FORMS · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP

Hosted forms

Build a form in the dashboard, show it on your site, and get every submission by email.

A hosted form is a form you build in the dashboard. SecureSMTP keeps its fields and settings. On WordPress the plugin shows it with a shortcode. On any other site your server reads the form and sends the submissions to the API. Every submission is stored and emailed to you.

Already have your own form? You do not need the builder. Send its submissions with the Forms API.

Build a form

  1. Open Form builder in the dashboard (/app/forms/builder) and create a form with a name.
  2. The slug is made from the name. You can change it: lowercase letters, numbers and dashes, up to 80 characters, unique in your account. The shortcode and the API use the slug.
  3. A new form starts with three fields: name, email and message. Add, remove and reorder fields. Each field has a label, a key (the name attribute), a type, a placeholder and a required switch. Keys must be unique in the form.
  4. Set the options below and click Save changes. The live preview shows the form as visitors will see it.

Field types

TypeShown in the builder asNotes
textShort text—
emailEmailUsed for Reply-To and the auto-reply.
telPhone—
urlURL—
numberNumber—
textareaLong text—
selectDropdownOptions, one per line.
checkboxCheckbox—
dateDate—
timeTime—

Field keys can be up to 60 characters and labels up to 200. In the form definition each field is stored as { name, label, type, placeholder, required, options }.

Settings

SettingKeyWhat it does
Submit button textsubmit_labelUp to 80 characters. Default “Send message”.
Success messagesuccess_messageShown after a submission. Up to 500 characters.
Notification recipientsnotify_emails, notify_emailUp to 3 addresses that get each submission. The first is required. notify_email holds the first one.
Auto-responderconfirm_enabled, confirm_from_name, confirm_subject, confirm_bodyAn email to the person who filled in the form. See below.
Brand colorbrand_colorA hex color such as #FF5500.
Corner roundnessradius_presetsharp, small, medium, large or pill.
Field backgroundfield_tonelight, subtle or dark.
Submit alignmentbutton_alignleft, center, right or block (full width).
Cardcard_wrapWrap the form in a card.

Auto-responder

When it is on, the person who filled in the form gets an email with your subject and body. It is sent only when the submission contains an email address, and never for a submission classified as spam or over the monthly limit, to a suppressed address, or to someone who unsubscribed from your site. Replies to it go to the first notification recipient. If the subject is empty, it is “Thanks — site name”.

The body can be plain text or HTML. You can use these placeholders in the subject and the body. Values typed by the visitor are HTML-escaped in the body. A placeholder that cannot be filled is left as it is.

PlaceholderReplaced with
{name}The first non-empty value of a field called name, full_name, first_name, your-name or similar; otherwise the first field whose key contains “name”.
{email}The submitter’s email address (see below).
{form_name}The form name.
{site_name}The site’s display name.
{site_domain}The site’s domain, for example example.com.
{field:KEY}The value of the field with key KEY, for example {field:phone}.

How the email address is found: the value of a field with the key email, e_mail, your-email, your_email or mail; otherwise the first value that looks like an email address. The same address becomes the Reply-To of the notification you receive.

Show the form on WordPress

Install the WordPress plugin, add the site’s API key, and put the shortcode on any page or post:

Shortcode
[securessmtp_form slug="contact"]

Pages that use the older [qcs_form slug="…"] shortcode keep working with plugin 1.23.1 or later. The plugin keeps a copy of the form for 5 minutes, so a change in the builder can take up to 5 minutes to show on your site.

Use a hosted form outside WordPress

Your server does the work, because both calls need the API key:

  1. Read the form with GET /forms/render/{slug}.
  2. Build the HTML from form.fields and form.settings.
  3. Let the form post to your own server.
  4. From your server, send the values to POST /forms/submit. See Forms API for a full example.
curl https://securessmtp.com/api/v1/forms/render/contact \
  -H "x-securessmtp-api-key: $SECURESSMTP_API_KEY"
Response
{
  "ok": true,
  "form": {
    "id": "6f0c2d1e-8a4b-4c3d-9e2f-1a2b3c4d5e6f",
    "name": "Contact",
    "slug": "contact",
    "fields": [
      {
        "name": "name",
        "label": "Your name",
        "type": "text",
        "required": true,
        "placeholder": "Jane Doe"
      },
      {
        "name": "email",
        "label": "Email",
        "type": "email",
        "required": true,
        "placeholder": "[email protected]"
      },
      {
        "name": "message",
        "label": "Message",
        "type": "textarea",
        "required": false,
        "placeholder": "Tell us a bit about your project"
      }
    ],
    "settings": {
      "submit_label": "Send message",
      "success_message": "Thanks. We will be in touch.",
      "notify_email": "[email protected]",
      "brand_color": "#FF5500",
      "radius_preset": "medium",
      "button_align": "left",
      "field_tone": "light",
      "card_wrap": false
    },
    "updated_at": "2026-10-07T09:30:00.000Z"
  }
}
  • The response can be cached for 60 seconds (Cache-Control: public, max-age=60).
  • POST /forms/submit does not read the saved settings. Pass the notification recipients, the from name and the auto-responder (confirm) in the request yourself.
  • form_id in POST /forms/submit must be a positive whole number. The id above is a UUID and is not accepted there, so use your own number for each form.
  • Errors: 400 invalid_slug, 404 form_not_found, 410 form_archived. See the error catalogue.

Where submissions show

  • By email. Each submission is emailed to the notification recipients with the subject “New form name submission — site domain”. Reply-To is the visitor’s email address, so you can answer straight away.
  • In the dashboard. Submissions (/app/forms/submissions) lists every stored submission with the time, site, form, a preview, the spam class (legitimate, suspicious or spam) and the email status. You can filter by site and by class.

Spam and submissions over your plan’s monthly limit are stored too, but not emailed. See Spam protection and Plans and limits.