,” it follows the general setting; if set to “ mandatory,” the customer must select “Yes” or “No.” This setting applies only to the shipping service providers listed under “Data Protection Consents for Shipping Service Providers.”
Curbing Spam
Form spam usually comes from programs that fill out forms en masse. Work through the measures from top to bottom: The first ones are the most effective.
What Works Out of the Box
Every time a form is submitted, the store’s forms check whether the request comes from a valid session, whether a field invisible to humans has been filled out, and whether the form was submitted too quickly or remained open for too long. This check is always enabled; there is no setting to disable it. The store does not use a CAPTCHA image puzzle.
- Set up reCAPTCHA v3. Google invisibly determines whether a human is submitting the form. It protects the contact form, callback service, product inquiries, price quotes, request for a quote, shopping cart inquiries, newsletter, availability alerts, “Forgot Password,” and the cancellation form. Instructions can be found under reCAPTCHA v3.
- Allow only logged-in customers. With “Contact Form: Login Required” and the login buttons for product and price inquiries, only customers with an account can submit forms—see Login Required. This is the most effective way to prevent spam. Guests can then contact you via the email address listed in your legal notice.
- Set a daily limit. “Maximum number of tickets per day” limits the number of inquiries that arrive as tickets.
- Disable unused forms. Every form you don’t need is one less potential entry point. The toggles are located under “Forms at a Glance.”
- Enable the quote form’s spam filter. “Quote Form: Spam Content Filter” under Settings → Design → Product Detail View blocks typical advertising text in the name, company, and location fields. Enabled by default.
- Protect your own forms. In the Form Builder, under the “Settings” tab, the “Abuse Protection” section includes “Decoy Field” (enabled by default), “reCAPTCHA v3” (disabled), “Minimum Fill Time (seconds)” (3), and “Submissions per IP per hour” (10). This section is missing in extended shop forms; in those cases, protection is provided by the shop-form.from 4.10
"Forgot Password"
The form is throttled by default: The shop does not respond to repeated requests within a short period of time with a new email. The shop’s response is always the same, regardless of whether the email address has an account or not. The shop performs an additional check using reCAPTCHA.
Spam via an embedded form
Starting with version 4.10, enable the form’s abuse protection for this purpose. In older versions, temporarily set the form to inactive or contact us.
Setting up reCAPTCHA v3
reCAPTCHA v3 is a service provided by Google. It does not display a checkbox or a puzzle, but instead assigns each submission a score between 0.0 (likely a program) and 1.0 (likely a human).
- Create a key for reCAPTCHA v3 on Google at google.com/recaptcha. Enter all the domains under which your store is accessible.
- Under Settings → Interfaces → Spam Protection → Google reCAPTCHA, enter the “Google reCAPTCHA V3 SiteKey (Website Key)” and the “Google reCAPTCHA V3 SecretKey (Secret Key).” The store will only perform the reCAPTCHA check once both fields are filled in.
- Leave the “Minimum reCAPTCHA Score (0.0 to 1.0)” set to 0.5. If the score is lower than this, the storewill reject the submission.from 4.9.47
- Test: Submit the contact form. reCAPTCHA verifies guests and logged-in customers the same way, so you can also test it using your customer account.
reCAPTCHA v3: Enter the website key and secret key, and set the minimum score to 0.5. Click to enlarge.
If real customers are being rejected
Customers will then see “The reCAPTCHA verification failed. Please try again.” Check the following:
- Key type: A key for reCAPTCHA v2 (“I’m not a robot”) won’t work. Create a new one for v3.
- New key: Google learns from your store’s traffic. A new key tends to be stricter at first.
- Forms from emails: Users who open a form directly via a link—such as the return form in the order confirmation email—often receive low scores. A high threshold will block these customers in particular.
- Threshold: Gradually lower the minimum score, for example to 0.4 or 0.3.
- Log: The store logs every rejected check along with the reason and score. Our support team uses this information to determine whether the key or the threshold is the cause.from 4.9.47
Privacy
Mention reCAPTCHA in your privacy policy. Consult your data protection advisor to determine whether you need to obtain additional consent for this.
The store only loads reCAPTCHA when a visitor uses a protected form—that is, when they click on it, type into it, or submit it. It does not load simply by visiting the page.from 4.9.144
Frequently Asked Questions
How do I protect the contact form from spam?
How do I protect product inquiries from spam?
Is there a CAPTCHA that customers have to type in?
How do I set up reCAPTCHA v3 correctly?
How do I disable the contact form?
Where do I set who the contact form sends to?
How do I add a note to the contact form?
store-contact) as a “custom value,” or add a field labeled “Note” to the contact form under CMS → Forms. The “Contact Information” box displays your store address and contact details from the basic settings. See Contact Form for details.Where is the product inquiry sent?
How do I configure whether product inquiries arrive as emails or as tickets?
Why does an inquiry arrive as an email even though “as a ticket” is selected?
Where can I view contact and shopping cart inquiries in the store?
A customer reports that the form isn’t submitting. What should I check?
If a message about logging in appears, the login requirement is enabled. If a reCAPTCHA verification message appears, check reCAPTCHA v3. If the form freezes without displaying a message, have the customer refresh the page and resubmit the form. If none of this helps, contact us: We’ll check the logs to see why the submission was rejected.
The browser’s autofill feature no longer triggers the spam protection. In older versions, it could block legitimate customers without any notification.from 4.9.144
Why are the additional fields from the contact form missing from the email?
Can I create a form that allows customers to upload files?
Does the customer receive confirmation of their inquiry?
How long are uploaded files stored?
Further Guides
We help protect your forms
We’ll set up reCAPTCHA with you, analyze the logs when customers are blocked, and work with you to build forms for your inquiries.
Contact Support Now