Signup forms
Your form, your site, our plumbing.
One endpoint takes a signup from a browser. Everything that makes it trustworthy — the confirmation email, the consent record, the spam defences — happens behind it.
A key that is safe to publish
Publishable keys can do exactly one thing: subscribe somebody to a topic. They cannot read your contacts, export anything or send. That is what makes them safe in page source, and you can restrict them to your own domains as well.
- Restrict to the domains you actually use
- Separate test keys that validate and send nothing
- Secret keys stay on your server, for everything else
The response never says whether somebody is already on your list.
New, pending, subscribed or previously unsubscribed all answer identically. Anything more specific turns a public form into a way for anyone to check whether a particular person subscribes to you, which is their business and not ours to leak.
Built-in defences
- Honeypot field
-
A field no person sees and every bot fills. A filled one is answered exactly like a real signup and quietly dropped, so the bot learns nothing.
- Rate limits
-
Per key, per minute, with a separate limit on how often one address can be mailed a confirmation.
- Confirmation by default
-
Anyone can type anyone’s address into a form. It is not consent until somebody proves they can read that inbox.
Try ZevCampaign for 14 days
No card to start. Pick a plan before the trial ends and nothing pauses; your contacts, campaigns and reports carry straight on.
[object Object]