PHP Contact Form Script
A production-ready PHP contact form with AJAX submission, SMTP email delivery, reCAPTCHA spam protection, file attachments, and full GDPR compliance. Drop it into any website in minutes.
Overview
Every website needs a reliable contact form. This script provides a complete solution that handles form validation on both the client and server side, sends emails securely through SMTP, and protects against spam bots using Google reCAPTCHA. The form submits via AJAX for a seamless user experience with no page reloads.
Built on top of PHPMailer for robust email delivery, the script supports HTML email templates, file attachments, auto-responders, and stores submissions in a database for backup. It is designed to be easy to configure and integrates into any existing website design.
Key Features
- AJAX form submission without page reload
- Server-side and client-side validation
- SMTP email delivery via PHPMailer
- Google reCAPTCHA v3 integration
- Honeypot field for extra spam filtering
- File attachment support (up to 5 files)
- HTML email templates with customization
- Auto-responder to form submitter
- Database backup of all submissions
- GDPR consent checkbox and data handling
- CSRF token protection
- Rate limiting per IP address
Quick Start Code
Here is the core form handler that processes submissions securely:
Installation Steps
- Download the script package and extract the files
- Upload all files to your web server via FTP or file manager
- Edit
config.phpwith your SMTP credentials and reCAPTCHA keys - Import
database.sqlif you want submission backups (optional) - Include the form HTML snippet in your webpage
- Test the form by submitting a message to yourself
Server Requirements
| Requirement | Minimum | Recommended |
|---|---|---|
| PHP Version | 8.0 | 8.2+ |
| Web Server | Apache / Nginx | Apache with mod_rewrite |
| Database | Optional | MySQL 5.7+ |
| PHP Extensions | OpenSSL, mbstring | + PDO for database |
| SSL Certificate | Recommended | Required for reCAPTCHA |
Configuration Options
The script is highly configurable through a single config.php file. You can customize SMTP settings, toggle reCAPTCHA on or off, set file upload limits, define allowed file types, enable or disable the auto-responder, choose between database storage and flat-file logging, and customize the email template with your branding.
Spam Protection
The contact form uses a multi-layered approach to prevent spam. Google reCAPTCHA v3 runs invisibly in the background and scores each submission. A hidden honeypot field catches basic bots. Server-side rate limiting prevents flood attacks by restricting submissions per IP address within a time window. Together, these measures block virtually all automated spam without inconveniencing real users.
GDPR Compliance
The script includes a consent checkbox that must be checked before submission. It logs consent timestamps, provides a data export endpoint for subject access requests, and includes a data deletion function for right-to-erasure requests. All stored data can be automatically purged after a configurable retention period.