For many sites, the main objective is to capture contact information and sales leads, and a contact form asking for a simple name, email, phone and enquiry message is a perfect way to achieve this. Typically, on submission, these forms will send an email to the site owner that may contain either the full enquiry or a notification for the site owner to review the enquiry via their CRM.
Should you also send an email to the site visitor who has just submitted the form?
Sending such an email can confirm the details of what was submitted and when, allowing the site visitor to reference this in any further correspondence.
In many cases, the confirmation email sent to the customer is just another annoyance; the customer knows what they submitted and you are forcing them to file or delete the email.
The noise and validation challenge
When you place an order on a website, you have made payment, which (in general) proves that you are a human and legitimately interested in the business. However, on contact forms, there is no such validation step, you enter details, and the website sends a confirmation email to the address entered.
Form spam has been a challenge for site owners for many years, and there are many tools to help identify legitimate from spam submissions, most commonly this is to use a Captcha such as Google’s eponymous Recaptcha “I’m not a robot” using image identification to prove humanity. However, AI is increasingly able to complete such challenges.
Allowing spam form submissions to be sent can hinder your sites email sending reputation with both your own provider, and others, making genuine emails sent afterwards less likely to reach their intended destination.

When confirmation spam can turn malicious
Imagine opening your inbox that normally contains a handful of emails each morning and instead finding 5,000+ emails. You may have been the victim of a scam campaign where the scammer is using a plethora of sites that send a form submission confirmation email to fill your inbox.
This is known by a few names, such as email bombing or inbox flooding and is something we have seen happen.
Why would they do that?
The answer is surprisingly simple: they want to hide an important email.
One such example is that for a .com domain transfer, if a domain is unlocked and a transfer request is placed, it triggers a notification email to the current owner giving them x days to decline the transfer or it will be automatically completed.
If the scammer is able to trigger such an email then they need to make sure that the victim won’t notice that email. What better way to do so than bury it within 4,999 other junk emails? Most people will then delete the one legitimate email amongst that avalanche of junk, thus allowing the transfer to complete.
What’s more, while I’ve taken a site owner and domain as the example here, in fact the victim may not even run a website or own any domains, they could be a relative of yours, someone who has just missed a notice that they’ve made a large financial transaction, where the attacker had obtained their login separately and the email avalanche gave them enough time to move the funds out of reach of the authorities.
What can be done to prevent this scam?
This is where site owners come in. If your site sends a confirmation email after a form submission, but doesn’t validate that the person submitting it is legitimate first, it’s worth reconsidering that approach. In many cases, a simple on-screen “thank you” message is a better experience for genuine visitors than an automated email confirmation.
You could be doing your bit to make the internet a little bit safer, less noisy and less full of scams and spam while at the same time helping retain the reputation of your site and email.