How it works
Form2Email turns any HTML form into an email — no accounts, no dashboards, no code on your site.
The lifecycle of an endpoint
-
Create
Tell us the email address that should receive submissions and the domain your form lives on. We give you a public form URL.
-
Verify
We email a verification link to the destination address. Nothing is accepted until you click it — the link is single-use and expires after 24 hours.
-
Active — 7-day temporary window
Once verified, the endpoint accepts submissions for 7 days. Every submission is relayed to your inbox.
-
Extend for free
From your manage page you can extend the endpoint by another 7 days, as many times as you like. Extending also revives an endpoint that has already expired.
-
Expiry
If the window runs out, the endpoint stops accepting submissions and responds with HTTP 410 until you extend it.
-
Permanent endpoints
Endpoints that should never expire are granted permanence by the operator. A permanent endpoint stays active indefinitely.
Getting our emails
Verification and submission emails come from form2email@terragohan.com. Add that address to your contacts or trusted-senders list so it doesn't get filtered into spam.
Temporary (default)
- Active for 7 days after verification
- Free 7-day extensions, any number of times
- Extending an expired endpoint revives it
- Answers HTTP 410 while expired
Permanent
- Never expires
- Granted by the operator on request
- No extensions needed — the extend action does not apply
- Can be revoked by the operator, returning to a 7-day window
Security model
- Only token hashes are stored. The public, manage and verification tokens you receive exist only in the URLs we hand you — the database keeps SHA-256 hashes, so lost raw tokens are unrecoverable and a database leak doesn't expose them.
- Origin enforcement. Submissions are only accepted from exactly the domain you registered — subdomains must be registered separately — checked against the browser's Origin/Referer headers and enforced via CORS.
- Sender becomes Reply-To. Submission emails are sent to you with the visitor's address as Reply-To, so answering the email replies directly to them.
- Rate limits with backoff. Endpoint creation and form submissions are rate-limited per client IP. Once an IP exceeds the submission cap, every further attempt doubles its lockout — 1s, 2s, 4s, up to 5 minutes — until it slows down.
Error semantics
- 403
- Forbidden — the email isn't verified yet, or the submission came from a domain other than the registered origin.
- 410
- Gone — the endpoint has expired. Extend it from the manage page to revive it.
- 429
- Too many requests — you hit a rate limit. Slow down and retry.
- 502
- Bad gateway — the submission or verification email couldn't be delivered by the mail provider. Nothing was lost on our side; try again.