Contact forms

Why your contact form must not send “From” the visitor’s email (use Reply-To)

Setting the From address to the person who filled in the form makes the email look forged, and Gmail and Outlook treat it that way. Send from your own domain and put the visitor in Reply-To. Settings for every major form plugin.

October 3, 2026 · 6 min read

It seems logical: a visitor fills in your form, so the email should come from them, and you can press Reply. Many form plugins even suggest it. In practice it is one of the most common reasons contact form emails go to spam or never arrive.

This is one cause among several. For the complete checklist, see Contact form not sending email? Why it happens and how to fix it.

Why it fails

When a visitor with a @gmail.com address uses your form, your website’s server sends an email that says it is from [email protected]. The receiving server checks: is this server allowed to send for gmail.com? It is not. SPF fails, there is no valid gmail.com DKIM signature, and DMARC fails.

From the receiver’s point of view this looks exactly like a forged phishing email. Domains with a strict DMARC policy, such as yahoo.com and aol.com, tell receivers to reject it outright. The rest usually end up in spam. Which one happens depends on each visitor’s email provider, which is why the problem seems random.

The correct setup

  • From: an address on your domain, for example Your Site <[email protected]>. Your sending service must be covered by that domain’s SPF record and sign with its DKIM key.
  • Reply-To: the visitor’s email address. When you press Reply, your email program uses this address, so the conversation works exactly as before.

Keep the visitor’s address in the message body too. If anyone forwards the email, the Reply-To header can be lost, but the address in the text stays.

Where to change it in each form plugin

PluginSet From to your domainPut the visitor in Reply-To
Contact Form 7Mail tab → FromMail tab → Additional headers: Reply-To: [your-email]
WPFormsSettings → Notifications → From EmailSettings → Notifications → Reply-To (choose the Email field)
Elementor Pro formsActions After Submit → Email → From EmailEmail → Reply-To (choose the Email field)
Gravity FormsSettings → Notifications → From EmailNotifications → Reply To (insert the Email field merge tag)
Fluent FormsEmail Notifications → From EmailEmail Notifications → Reply To (the Email field)
ForminatorEmail Notifications → the sender (From) addressEmail Notifications → Reply-to address (the Email field)

Menu names change between plugin versions. If you cannot find one of these, open the form’s notification or email settings and look for the sender and reply-to fields.

Check it worked

Submit the form using a Gmail address, open the email you receive, and in Gmail choose ⋮ → Show original. SPF, DKIM and DMARC should all say PASS. Then press Reply and confirm it is addressed to the visitor.

If you send through SecureSMTP, this is handled for you. The email is sent from SecureSMTP’s verified address or your own verified domain, and the address your form put in From is moved into Reply-To automatically.

Frequently asked questions

If the From address is my own domain, how do I reply to the visitor?

Put the visitor’s email in the Reply-To header. Email programs send replies to the Reply-To address, so pressing Reply goes straight to the visitor.

Which address should I use as the From address?

An address on your own domain that your sending service is allowed to send for, such as [email protected] or [email protected]. It does not need to be a real mailbox, but it must be on a domain whose SPF and DKIM cover the service sending the email.

Why did this setup work before and stop now?

Gmail, Yahoo and Microsoft have tightened authentication checks since 2024. Email that claims to come from a domain it was not sent for is now far more likely to be rejected or sent to spam than a few years ago.

Related reading

Fix email delivery on your site

SecureSMTP delivers WordPress, Shopify, and custom form emails with SPF + DKIM + DMARC alignment. Free tier covers most small sites.