_honey honeypot, webhooks, autoresponses and file attachments (multipart forms, 10 MB total per submission). Its limits: no dashboard, submissions kept 30 days and readable through its API only 5 times a day, and attachments aren't stored. Switch when you need a searchable inbox, exports or signed webhooks.Point any HTML form at one endpoint. 500 free submissions — no card, no time limit — and unlimited forms.
Create free accountFormSubmit is a good free choice for a simple contact form, and it handles file attachments, webhooks and autoresponses. It stops being enough when you need to find a submission again: there's no dashboard, the archive lasts 30 days, and uploaded files aren't kept. That's the point where a backend like splitforms makes sense.
Does FormSubmit support file attachments on a multipart form?
Yes. FormSubmit.co accepts file attachments when the form uses enctype="multipart/form-data" and a file input; several file inputs are allowed, but together the files must stay under 10 MB, and FormSubmit emails them without keeping them or exposing them through its API (FormSubmit documentation, checked October 2, 2026).
Older guides still quote a 5 MB limit: that was the documented cap until early 2026 (see FormSubmit's change history below). Without the multipart enctype, the browser sends only the file name, so no attachment arrives. For the full setup and the reasons attachments go missing (AJAX submits, the 10 MB total, uploads sent before you confirm the form), see our guide to FormSubmit file uploads and attachments.
<form action="https://formsubmit.co/[email protected]"
method="POST"
enctype="multipart/form-data">
<input type="email" name="email" required>
<input type="file" name="attachment">
<button type="submit">Send</button>
</form>The splitforms version uses the same enctype and posts to https://splitforms.com/api/submit; paid plans store up to 5 files of 5 MB each per submission, with links in the email and dashboard.
<form action="https://splitforms.com/api/submit"
method="POST"
enctype="multipart/form-data">
<input type="hidden" name="access_key" value="YOUR_ACCESS_KEY">
<input type="email" name="email" required>
<input type="file" name="attachment">
<button type="submit">Send</button>
</form>Stored files count toward your plan's storage: 500 MB on Pro and 5 GB on Annual. See how file uploads work on splitforms, or start from our HTML file upload form guide for the markup and accept/size attributes.
FormSubmit parameters
FormSubmit is configured with hidden inputs whose names start with an underscore:
| Field | What it does |
|---|---|
_captcha | Set to false to turn off reCAPTCHA (on by default) |
_honey | Honeypot; submissions with a value are ignored |
_blacklist | Comma-separated spam phrases (about 20 at most) |
_autoresponse | Instant reply to the submitter (not with AJAX or with reCAPTCHA off) |
_webhook | URL called on each submission |
_next | Thank-you page URL |
_cc | Copy to other addresses (comma-separated) |
_replyto | Sets the email's Reply-To address |
_subject | Email subject |
_template | One of 3 email templates |
AJAX endpoint: https://formsubmit.co/ajax/[email protected]. After your first confirmation, FormSubmit gives you a random-string alias to use instead of your email address.
What are FormSubmit's limits?
FormSubmit does a lot for a free service with no signup. Its limits show up once a form starts carrying leads you can't afford to lose:
- No dashboard. Submissions arrive as emails. There's no inbox to search, filter or mark as handled, and no CSV export.
- A 30-day archive with capped API reads. FormSubmit keeps submissions for 30 days, and you can call its API to read them 5 times a day.
- Attachments aren't kept. Files are emailed and then gone; you can't fetch them later through the API.
- Autoresponses have conditions.
_autoresponsedoesn't run for AJAX submissions or when reCAPTCHA is turned off. - No paid plan. There's nothing to upgrade to when you need longer history, exports or file storage.
- Use the alias, not your address. Until you swap in the random-string alias FormSubmit sends when you confirm your email, your address is visible in the form's action URL.
FormSubmit facts at a glance (verified October 2, 2026)
| Service | Free plan | Free history | Uploads on Free | Entry paid plan | Source | Checked | Last changed |
|---|---|---|---|---|---|---|---|
| splitforms | 500 submissions total (one-time, no card), unlimited forms | No automatic expiry | No (paid plans: 5 files of 5 MB per submission) | Pro: $5/month (5,000/month); Annual: $49/year (15,000/month) | splitforms.com/pricing | Pricing set | |
| FormSubmit | Unlimited submissions, no signup, no dashboard | 30 days (API, 5 reads/day) | Emailed only: multipart forms, 10 MB total, not stored | No paid plans | formsubmit.co/documentation | Seen February 21, 2026 | |
| Web3Forms | 250 submissions/month, unlimited forms | 30 days | No (Pro and Agency) | Pro: $15/month, or $149/year (about $12/month billed yearly) (10,000/month) | web3forms.com/pricing | Seen January 4, 2026 | |
| Formspree | 50 submissions/month, unlimited forms | 30 days | No (paid plans) | Personal: $15/month, or $10/month billed yearly (200/month) | formspree.io/plans | No change since May 22, 2025 |
splitforms is a competitor; prices were checked on each vendor's public pricing page on September 27, 2026 to October 10, 2026 (date per row). Archive dates come from web.archive.org snapshots: a “Seen” change happened between the linked snapshot and the one before it.
Has FormSubmit changed its limits?
- : The combined attachment limit per submission rose from 5 MB to 10 MB. First seen in the February 21, 2026 archived snapshot; the previous snapshot still showed the old terms.
How does splitforms compare with FormSubmit?
| Feature | FormSubmit | splitforms Free |
|---|---|---|
| Submission dashboard | ❌ Email only | ✅ Searchable inbox |
| Submission history | 30 days, API only (5 reads/day) | No automatic expiry on any plan |
| Spam protection | reCAPTCHA (on by default), _blacklist | Automatic spam scoring, rate limiting, spam folder |
| Honeypot spam protection | ✅ _honey | ✅ botcheck |
| File attachments | ✅ Emailed, 10 MB total, not stored | Paid plans: 5 files of 5 MB, stored |
| Webhooks | ✅ _webhook | Paid plans (from $5/mo), HMAC-signed |
| Autoresponders | ✅ Not with AJAX | Paid plans |
| CSV export | ❌ | Paid plans |
| Email kept out of page source | ✅ Random-string alias | ✅ Access key |
| Plain HTML form, no JavaScript | ✅ | ✅ |
| Free submissions | Unlimited | 500 submissions total, no card, no time limit |
| Paid plans | None | Pro $5/month or Annual $49/year |
In short: FormSubmit covers delivery well. splitforms adds the part that comes after delivery, a place to keep, search and export what people send you.
Try a working splitforms form
Submissions land in a searchable dashboard and your inbox, with automatic spam scoring. No JavaScript SDK required.
What happens next ⚡
- 📥Submission received — stored in your searchable dashboard
- 📧Email notification — delivered to your inbox instantly
- 🛡️Spam filtered — rule-based content filter + honeypot, no CAPTCHA
- 🔗Webhook fired — optional: forward to Slack, Discord, Sheets
- ↩️User redirected — to your thank-you page
500 free submissions total · No credit card
How does spam protection compare?
FormSubmit's defenses work at the form: reCAPTCHA is on by default, _honey drops submissions where a hidden field is filled, and _blacklist rejects submissions containing phrases you list (FormSubmit suggests 20 at most). They help, but there's no spam folder to review, and anything that slips through lands in your inbox.
splitforms adds automatic spam scoring on the server, on every plan including Free. Each submission is checked with:
- Content rules: link-stuffed messages, known spam phrases, disposable or malformed email addresses, suspicious domains, repeated text and gibberish
- Honeypot field detection: an invisible
botcheckfield that bots fill in and people never see - Rate limiting: per-IP throttling that stops submission floods
Flagged submissions go to a spam folder in the dashboard instead of your inbox. If something real gets caught, mark it "Not spam" and that sender is trusted from then on.
Why does a submissions dashboard matter?
A dashboard is the difference between "I think someone contacted me last Tuesday" and "here are this month's leads, sorted and searchable."
The splitforms dashboard gives you:
- Submission history: No automatic expiry on any plan, searchable by name, email, content or date
- Read / unread tracking: mark submissions as handled so nobody replies twice
- A spam folder: review flagged submissions without them cluttering your inbox
- CSV export (paid plans): download submissions for your CRM, spreadsheet or backup
FormSubmit gives you an inbox. splitforms gives you an inbox plus a record you can come back to.
How do I migrate from FormSubmit to splitforms?
Most forms take about three minutes. Change the action URL, add your access key, and rename FormSubmit's underscore fields:
<!-- BEFORE: FormSubmit -->
<form action="https://formsubmit.co/[email protected]" method="POST">
<input type="hidden" name="_subject" value="New enquiry">
<input type="hidden" name="_next" value="https://yoursite.com/thanks">
<input type="text" name="name" required>
<input type="email" name="email" required>
<textarea name="message" required></textarea>
<button type="submit">Send</button>
</form>
<!-- AFTER: splitforms -->
<form action="https://splitforms.com/api/submit" method="POST">
<input type="hidden" name="access_key" value="YOUR_ACCESS_KEY">
<input type="hidden" name="subject" value="New enquiry">
<input type="hidden" name="redirect" value="https://yoursite.com/thanks">
<input type="text" name="name" required>
<input type="email" name="email" required>
<textarea name="message" required></textarea>
<button type="submit">Send</button>
</form>_subjectbecomessubject, and_replytobecomesreplyto._nextbecomes a hiddenredirectfield, which works on every plan._honeybecomesbotcheck._captchaand_blacklistcan go; spam is scored on the server._cc,_webhookand_autoresponsemove to the form's dashboard settings. Webhooks and autoresponders are on paid plans.- Keep
enctype="multipart/form-data"and your file inputs; stored uploads need a paid plan.
Your other field names stay the same, and the form keeps working on any static host with no JavaScript.
How much does FormSubmit cost compared with splitforms?
| Plan | FormSubmit | splitforms |
|---|---|---|
| Free | Unlimited submissions by email, no dashboard | 500 submissions total (no card, no time limit), dashboard, spam filtering, email notifications |
| Pro | — | $5/mo: 5,000 submissions/month and every paid feature (webhooks, autoresponders, exports, 500 MB file storage) |
| Annual | — | $49/year (about $4.08/mo): 15,000 submissions/month, every Pro feature, 5 GB file storage |
FormSubmit costs nothing, and for a low-stakes contact form that's hard to beat. The cost shows up elsewhere: no inbox to search, a 30-day archive and files you can't get back. splitforms' Free plan covers your first 500 submissions; when you need a monthly allowance, webhooks or file storage, Pro is $5/month.
FAQ
Does FormSubmit.co support file attachments?
Yes. Add enctype="multipart/form-data" to the form and one or more file inputs; the combined size must stay under 10 MB. FormSubmit emails the files but doesn't keep them or make them available through its API.
Did FormSubmit change its attachment limit?
Yes. FormSubmit's documentation listed a 5 MB combined attachment limit in its October 30, 2025 web.archive.org snapshot and 10 MB from the February 21, 2026 snapshot onward, which is still the limit on formsubmit.co/documentation (checked October 2, 2026).
Is FormSubmit.co free?
Yes. FormSubmit is free with unlimited forms and submissions and no registration, and it has no paid plans. The trade-offs are no dashboard and a 30-day archive you can read through its API up to 5 times a day.
Is FormSubmit safe? Will my email address be exposed?
After you confirm your email address, FormSubmit sends you a random-string alias to use in the form's action instead of your email, so the address isn't visible in your page source. Keep reCAPTCHA on and add the _honey field, and avoid sending sensitive data through any email-only form service.
How do I submit to FormSubmit with fetch or AJAX?
POST JSON to https://formsubmit.co/ajax/[email protected] (or your alias) with the Content-Type and Accept headers set to application/json. Note that _autoresponse doesn't work for AJAX submissions.
How do I stop spam on a FormSubmit form?
Keep the default reCAPTCHA, add a hidden _honey input and list spam phrases in _blacklist (about 20 at most). If spam still gets through, move to a backend with server-side scoring and a spam folder you can review.
How long does FormSubmit keep submissions?
30 days, readable through its API up to 5 times a day; uploaded files aren't kept. On splitforms, every plan, Free included, keeps submissions in a searchable dashboard until you delete them.
Does FormSubmit support webhooks?
Yes. Add a hidden _webhook field with your endpoint URL and FormSubmit calls it each time the form gets a submission. On splitforms, webhooks come with every paid plan (Pro at $5/month or Annual at $49/year), are set up in the dashboard instead of your HTML, and every request is signed with an HMAC-SHA256 X-Splitforms-Signature header.
Can I see my submissions in a dashboard?
Not on FormSubmit, which emails each submission and keeps a 30-day archive you reach through its API. splitforms stores submissions in a dashboard on every plan, where you can search and sort them, mark them as read and review the spam folder. CSV export is on paid plans.
FormSubmit details checked against its documentation and AJAX documentation on September 27, 2026.