Let's talk
operations

The website forms only brought spam

An inbox of identical emails from the website, so nobody read them. About ten real enquiries a day were arriving, and one form had rejected every genuine one.

· · updated

A hallway floor covered in a drift of identical blank white envelopes beside a door.

Your admin inbox fills with emails from the website, every one titled the same. They pile into a single thread. Somebody opens one, sees nothing useful, and the whole thread is written off as spam. Meanwhile the dealership application form, the drone enquiry form and the export enquiry form appear to produce nothing, and the sales team has stopped expecting anything from the website at all. The website is Aries Agro’s.

When we read the server logs, the submissions were real: about ten submissions a day, from ordinary phones and browsers, with dealers’ own email addresses. There was one bot pattern and no bot protection at all. The “spam” was mostly customers.

The cost was in what the forms did with them. The dealership application emailed one of its 38 fields and discarded the rest, including all six uploaded documents: the tax registration, the licence, the identity proofs. The drone enquiry form had rejected every genuine submission since the day it was built. The export enquiry dropped the country and the products of interest, the two fields that make an export enquiry actionable. And the newsletter sign-ups were being sent to a personal mailbox.

What was actually going on

Every one of the seven forms had shipped with the stock subject line, which refers to a field called “your subject”. No form on the site had that field. So every notification arrived with the same title, and the mail client did what mail clients do with identical titles: it collapsed 17 unrelated enquiries into one thread.

The notification templates had drifted from the forms. The dealership application’s email was a copy of the generic contact form’s, so it knew about one field. The drone form’s template set its reply address to an email field the form did not have.

The drone form’s failure was the strangest. Its mobile number field had been given a minimum and maximum of ten. On that kind of field those limits constrain the value, not the length, so the only number that ever passed was the number ten itself. We proved it live: a real mobile number returned “too large a number”, and typing 10 sent the mail.

What we changed

All seven forms were rewritten against the fields they actually render, with a distinct subject for each (“Dealership application: firm, contact”), a working reply address, and the six documents attached. Everything routes to the sales mailbox, careers to HR, and the recipients are set explicitly per form rather than inherited from wherever the site’s settings happened to point. The forms were renamed, because the name is the email heading.

Submissions are now stored on the site as well as emailed. Until then, the emails were the only record, and a discarded email was a lost enquiry.

A light guard went in with no third-party service and no CAPTCHA: a hidden field that only a bot fills, a check on how long the visitor spent on the page, a per-address limit, and rejection of throwaway addresses. Two details of that guard matter. The time on page is stamped in the visitor’s browser, not on the server, because the site’s pages are cached at the edge and a server-side timestamp would have been frozen into the cached page, measuring the age of the cache rather than the visitor. And the per-address limit is fifteen an hour rather than five, because Indian mobile carriers put many subscribers behind one address.

The server had also been recording the cache network’s addresses for every visitor rather than the visitor’s own, which blinds any limit by address. That was corrected.

Two other things turned up. A product-enquiry pop-up form was live nowhere on the site; the only submission it had ever received was our test. And 17 submissions had come from an unrelated company’s website posting to this site’s form endpoint by mistake, all of them rejected, so no enquiry was lost that way.

We caught one bug of our own during testing. The routine that strips empty rows from an email matched too greedily, and one empty field emptied the entire drone email. It was fixed and verified with five rows kept and one dropped.

What it did not fix

The drone form still collects a phone number and no email address, so its notification has no reply address. The automatic acknowledgements to visitors were repaired but left switched off, because turning them on emails customers, and that is the client’s call. And because the drone form sits on nineteen product pages, an enquiry about a soil-treatment product still arrives titled “Drone enquiry”.

The mechanism

Seven notification templates that no longer matched the seven forms they served, one validation rule that constrained the wrong thing, and no record of a submission anywhere but the email it generated. None of it was visible from the inbox, which only showed the symptom: identical subjects.

Where this ends up

A form is a small piece of software with a contract, and this one had drifted from it for years without anybody noticing. That is the kind of system custom software development exists to build and, more to the point, to keep honest once it is live.

Working on something like this?

We build this kind of software, and we staff the teams that do.

Get in touch