splitforms.com

Review · Updated

EmailJS review: email from front-end code, through your own email account

EmailJS is a legitimate email-sending service run by EmailJS Pte. Ltd. in Singapore, with servers on AWS in the US. It lets front-end code send templated emails through an email account you connect, such as Gmail or Amazon SES, using a public key. That suits contact forms and app notifications without a server. It is not a form backend: history is kept 7 days on Free and 30 on paid plans, and the public key needs the allowlist and CAPTCHA turned on.

splitforms makes a competing form backend. This review is based on EmailJS's public pricing, docs and policies, checked .

Illustration for our EmailJS review: a magnifying glass inspecting a web form, next to a checklist

EmailJS at a glance

What it isEmail-sending API and SDK that sends through an email service you connect
Free plan200 requests/month, 2 templates, 50 KB requests, 7-day history
Paid plansPersonal $9/mo, Professional $15/mo, Business $40/mo; yearly billing advertised as 20% off
Over the limitRequests dropped at 100%, no overage fees; warnings at 80%, 95% and 100%
Abuse controlsDomain allowlist (paid), IP rate limits, reCAPTCHA v2, optional private key
AttachmentsNone on Free; 500 KB, 2 MB or 30 MB per request on paid plans
Dashboarddashboard.emailjs.com: services, templates, email history, contacts
OperatorEmailJS Pte. Ltd. (terms governed by Singapore law)
HostingAmazon Web Services, United States; Cloudflare as infrastructure provider
ComplianceGDPR and nFADP statements, DPA, HIPAA BAA on Business

Who EmailJS is for

Best for

  • Static sites and single-page apps that need to send an email without running a server
  • Developers who want to send through their own provider (Gmail, Outlook, SES, SendGrid and others) and switch providers from the dashboard
  • Mobile and cross-platform apps: the docs cover React Native and Flutter as well as browser frameworks
  • Branded transactional emails built from templates with dynamic variables, auto-replies and attachments

Not for

  • Anyone who wants a stored, searchable inbox of form submissions kept indefinitely
  • Free-plan users who need file attachments or a domain allowlist (both start on Personal)
  • Sites that cannot have an email-sending key in client-side code, even a restricted one
  • High-volume sending through a personal Gmail or Outlook account, which EmailJS itself advises against

EmailJS pricing

PlanPriceIncludes
Free$0200 requests/month, 2 email templates, requests up to 50 KB, no attachments, 500 contacts, 7-day email history, 1 seat, EmailJS footer on emails, community support
Personal$9/month2,000 requests/month, 6 templates, attachments up to 500 KB, unlimited contacts, 30-day history, domain allowlist, no EmailJS footer, standard support
Professional$15/month5,000 requests/month (a 10,000 option is also listed), unlimited templates, attachments up to 2 MB, suppressions list, 3 seats, priority support
Business$40/month25,000 requests/month (50,000, 100,000 and 200,000 options also listed), attachments up to 30 MB, unlimited seats, priority support, HIPAA BAA available

Source: emailjs.com/pricing, checked . Prices can change; check the vendor's page before you buy.

Pros and cons

Pros

  • No server needed: a few lines of SDK code send an email from the browser, React Native or Flutter
  • Sends through the email provider you choose, and you can switch providers from the dashboard without changing code
  • Your provider's credentials stay on EmailJS servers; the browser only holds a public key and template IDs
  • Documented abuse controls: domain allowlist, IP-based rate limits, reCAPTCHA v2 per template, optional private key
  • Email history can be switched off per template, and a HIPAA BAA is available on Business
  • No overage charges: requests over the quota are dropped, with warnings at 80%, 95% and 100%

Cons

  • The public key is visible in your page source, so anyone can trigger your templates and use up your quota unless you lock it down
  • The domain allowlist is not on Free
  • Email history is kept 7 days on Free and 30 days on paid plans; it is a send log, not a submissions database
  • Only reCAPTCHA v2 is supported, and it is off until you configure it per template
  • Free has no attachments, a 500-contact list and an EmailJS footer on every email
  • Each auto-reply counts as an extra request against your quota

How EmailJS works

EmailJS does not send emails itself. You connect an email service in the dashboard, either a personal account such as Gmail, Outlook 365 or Fastmail, or a transactional provider such as Amazon SES or SendGrid, and EmailJS sends through it. You then build email templates in the dashboard, with dynamic variables like {{name}} filled in at send time.

Your code calls emailjs.send or emailjs.sendForm with a service ID, a template ID and your public key, or posts the same values to the REST API at api.emailjs.com. EmailJS looks up the template, fills in the variables and sends the email through your connected service. The docs list a rate limit of 1 request per second for the send methods.

EmailJS recommends personal email accounts only for development or very low volume, because the provider can block an account that exceeds its daily limit or flag it for spam. For production it recommends a transactional provider.

The public key: what it exposes and how to lock it down

Your EmailJS public key sits in client-side code, so anyone who views your page source can copy it along with your service and template IDs. EmailJS's own FAQ acknowledges this. Its position is that a copied key can only send your predefined templates with your content, not arbitrary spam. Your email provider's credentials are never exposed to the browser.

The practical risks are still real. Someone with your key can send your templates repeatedly, using up your monthly quota (requests over 100% are dropped, so your real form stops sending too) and sending mail through your connected account. Template fields, including the recipient, can take dynamic variables, so a template whose To address comes from a variable can be pointed at addresses you did not choose. Keep the recipient fixed in the template.

  • Domain allowlist (Personal and up): only requests whose origin matches your listed domains are processed.
  • IP-based rate limits on the EmailJS side, plus the documented 1 request per second limit.
  • reCAPTCHA v2 per template: once enabled, that template cannot send without a solved CAPTCHA.
  • Private key: an optional second key enabled under Account, Security, for server-side or app use.
  • SDK options blockHeadless, blockList and limitRate. These run in the SDK, so they stop casual bots rather than someone calling the REST API directly.
  • Triple-bracket {{{variables}}} insert raw HTML; the docs warn they are unsafe and can be abused.

The EmailJS dashboard and login

You sign in at dashboard.emailjs.com. The dashboard is where you connect email services, edit templates (with a Test It dialog and a generated JSFiddle), view email history, manage contacts and find your public and private keys. Multi-factor authentication with any TOTP app is free on every account.

Email history shows each send with its template variables and any provider error, kept for 7 days on Free and 30 days on paid plans. It can also be read through the /history REST endpoint with your private key. Templates can optionally save each sender as a contact, viewable and exportable as CSV in the dashboard (500 contacts on Free, unlimited on paid plans).

Team access is on Professional (3 seats) and Business (unlimited), with four permission levels: Account, Service, Template and Read-Only.

Spam protection for contact forms

EmailJS's spam tools are about stopping bots from triggering your templates, not about filtering what a submitter writes. The FAQ lists IP-based rate limits, the origin allowlist and reCAPTCHA support, and notes that it is up to the developer to turn reCAPTCHA on. The SDK can also refuse headless browsers and block requests where a chosen variable matches a blocklist.

The docs we checked describe no content-based spam scoring, no honeypot field and no spam folder. A message that passes the CAPTCHA and rate limits is sent as an email.

File attachments

Attachments are configured per template, either static (the same file on every email) or dynamic. Dynamic attachments come from a file input in a form sent with sendForm, or from a Base64 or URL variable, such as a canvas image.

The plan sets the total attachment size per request: none on Free, 500 KB on Personal, 2 MB on Professional and 30 MB on Business. EmailJS notes that some email services cap attachments at 10 MB and recommends staying under that. Files travel inside the email; there is no separate file storage to browse later.

Privacy, data storage and who runs EmailJS

EmailJS is operated by EmailJS Pte. Ltd., and its terms are governed by Singapore law. The privacy policy (last modified September 8, 2026) says all servers are in the USA on Amazon Web Services, data is stored encrypted, and its subprocessors are Cloudflare, AWS, Redis, Zendesk and Sentry, all in the United States. EU and UK transfers use Standard Contractual Clauses or the UK IDTA.

Per the policy, EmailJS stores email requests (unless you switch history off for a template) and request metadata, active accounts' data is retained for 30 days, and deleting an account removes its data from production servers immediately. The policy says it uses only session cookies and has no advertising, and the pricing FAQ says EmailJS does not sell email content, metadata or logs.

EmailJS publishes a data processing agreement, an nFADP page and a HIPAA page. The HIPAA page offers a BAA on the Business plan and requires the template setting that stops private data being saved. Payments go through Paddle, so charges appear as PADDLE.COM * EMAILJS.

Support, uptime and billing

Support is community-only on Free, standard on Personal and priority on Professional and Business. There is a contact page and a public status page at status.emailjs.com.

The pricing page advertises a 99.5% uptime SLA, while the terms of service promise 99% for paid plans, with service credits of 10% of the monthly cost below 99% and 30% below 95%. There are no long-term contracts: upgrades apply immediately and downgrades or cancellations at the end of the billing cycle. The terms describe fees as generally non-refundable.

EmailJS vs a form backend like splitforms

splitforms is a form backend and publishes this review. The difference is the model. EmailJS sends an email through your account and keeps a short send log. A form backend receives the submission on its own server, stores it, filters spam and then emails you, so there is no email-sending key in your page.

splitforms Free is 500 submissions in total (a one-time allowance), with owner email notifications on every plan and stored submissions that do not expire automatically. Pro is $5/month for 5,000 a month with signed webhooks, and Annual is $49/year for 15,000 a month. EmailJS remains the better fit when you need to send many kinds of transactional email from client code, not just collect form submissions.

Is EmailJS safe to use?

Yes, EmailJS is a legitimate service run by EmailJS Pte. Ltd. in Singapore. Its privacy policy says data is stored encrypted on AWS servers in the US, it lists its subprocessors, it uses no tracking or advertising cookies, and it does not sell email content. Your email provider's password or API key stays on EmailJS's servers. The public key in your front-end code is the part to secure. Anyone can copy it and send your templates, so turn on the domain allowlist (paid plans), add reCAPTCHA to public forms, keep recipients fixed in templates and enable MFA on your dashboard login.

EmailJS FAQ

How do I log in to the EmailJS dashboard?

Sign in at dashboard.emailjs.com with the email and password you registered with. If you enabled multi-factor authentication, you will also need a code from your authenticator app. Free accounts need only a name and email to sign up, with no card.

Is EmailJS free?

Yes. The Free plan includes 200 requests a month, 2 email templates, requests up to 50 KB and 7 days of email history, with no attachments and an EmailJS footer on emails. Personal is $9/month for 2,000 requests.

Is it safe to put my EmailJS public key in front-end code?

It is designed to be public, but anyone can copy it and trigger your templates against your quota. Turn on the domain allowlist (Personal and up), enable reCAPTCHA on templates used by public forms, keep the recipient address fixed and use a transactional email provider rather than a personal inbox.

Does EmailJS store form submissions?

Only as email history: each send and its variables are kept for 7 days on Free and 30 days on paid plans, and you can switch history off per template. Templates can also save senders as contacts. There is no permanent, searchable submissions inbox.

What happens when I reach my EmailJS monthly limit?

EmailJS does not charge overage fees. Once you reach 100% of your monthly requests, further requests are dropped until the next cycle or an upgrade. It emails you at 80%, 95% and 100%.

What are free EmailJS alternatives for a contact form?

A form backend avoids putting an email-sending key in your page. splitforms Free gives 500 submissions in total with a stored dashboard and email notifications. Web3Forms and FormSubmit are other free options, reviewed separately.

EmailJS alternatives

Need a form backend that works on any host?

splitforms takes any HTML form, filters spam and stores every submission in a dashboard. Free for 500 submissions total with no card; Pro is $5/mo.

Sources

  1. EmailJS pricing and FAQ emailjs.com/pricing
  2. EmailJS docs: Tutorial overview emailjs.com/docs/tutorial/overview
  3. EmailJS docs: Connecting email services emailjs.com/docs/user-guide/connecting-email-services
  4. EmailJS docs: Creating email templates emailjs.com/docs/user-guide/creating-email-templates
  5. EmailJS docs: Dynamic variables in templates emailjs.com/docs/user-guide/dynamic-variables-templates
  6. EmailJS docs: emailjs.send emailjs.com/docs/sdk/send
  7. EmailJS docs: SDK options emailjs.com/docs/sdk/options
  8. EmailJS docs: REST API /send emailjs.com/docs/rest-api/send
  9. EmailJS docs: REST API /history emailjs.com/docs/rest-api/history
  10. EmailJS FAQ: Is it okay to expose my Public Key? emailjs.com/docs/faq/is-it-okay-to-expose-my-public-key
  11. EmailJS FAQ: Does EmailJS expose my account to spam? emailjs.com/docs/faq/does-emailjs-expose-my-account-to-spam
  12. EmailJS FAQ: Can I add my domain to the allowlist? emailjs.com/docs/faq/can-i-add-my-domain-to-allowlist
  13. EmailJS FAQ: Can't I use services like Sendgrid directly? emailjs.com/docs/faq/cant-i-use-services-like-sendgrid-or-mandrill-directly
  14. EmailJS docs: Adding CAPTCHA verification emailjs.com/docs/user-guide/adding-captcha-verification
  15. EmailJS docs: File attachments emailjs.com/docs/user-guide/file-attachments
  16. EmailJS docs: Collecting contacts emailjs.com/docs/user-guide/collecting-contacts
  17. EmailJS docs: Auto-Reply emailjs.com/docs/user-guide/auto-reply
  18. EmailJS docs: Multi-Factor Authentication emailjs.com/docs/user-guide/multi-factor-authentication
  19. EmailJS docs: Multi-user access emailjs.com/docs/user-guide/multi-user-access
  20. EmailJS privacy policy emailjs.com/legal/privacy-policy
  21. EmailJS terms of service emailjs.com/legal/terms-of-service
  22. EmailJS data processing agreement emailjs.com/legal/data-protection-agreement
  23. EmailJS HIPAA emailjs.com/legal/hipaa
  24. EmailJS nFADP emailjs.com/legal/nfadp

Updated · First published · All reviews