Help · Content & Design · Forms & Spam Protection

Forms and Spam Protection

Contact forms, inquiries on product pages, callback services, and custom forms: This guide explains where to enable forms, where inquiries are routed, when they become tickets, and how to curb spam using reCAPTCHA, required logins, and limits.

At a Glance

  • Store forms: You can enable or disable the contact form, “Inquiry” and “Price Quote” on the product page, “Request a Quote,” “Inquiry About Cart,” and the callback service individually.
  • Recipients: The contact form sends inquiries to the selected department; the other forms send them to specific addresses or to the shop operator’s email address.
  • Tickets Instead of Email: Contact, product, and price inquiries from registered customers can be converted into tickets upon request. Inquiries from guests are sent as emails.
  • Custom Forms: Go to CMS → Create Forms and embed them in CMS pages or categories using the xoContentEditor.
  • Spam: Set up reCAPTCHA v3, require login, and use a daily limit; disable unused forms.

In this guide


Forms at a Glance

The store comes with these forms. Each has its own button, its own recipients, and its own email template.

FormIn the StoreEnable under
Contact Form"Contact" pageSettings → General → Basic Settings → Contact Form: Status (new stores: on)
Inquiry about the item"Inquiry" button on the product pageSettings → Design → Product Detail View → “Questions About This Item” on/off (new stores: on)
Price Suggestion"Price Suggestion" button on the product pageSettings → Design → Product Detail View → Price Suggestion on/off (new stores: off)
Request a Quote"Request a Quote" button on the product pageSettings → Design → Product Detail View → “Request a Quote” button (new stores: off)
Cart Inquiry"Inquiry about the shopping cart" button below the product list in the shopping cartSettings → Checkout → Shopping Cart → Show “Add to Cart” button (new stores: off)
Callback Service"Free Callback" boxBox under CMS → Box Manager; settings under Settings → Design → CallBack
Custom FormsCMS Pages and CategoriesCMS → Forms

Additional forms are described in separate guides: the newsletter sign-up under “Newsletter,” the cancellation form under “Cancellation Button,” the availability alert under “Product Notification, ” and the ticket form in the customer account under “Tickets & Tasks.”


Set Up the Contact Form

The contact form is the “Contact” page. Customers select a department, describe their request, and provide an email address or phone number.

Contact page in the store as a guest: on the left, the contact information box with the showroom address; on the right, a note about the ticket after logging in; the section buttons "General Questions" (selected) and "Orders"; the filled-in fields for name, email address, phone number, and “Inquiry,” the “Privacy Policy” checkbox unchecked, and the “Next” button disabled

The contact page with two departments: As long as the privacy policy checkbox is unchecked, the “Continue” button remains disabled. Click to enlarge.

Departments and Recipients

Under Settings → General → Basic Settings → Contact Page Data, create a “Department” with an “Email Address” for each line, for example, “General Questions” and “Orders.” In the store, the departments appear as buttons, with the first one preselected. The inquiry is sent to the email address of the selected department.

Use the “Language” column to display a department in only one language. Rows with “---” appear in all languages. If no entries are made, the inquiry is sent to the “Shop Owner’s Email Address.”

Required Information

The subject and at least one contact method—email address or phone number—are required. The name is optional. The subject must be a complete sentence; the form rejects nonsensical phone numbers and names.

If you want the phone number to always be required, set Settings → Checkout → Customer Details → Phone Number to “ mandatory.” This setting also applies to registration. Logged-in customers do not see these fields: name, email, and phone number are retrieved from the customer’s account.

Setting up data for the contact page in edit mode: A table with the columns Language, Department, and Email Address; two rows—General Inquiries at info@example.com and Orders at bestellung@example.com—both labeled with the language ---; below that, the New Entry button and the Save buttons

“Data for Contact Page”: one department per line with a recipient address; the language “---” displays it in all languages. Click to enlarge.

Texts and Notes in the Form

The contact form does not have a separate field for a note. You have three options:

  • Editing text: Under Tools → xoLanguage, select “Framework” Frontend and “Section” store-contact. There, you can edit the heading “Contact Request,” “Contact Information,” or the note “To contact us, you must…,” which is visible only to guests. If you enter your text as a “custom value,” it will be preserved during updates.
  • “Contact Information” box: This displays Settings → General → Basic Settings → Store Address and Contact Information. This information also appears in the footer of your emails; see CMS Manager & Emails.
  • Additional field with note: Using the Form Builder, you can add custom fields to the contact form, each with its own “note text”; see Expanding Store Forms.

Disable the contact form

Set Settings → General → Basic Settings → Contact Form: Status to false. Anyone who visits the page will then be redirected to the home page. Afterward, remove any links to the contact page, such as those in the footer; see CMS Manager & Emails. Often, requiring a login is sufficient instead of disabling the form; see Login Required.


Inquiries on the Product Page and in the Shopping Cart

Four forms are associated with products. All open as pop-up windows above the page. The form specifies the product; for the shopping cart form, it lists all items in the shopping cart.

Product Inquiry

The “Inquiry” button opens the “Product Inquiry” window. The customer writes their question and, as a guest, provides their name, email, and phone number. The store includes any selected product attributes in the request. Enable or disable this feature via Settings → Design → Product Detail View → Product Inquiry “Questions About the Product” on/off.

The same window opens for “Price Upon Request” (see Prices & Customer Groups) and for items with the “Click-to-Call Product” toggle, which can only be purchased via inquiry. If you use one of these features, keep the product inquiry enabled; otherwise, the inquiry will not be received.

Price Suggestion

With “Price Proposal,” the customer specifies a price at which they would be willing to purchase the item. To enable this, go to Settings → Design → Product Detail View → Price Proposal On/Off. The button appears only for items with a visible price. For individual items, you can disable it within the item by selecting “Lock for Price Proposal.”

Request a Quote

The request results in a quote: an order with “Quote” status that you can edit in the “Quotes” tab of the order overview; see Orders. Even guests without a customer account can submit requests.

  • “Request Quote” button: Located below the shopping cart button, below the product options, or among the other actions.
  • “Quote Status IDs”: At least one order status. Without it, the button will not appear.
  • “Quote Form: Active Fields”: Which information the form requests. The email address is always included.
  • “Send Quote Emails” (customer, store owner) and “Quote Email with PDF.”

Cart Inquiry

Under Settings → Checkout → Shopping Cart → Show “Shopping Cart Inquiry” Button, a button appears in the shopping cart below the item list. The customer uses this to ask a question about their entire shopping cart. The “Shopping Cart Inquiry” email contains all items from the shopping cart. Shopping cart inquiries are always sent as emails, never as tickets.

The settings for “Request a Quote” are all located under Settings → Design → Product Detail View. The “Recipients and Emails” section shows where the requests are sent.


Callback Service

Through the callback service, a customer can request a phone call by providing their name, phone number, email address, preferred date, time slot, and reason for the call.

  1. Under CMS → Box Manager, enable the “Free Callback” box. It links to the callback page.
  2. Under Settings → Design → CallBack → Email Departments CALLBACK (Callback), enter the departments along with their email addresses. If no departments are listed, the request will be sent to the store owner’s email address.
  3. Under “Business Hours for CALLBACK (Callback),” add a note, such as your phone hours. It will appear on the callback page.
  4. Set weekdays and time slots: “Callback: Selectable Weekdays,” “Callback: Time Slots” with your own times and order, and “Callback: Offer ‘Any Time’ option.” At least one weekday must remain selectable.from 4.9.10

Callback requests arrive as an email titled “Callback Request,” not as a ticket.


Where Requests Go

Each form has its own recipients. If no specific address is entered, the request goes to the “Shop operator’s email address” under Settings → Interfaces → Email Marketing / CRM → Email Options.

FormAs an email toAs a ticket
Contact FormSelected department from “Contact Page Data”Ticket, notification sent to the department’s email address
Inquiry about the item“Different email address (product inquiry and shopping cart inquiry)”Ticket, notification sent to the same address
Price quote“Different email address (price quote)”Ticket, notification sent to the same address
Shopping Cart Inquiry“Different email address (product inquiry and shopping cart inquiry)”No ticket
Callback serviceSelected department from “Email Departments CALLBACK (Callback)”No ticket
Request a quoteCopy to the store operator if “Send quote emails” includes themA quote is included in the orders
Custom forms"Recipient Email (for Email Destination)" in the formDestination “Create Ticket” or “Ticket + Email”

The two “alternate” addresses are also listed in the email options. If your own address is missing from a ticket, the notification goes to “Infomail Tickets” under Settings → General → Tickets & Tasks.

Reply Directly

The email sent to you includes the customer’s name and email address as the reply-to address. Use “Reply” in your email program to write to them directly.

Confirmation to the Customer

If a request arrives as an email, the customer receives an “Request Confirmation” email with your privacy policy as a PDF. If it becomes a ticket, they’ll see the ticket number in the store and can track the ticket in their customer account.

Email Templates

You can edit the templates “Contact Inquiry,” “Product Inquiry,” “Price Inquiry,” “Shopping Cart Inquiry,” “Callback Request,” “Inquiry Confirmation,” and “Quote Email” can be edited under CMS → Emails & Marketing / Automations; see CMS Manager & Emails.


Ticket Instead of Email

Contact, product, and price inquiries can be routed to the ticket system upon request. There, your team can process them with assigned responsibilities, status updates, and a history.

Settings Group: Tickets & Tasks, Lines 1 through 13: Ticket System On/Off, Product Inquiries as Tickets, Product Inquiry: Login Required, Price Inquiries as Tickets, Price Inquiry: Login Required, Contact Requests as Tickets, and Contact Form: Login Required, all set to true; following a dashed line, lines 31 through 33 with Info Mail Tickets (tickets@example.com) and Maximum Number of Tickets per Day: 10

Ticket delivery, required login, and daily limit are located in the “Tickets & Tasks” group; the dotted line marks omitted rows. Click to enlarge.

  1. Settings → General → Tickets & Tasks → Ticket System On/Off set to true.
  2. In the same group, set “Contact Inquiries as Tickets,” “Product Inquiries as Tickets,” and “Price Inquiries as Tickets” to true. In new stores, all three are enabled by default.
  3. A ticket is created only for logged-in customers. Inquiries from guests are still sent as emails. Guests see a note in the form stating that their inquiry will be recorded as a ticket once they log in.

Login Required

With “Contact Form: Login Required,” “Product Inquiry: Login Required,” and “Price Inquiry: Login Required,” you allow only logged-in customers to submit inquiries. Guests see a message with a link to log in; the form is disabled for them. In new stores, all three options are enabled by default.

The login requirement for the contact form always applies, even if contact inquiries are received via email. The login requirement for product and price inquiries only applies if the ticket system and “Product Inquiries as Tickets” or “Price Inquiries as Tickets” are enabled.

Notification to Your Team

For every new ticket generated from one of these forms, the store sends an email with a link to the ticket to the address specified in the “Recipient” and “Emails” fields. The template is called “New Support Ticket Request.”

Daily Limit

“Maximum Number of Tickets per Day” limits how many tickets an email address can create within a 24-hour period. New stores have a limit of 10; leaving this field blank removes the limit. If the limit is reached, a notification is sent instead of a ticket.

The Tickets & Tasks guide explains how to process tickets, assign them to responsible parties, and respond to them.


Finding Incoming Requests

Where a request appears depends on whether it was received via email, as a ticket, or through a custom form.

RequestHere’s where you’ll find them
Created as a ticketTools → Tickets & Tasks → Tickets & Tasks
Sent as an email, including all shopping cart and callback requestsin the recipient’s inbox. The store does not maintain a separate list of these emails.
Custom formsCMS → Forms, “Inbox” tab, regardless of the form’s destination
Additional fields in the store’s formsalso in the inbox, in addition to tickets or emails
Quote RequestsOrder Overview, “Quotes” tab
ConsentsTools → Data Protection Management, only the record without the content of the request

The forms inbox

Under CMS → Forms, you can switch between “Administration” and “Inbox” at the top. The inbox counts unread submissions and filters by “All” and “Unread.” A row expands to show all details under “Submitted Data.” Options include “Open in Ticket” if the submission has been converted into a ticket, as well as “Mark as Read” and “Delete.”

Form Management, Inbox tab: 2 unread, filters All (3) and Unread (2), search field, and three submissions; the top entry from Erika Musterfrau for the "sample request" form, with the destination set to "Ticket + Email" and Ticket 28001, is expanded and displays the following under "Submitted Data": Name, Email, Phone, Quantity, and Message, as well as the buttons "Open in Ticket," "Mark as Read," and "Delete"

The Inbox collects every submission from your own forms, expanded to show all details and the path to the ticket. Click to enlarge.

Who Can View the Inbox

  • Users who are allowed to edit the settings can create, modify, and delete forms, as well as delete submissions.
  • The Inbox and uploaded files can be shared with a specific user group: Under Settings → Administrators → User Groups, read access to “Forms” is sufficient. This allows, for example, a vacation substitute to process inquiries without access to the other settings.from 4.10

Create Your Own Forms with the Form Builder

Under CMS → Forms, you can create forms without programming—for example, for sample orders, appointment requests, or inquiries about custom products. A live preview shows the form as you build it.

  1. Under CMS → Forms, click “New Form” in the “Administration” tab.
  2. In the “Settings” tab, assign the “Form Key,” such as musteranfrage: only lowercase letters, numbers, and underscores. It cannot be changed after creation. The keys contact, product_inquiry, price_inquiry, and ticket are reserved for the Shop Forms extension.
  3. Select the “Destination” (table below) and, for email, enter the “Recipient Email (for Email Destination).”
  4. Fill in the “Title,” “Introductory Text,” “Success Message,” and “Subject (Email/Ticket)” for each language. You can switch the language at the top.
  5. In the “Fields” tab, click “Field” to add fields. For each field, set the field type, “Label,” “Help Text,” “Placeholder in Field,” and “Required Field.” You can change the order by dragging the fields.
  6. Toggle “Active” on at the top and save by clicking “Save and Close” or “Refresh.” The store will not display an inactive form. The “CSRF” toggle next to it (enabled by default) verifies a security token from the visitor’s session when the form is submitted; leave it enabled.
Form Builder for the sample request, "Fields" tab: on the left, the field list—Name, Email, Phone, Quantity, and Message; in the middle, the settings for the “Email” field, including the field key, field type “Email,” required field, label, tooltip, custom error message, minimum and maximum characters, and placeholder in the field; on the right, a live preview of the form

In the “Fields” tab, select a field on the left, configure it in the middle, and immediately see a preview on the right. Click to enlarge.

Field Types

Field TypePurpose
"Text," "Text Area"Single-line or multi-line input, with “Min. characters” and “Max. characters”
“Email,” “Phone”Contact information. The “Email” field checks for correct spelling.
“Numbers”Quantities and measurements, with “Minimum,” “Maximum,” and “Increment”
“Dropdown,” “Multiple Selection (Radio)”Selection from options. Each option has a value and a label for each language; one can be preselected as “Default.” In “Text Mode,” you enter multiple options line by line.
“Switch”Yes/No, as a required field, for example, for confirmation. The “tooltip” appears next to the switch.
“Date”Date selected from the calendar. Works reliably starting with version 4.10; in older versions, use a text field.
“Color”Color selection
“File Upload”Allow users to upload files; see FileUpload.from 4.10

For required fields, use “Custom Error Message” to specify the text the customer sees if a field is left blank. Custom messages for each rule—such as “too short” or “too large”—are also available for optional fields.from 4.10

The Purpose of a Submission

PurposeWhat happens
“Collect Only (Inbox)”The submission is stored only in the inbox; no one receives an email.
“Send Email”Email is sent to the “Recipient Email.” If this field is left blank, the email is sent to the shop operator’s email address.
“Create Ticket”Creates a ticket in the ticket system without sending an email to your team. Default setting for new forms.
“Ticket + Email”Creates a ticket and also sends an email to the “Recipient Email.”

Every submission also appears in the inbox. The subject line is “Subject (Email/Ticket),” otherwise it’s the title of the form.

Form Builder, Settings tab: Form key: musteranfrage (cannot be changed after creation), Destination: Ticket + Email, Recipient email: anfragen@example.com, below that the German texts for Title, Introductory Text, Success Message, and Subject (Email/Ticket), and on the right, the live preview

In the “Settings” tab, you can specify the key, destination, recipients, and the form’s text for each language. Click to enlarge.

To ensure replies reach the customer: Create exactly one field of the “Email” type. Its address will serve as the reply-to address for the email and the customer’s address on the ticket. If there are multiple email fields, the store uses the one with the field key email. A text field with the field key name provides the name. If the email field is missing, your own address will appear as the sender.

Embedding Forms

A custom form appears in the store as soon as you embed it in a page. In contrast, you can add your own fields directly to the store’s forms.

In a CMS page or category

Enable the xoContentEditor in the page content, add the “Form / Embedded Form” block, and select your form under “Select Form.” This can be done on CMS pages (CMS → CMS Manager) and in the category description (Products → Categories / Products); see xoContentEditor.XONIC Premium: Content Editor

  • Embed a form only once per page.
  • Do not copy the block as HTML into a normal text field. When you save, the store removes the necessary script, and the form gets stuck at “Form is loading…”
  • The selection shows only active, standalone forms.

Extend Shop Forms

In the overview under CMS → Forms, you’ll find the “Integrations” tab with “Contact Form,” “Product Inquiry,” “Price Inquiry,” and “Ticket Form.” Click “Create” to add custom fields to the respective shop form, such as a customer number or a batch number.

The fields appear in the shop form. The shop form handles shipping, tickets, and spam protection, so the destination is set to “Collect Only (Inbox)” by default. The information appears in the ticket or email and additionally in the inbox. Exception: For the contact form, the additional fields appear only in the ticket and in the inbox, not in the email.

After updating to 4.10: Before enabling reCAPTCHA for an embedded form, save the pages containing the form module once. To refresh all pages at once, go to CMS → Template Manager (xoContentEditor), “Migration” tab,and click “Render All Content.” from 4.10

Allowing File Uploads

Using the “File Upload” field type, customers can submit drawings, photos, or documents—for example, for a custom order.from 4.10

Allowed Formats

Under “Allowed Formats,” select groups. At least one group must remain selected; new fields will support CAD drawings and documents by default.

  • “CAD Drawings”: dxf, dwg, step, stp, iges, igs, stl
  • “Documents”: pdf, txt, csv, doc, docx, xls, xlsx
  • “Images”: jpg, jpeg, png, gif, webp
  • “Archives”: zip, 7z. Disabled by default because the store cannot verify the contents of an archive.

Size and Number

For each field, you can set the “Max. Size (MB)” and “Max. Files” (up to 10 files). The following setting applies to the entire store : Settings → Privacy → General → Form Upload: maximum file size (MB), set to 10 by default.

The server’s limits also apply. If they are lower, the smaller value takes precedence. If the store cannot save a file, the customer receives an error message instead of a confirmation.

Delivery as a Link

Emails and tickets contain a link to each file. This link opens the file in the backend, but only after logging in and with the appropriate permissions for the forms. If you are not logged in, the link will open the file directly after you log in. In the ticket, the files remain as links; they do not become ticket attachments.

Additionally as an attachment

“Send files additionally as attachments” appears under “Recipient Email” if the destination is “Send Email” or “Ticket + Email” and the form has a file field. Disabled by default. Intended for recipients without backend access. The email is sent only to you, never to the customer.

The total size of all attachments in a single submission must not exceed the value set in Settings → Privacy → General → Form Email: Maximum Attachment Size (MB); the default is 7. Larger files remain as links. If your mail server rejects the email, the store will resend it without the attachment, including a notification. Do not increase this value until your mail server accepts larger emails.

Uploaded files come from third parties and are not scanned for malware. Only open files you expect to receive.

Retention Period

Under Settings → Privacy → General → Form Upload: Retention (days), default 365, the shop deletes uploaded files when you log in to the backend. Setting this to 0 disables this feature. The submission in the inbox and the proof of consent remain. If you delete a submission from the inbox, the store deletes its associated files as well.


Privacy Checkboxes and Proof of Consent

Whether customers must consent to the processing of their information is determined by Settings → Privacy → General → Privacy Consents for General Forms, which applies to all store forms collectively.

ValueIn the formProof
opt-in (new stores)A checkbox that the customer must check. Until then, the submit button is disabled.Yes, confirmation type “Checkbox”
adviseA note stating that the customer agrees by submitting the formYes, confirmation type “Note”
falseNo noticeNo

This setting applies to the contact form, product inquiry, price quote, request a quote, shopping cart inquiry, callback service, ticket form, and the newsletter page. The notice text links to your privacy policy.

The Record

Before sending the message, the store creates an entry under Tools → Privacy Management: type of request (e.g., “Contact Request (Email)”), confirmation type, date, IP address, and deletion date after ten years. The email address is not stored in plain text, but as a hash value. Therefore, search for the full address. The content of the inquiry is not stored there.

Custom Forms

Custom forms automatically check the data protection box according to the same settings and generate a record stating “Form submission (Form Builder).” A previously custom-created consent checkbox is then nolonger necessary.from 4.10

In older versions, you create a “Switch” field as a required field for this purpose and include the consent text in the “Note text.” This switch does not generate a record in the data protection management system.

There is a separate setting for sharing the email address with shipping service providers at checkout: “Data Protection Consent for Shipping: Mode.” If set to “ inherit,” it follows the general setting; if set to “ mandatory,” the customer must select “Yes” or “No.” This setting applies only to the shipping service providers listed under “Data Protection Consents for Shipping Service Providers.”


Curbing Spam

Form spam usually comes from programs that fill out forms en masse. Work through the measures from top to bottom: The first ones are the most effective.

What Works Out of the Box

Every time a form is submitted, the store’s forms check whether the request comes from a valid session, whether a field invisible to humans has been filled out, and whether the form was submitted too quickly or remained open for too long. This check is always enabled; there is no setting to disable it. The store does not use a CAPTCHA image puzzle.

  1. Set up reCAPTCHA v3. Google invisibly determines whether a human is submitting the form. It protects the contact form, callback service, product inquiries, price quotes, request for a quote, shopping cart inquiries, newsletter, availability alerts, “Forgot Password,” and the cancellation form. Instructions can be found under reCAPTCHA v3.
  2. Allow only logged-in customers. With “Contact Form: Login Required” and the login buttons for product and price inquiries, only customers with an account can submit forms—see Login Required. This is the most effective way to prevent spam. Guests can then contact you via the email address listed in your legal notice.
  3. Set a daily limit. “Maximum number of tickets per day” limits the number of inquiries that arrive as tickets.
  4. Disable unused forms. Every form you don’t need is one less potential entry point. The toggles are located under “Forms at a Glance.”
  5. Enable the quote form’s spam filter. “Quote Form: Spam Content Filter” under Settings → Design → Product Detail View blocks typical advertising text in the name, company, and location fields. Enabled by default.
  6. Protect your own forms. In the Form Builder, under the “Settings” tab, the “Abuse Protection” section includes “Decoy Field” (enabled by default), “reCAPTCHA v3” (disabled), “Minimum Fill Time (seconds)” (3), and “Submissions per IP per hour” (10). This section is missing in extended shop forms; in those cases, protection is provided by the shop-form.from 4.10

"Forgot Password"

The form is throttled by default: The shop does not respond to repeated requests within a short period of time with a new email. The shop’s response is always the same, regardless of whether the email address has an account or not. The shop performs an additional check using reCAPTCHA.

Spam via an embedded form

Starting with version 4.10, enable the form’s abuse protection for this purpose. In older versions, temporarily set the form to inactive or contact us.

No technical check can stop requests that a human types manually. The mandatory login and daily limit help prevent these.

Setting up reCAPTCHA v3

reCAPTCHA v3 is a service provided by Google. It does not display a checkbox or a puzzle, but instead assigns each submission a score between 0.0 (likely a program) and 1.0 (likely a human).

  1. Create a key for reCAPTCHA v3 on Google at google.com/recaptcha. Enter all the domains under which your store is accessible.
  2. Under Settings → Interfaces → Spam Protection → Google reCAPTCHA, enter the “Google reCAPTCHA V3 SiteKey (Website Key)” and the “Google reCAPTCHA V3 SecretKey (Secret Key).” The store will only perform the reCAPTCHA check once both fields are filled in.
  3. Leave the “Minimum reCAPTCHA Score (0.0 to 1.0)” set to 0.5. If the score is lower than this, the storewill reject the submission.from 4.9.47
  4. Test: Submit the contact form. reCAPTCHA verifies guests and logged-in customers the same way, so you can also test it using your customer account.
"Google reCAPTCHA" settings group under "Interfaces," "Spam Protection": informational text, SiteKey and SecretKey with example values, minimum reCAPTCHA score of 0.5, and next to it, the expanded help text regarding the minimum score

reCAPTCHA v3: Enter the website key and secret key, and set the minimum score to 0.5. Click to enlarge.

If real customers are being rejected

Customers will then see “The reCAPTCHA verification failed. Please try again.” Check the following:

  • Key type: A key for reCAPTCHA v2 (“I’m not a robot”) won’t work. Create a new one for v3.
  • New key: Google learns from your store’s traffic. A new key tends to be stricter at first.
  • Forms from emails: Users who open a form directly via a link—such as the return form in the order confirmation email—often receive low scores. A high threshold will block these customers in particular.
  • Threshold: Gradually lower the minimum score, for example to 0.4 or 0.3.
  • Log: The store logs every rejected check along with the reason and score. Our support team uses this information to determine whether the key or the threshold is the cause.from 4.9.47

Privacy

Mention reCAPTCHA in your privacy policy. Consult your data protection advisor to determine whether you need to obtain additional consent for this.

The store only loads reCAPTCHA when a visitor uses a protected form—that is, when they click on it, type into it, or submit it. It does not load simply by visiting the page.from 4.9.144


Frequently Asked Questions

How do I protect the contact form from spam?

First, set up reCAPTCHA v3; see reCAPTCHA v3. If that isn’t enough, go to Settings → General → Tickets & Tasks and set “Contact Form: Login Required” to true. Then only logged-in customers can submit the form. All steps in the correct order are listed under “Curbing Spam.”

How do I protect product inquiries from spam?

reCAPTCHA v3 works here as well. If you want to receive only inquiries from logged-in customers, enable the ticket system, “Product Inquiries as Tickets,” and “Product Inquiry: Login Required” under Settings → General → Tickets & Tasks. For price quotes, use the corresponding toggles “Price Quotes as Tickets” and “Price Quote: Login Required.” If you don’t need price quotes, turn them off.

Is there a CAPTCHA that customers have to type in?

No. The store uses Google’s reCAPTCHA v3. It works invisibly, without checkboxes or image puzzles. In addition, there’s the verification that runs by default in all store forms; see “Curbing Spam.”

How do I set up reCAPTCHA v3 correctly?

Create a reCAPTCHA v3 key on Google that includes all your store’s domains, enter the website key and secret key under Settings → Interfaces → Spam Protection → Google reCAPTCHA, and leave the minimum score set to 0.5. A reCAPTCHA v2 key will not work. See reCAPTCHA v3 for details.

How do I disable the contact form?

Go to Settings → General → Basic Settings → “Contact Form: Status” = false. Anyone who visits the contact page will be redirected to the homepage. Afterward, remove any links to the contact page, such as those in the footer. To prevent spam, requiring users to log in is often sufficient; see “Login Required.”

Where do I set who the contact form sends to?

Under Settings → General → Basic Settings → “Data for Contact Page.” Each line represents a department with its own email address, optionally for a single language only. If no entries are made, the request goes to the store owner’s email address.

How do I add a note to the contact form?

There is no separate field for this. Edit the form’s text under Tools → xoLanguage (“Framework” Frontend, “Section” store-contact) as a “custom value,” or add a field labeled “Note” to the contact form under CMS → Forms. The “Contact Information” box displays your store address and contact details from the basic settings. See Contact Form for details.

Where is the product inquiry sent?

As an email to the “alternate email address (product inquiry and shopping cart inquiry)” under Settings → Interfaces → Email Marketing / CRM → Email Options. If this field is left blank, the inquiry is sent to the store owner’s email address. If the inquiry becomes a ticket, it appears under Tools → Tickets & Tasks, and the notification is sent to the same address or, alternatively, to “Infomail Tickets.”

How do I configure whether product inquiries arrive as emails or as tickets?

Under Settings → General → Tickets & Tasks, select “Product inquiries as tickets.” To do this, “Ticket system on/off” must be enabled. A ticket is created only for logged-in customers; inquiries from guests are still sent as emails. The same toggles are available for the contact form and price quotes.

Why does an inquiry arrive as an email even though “as a ticket” is selected?

Because the customer was not logged in. Tickets are only created for customers with an account. If you want all inquiries to become tickets, also enable the login requirement for the form.

Where can I view contact and shopping cart inquiries in the store?

Contact inquiries that arrive as tickets are located under Tools → Tickets & Tasks. Anything sent as an email can be found in the recipient’s inbox. Shopping cart inquiries always arrive as emails; there is no list for them in the backend. Submissions from custom forms can be found under CMS → Forms in the “Inbox” tab.

A customer reports that the form isn’t submitting. What should I check?

If a message about logging in appears, the login requirement is enabled. If a reCAPTCHA verification message appears, check reCAPTCHA v3. If the form freezes without displaying a message, have the customer refresh the page and resubmit the form. If none of this helps, contact us: We’ll check the logs to see why the submission was rejected.

The browser’s autofill feature no longer triggers the spam protection. In older versions, it could block legitimate customers without any notification.from 4.9.144

Why are the additional fields from the contact form missing from the email?

For the contact form, only the ticket includes the additional fields from the form builder. If the request arrives as an email, you’ll find the additional fields under CMS → Forms in the “Inbox” tab. For product inquiries and price quotes, they’re also included in the email.

Can I create a form that allows customers to upload files?

Yes, using the “File Upload” field type in the Form Builder. You specify the allowed formats, size, and number of files. The files are sent as a link and, if desired, additionally as email attachments; see File Upload.from 4.10

Does the customer receive confirmation of their inquiry?

If the request is sent to you via email, the customer receives an “Request Confirmation” email with your privacy policy as a PDF. If it becomes a ticket, the customer sees the ticket number in the store and can find the ticket in their customer account. Custom forms display the “Success Message” from the Form Builder.

How long are uploaded files stored?

For as long as specified under Settings → Privacy → General → “Form Upload: Retention (Days)”; the default is 365 days. After that, the store deletes the files the next time you log in to the backend. Setting this to 0 disables deletion.from 4.10

Further Guides

We help protect your forms

We’ll set up reCAPTCHA with you, analyze the logs when customers are blocked, and work with you to build forms for your inquiries.

Contact Support Now