# Special fields

Fields that control how Nisuform handles a submission, like the _gotcha honeypot, the _elapsed fill time and _redirect.

Fields whose names start with an underscore tell Nisuform how to handle a submission. They are never saved, never shown in the inbox and never sent to notifications or integrations.

| Field                   | Plan | What it does                                                                                     |
| ----------------------- | ---- | ------------------------------------------------------------------------------------------------ |
| `_gotcha`               | All  | Honeypot. If it has any value, the submission is dropped as a bot.                               |
| `_elapsed`              | All  | Milliseconds the visitor spent on the form. Under 2 seconds, the submission is dropped as a bot. |
| `_redirect`             | Pro  | Where to send the visitor after a browser submit.                                                |
| `cf-turnstile-response` | All  | The Cloudflare Turnstile token. Checked when Turnstile is turned on for the form.                |

A dropped submission still gets a normal success response, so bots can't tell they were caught. The JSON response has no `submissionId` in that case.

## \_gotcha

A hidden text input that people never see, so they leave it empty. Many bots fill in every input they find.

```html
<input type="text" name="_gotcha" tabindex="-1" autocomplete="off" style="display:none">
```

* Hide it with CSS, not with `type="hidden"`. Bots skip hidden inputs.
* Keep `tabindex="-1"` so keyboard users don't land on it, and `autocomplete="off"` so browsers don't fill it in.

## \_elapsed

The time between showing the form and submitting it, in milliseconds. A person needs a few seconds to fill in a form. A bot needs a few milliseconds.

```js
const shownAt = Date.now()

form.addEventListener('submit', () => {
  form.elements._elapsed.value = String(Date.now() - shownAt)
})
```

```html
<input type="hidden" name="_elapsed">
```

Submissions with a value under 2,000 are dropped. If the field is missing or is not a number, the check is skipped, so plain HTML forms without JavaScript keep working. The styled embed from the form builder sends it for you.

## \_redirect

On Pro, a browser submit that includes `_redirect` is answered with a `303` redirect to that URL instead of the thank-you page.

```html
<input type="hidden" name="_redirect" value="https://example.com/thanks">
```

* It must be an absolute `http` or `https` URL.
* It must be on the same site as the page that sent the form, or on one of the form's [allowed websites](/docs/protection/access-rules). Anything else is ignored, which keeps your form from being used to redirect people to other sites.
* It overrides the redirect URL in the form's settings for that one submission.
* `fetch` requests that ask for JSON are never redirected.

See [Thank-you page and redirects](/docs/forms/after-submit) for the other options.

## cf-turnstile-response

Added by the Cloudflare Turnstile widget. When Turnstile is on for the form, a missing or invalid token is rejected with `403` and `captcha_failed`. See [Cloudflare Turnstile](/docs/protection/turnstile).

The names `g-recaptcha-response` and `h-captcha-response` are reserved too. They are ignored and never saved, but Nisuform does not verify reCAPTCHA or hCaptcha tokens.

## Other names that start with an underscore

Any other field that starts with an underscore, like `_subject` or `_next` from other form services, is ignored. Rename it without the underscore if you want to keep the value.
