NisuformDocs

Access rules

Accept submissions only from your own websites, and block IP addresses and countries.

Access rules limit where a form's submissions can come from. Set them in the form's Settings, Spam protection, Access rules.

Allowed websites

Enter the sites that are allowed to send submissions, one per line:

https://example.com
https://www.example.com
https://staging.example.com

Once the list has at least one site, Nisuform compares the site in each request's Origin header, or its Referer header when there is no Origin, with the list. Submissions from any other site are rejected with 403 and origin_not_allowed. Leave the list empty to accept submissions from any website.

  • Only the scheme, host and port count. A full URL like https://example.com/contact is saved as https://example.com.
  • https://example.com and https://www.example.com are different sites. Add both if your site answers on both.
  • Add http://localhost:3000, or whatever your dev server uses, to test locally.
  • Up to 50 sites per form.

Allowed websites also decide where a _redirect may send visitors.

Browsers only

Browsers always send Origin or Referer, and pages can't fake them. Scripts and servers can send any headers, or none. Requests without either header are allowed, so allowed websites stop other sites from embedding your form, but they don't stop a determined bot. Combine them with Cloudflare Turnstile for that.

Blocked IP addresses

Enter IP addresses to block, one per line or separated by commas. Both IPv4 and IPv6 addresses work, and each must match exactly. Ranges are not supported. Up to 1,000 addresses per form.

Find a sender's address on any submission in the inbox, under IP address.

Blocked countries

Pick countries to block. The country comes from where the request reaches Nisuform, based on the sender's IP address. VPNs and proxies change it.

What blocked senders see

Submissions from a blocked IP address or country are dropped without notice. The sender gets a normal success response, without a submissionId, so they have no reason to try another way. Nothing is stored, and nothing counts toward your limits.

Store IP addresses

Store IP addresses is on by default and saves each sender's IP address with the submission, so you can block it later. Turn it off for forms that don't need it. New submissions are then stored without an IP address. Blocking and rate limits still work, because they check the address while the request is handled. See Privacy and data.