Skip to main content

Overview

Every form has its own settings page. Open it from your dashboard by choosing Edit Form Settings from the menu next to a form — or from the same menu inside a form’s submission view. The page is split into four sections, listed down the left. Beside them you will find the things you need while setting a form up: the form’s endpoint URL, its code snippet, and a Send test submission button that posts a sample entry to your live endpoint so you can confirm the whole path works.
If you have any suggestions for features or improvements, please reach out to us through our support page.

Start here

Follow our quickstart guide.

The header

Form name and a single Active switch sit at the top of the page, next to Save.
Switching a form to Inactive stops it accepting submissions entirely — the endpoint rejects every post until you switch it back on. Existing submissions are untouched.
Changes are not saved until you press Save. While you have unsaved edits the header shows an Unsaved changes marker, and leaving the page asks you to confirm.

General

Form Name: a name for your own reference. Only you see it. Response Type: what the submitter’s browser gets back after posting.
  • Redirect — send them to a page of your own. Choosing this reveals a Success URL and a Failure URL; both must be full URLs including https://.
  • JSON — respond with a JSON status message, for forms you submit with JavaScript.
  • None — respond with a bare status code and nothing else.
Submission list columns: the two fields shown beside the date in this form’s submission list. The dropdowns offer the field names this form has actually received, so you can show name and company on a newsletter form rather than the email and message that a new form starts with. Either column can be set to None.
A form that has not received a submission yet has no field names to offer. Send a test submission from the form settings page and the names will appear here.

Notifications

Send to: the address that receives notifications and summaries.
You can only select from a list of verified emails associated with your Crunchforms account. To learn about verifying additional email addresses, read the Add Email Addresses Guide.
Email me each submission: an email as each submission arrives. Email me a daily summary: one digest instead of, or alongside, the individual emails. Remove Crunchforms branding: removes Crunchforms branding and the dashboard link from your notification emails. Available on paid plans.

Whitelabeling notification emails

Send notifications that look like they came from you

Spam protection

Two independent layers. You can use either, both, or neither. At the top of the section, Blocked traffic shows what these layers have actually caught on this form — how many submissions were blocked this month, the breakdown by reason, and when the last one arrived. The same panel appears above your submission list.

See what was blocked, and why

Reading the tally, and the warning that fires when a captcha starts rejecting everyone

Honeypot field

A field humans never see and bots fill in anyway. If anything arrives in it, the submission is rejected. Type a name, or press the button to generate one. As soon as a name is set, the page shows you the exact hidden input to paste into your page — and the code snippet in the left-hand panel includes it automatically.
Crunchforms checks the saved field name. If you change the name here, save before you update your page — otherwise the two no longer match and the trap catches nothing.

Add a Honeypot Field

Easy protection against simple bots using a hidden field

Captcha

One choice, three options: None, Cloudflare Turnstile, or reCAPTCHA v3. Selecting a provider reveals only that provider’s fields.
Whichever provider you pick, your page must send a valid token with every submission or every submission is rejected. Set the captcha up on your page and here at the same time.
Because the choice is exclusive, switching providers clears the settings of the one you switched away from. Crunchforms will not let you save a provider with an empty secret key — that combination rejects all traffic and used to be a very quiet way to break a form. reCAPTCHA v3 additionally requires an Action, matching the one your page passes to grecaptcha.execute(). A blank action is the opposite failure: reCAPTCHA is skipped entirely and every submission is accepted. Forms saved in that state before the check existed are flagged as Not working on their settings page.
Secret keys are never shown back to you in full. A saved key displays as •••••••• plus its last four characters, so you can tell which key is stored without exposing it; press Replace key to enter a new one.

Validate with Cloudflare Turnstile

Advanced bot protection using Cloudflare Turnstile

Validate with Google reCAPTCHA v3

Advanced bot protection using Google reCAPTCHA v3

Danger zone

Delete form permanently removes the form and every submission it has received, and any page still posting to its endpoint stops working. It cannot be undone.
To stop receiving submissions without losing anything, switch the form to Inactive in the header instead.

Next steps

Explore advanced configurations and features:

Set up a Honeypot Field

Get easy protection against simple bots using a hidden field

Set up Cloudflare Turnstile

Advanced bot protection using Cloudflare Turnstile

Set up Google Recaptcha

Advanced bot protection using Google reCaptcha v3

Add additional email addresses

Add and verify additional email addresses to receive form submission notifications

Need Help?

Get Support

Send us a note