Troubleshooting
Fixes for the most common problems, from missing submissions and emails to CORS errors, closed forms and failing integrations.
Start with Send a test on the form's Setup tab. If the test shows up in your inbox and your email, Nisuform is working, and the problem is in how your site sends the form.
- Check the Spam filter in the inbox. Messages with many links and exact repeats land there.
- Check the response.
{ "ok": true }without asubmissionIdmeans the submission was dropped on purpose: the hidden_gotchafield had a value,_elapsedwas under 2 seconds, or your IP address or country is blocked for the form. Browser autofill and password managers sometimes fill in a honeypot that isn't hidden with CSS. See Special fields. - Check that you are looking at the right form and the right team. The endpoint in your HTML must match the one on the form's Setup tab.
- Check the response status. Anything other than
200means it was rejected, and the error says why. See Errors.
- Every input needs a
nameattribute. Inputs without one are never sent by the browser. - Disabled inputs are never sent either. Use
readonlyif the visitor shouldn't edit a value. - Names that start with an underscore are not stored. Rename the field.
- File inputs need
enctype="multipart/form-data"on the form, and uploads turned on for the form, which is Pro.
- Check your spam or junk folder, and mark the email as not spam.
- In Settings, Email, check that Email me new submissions is on and Send to is right. On the Free plan, emails go to the team owner's account email.
- Spam submissions never send notifications.
- See Email notifications.
- Send only the
Content-TypeandAcceptheaders. Other headers, likeAuthorizationor customX-headers, fail the preflight check. - Don't send credentials. Leave
credentialsat its default. - Check the URL. A typo in the path answers
404, which the browser may report as a CORS error. - A
403withorigin_not_allowedmeans the site isn't in the form's allowed websites.
The form is paused, reached its Maximum submissions, or passed its Close on date. Check the notice in Settings, Submissions, Limits and in General. See Pause and close a form.
The team used all of this month's submissions. Usage resets on the first of the month in UTC, or you can upgrade to Pro for 5,000 a month.
Someone sent more than 5 submissions a minute to the form from one IP address, more than 30 a minute to your forms, or the form received more than 200 in an hour. Real visitors rarely hit these limits. If you post from your own server, every request shares your server's IP address. See Submitting from a server.
- The Turnstile widget must be inside the
<form>element. - The site key in your page and the keys in the form's settings must belong to the same widget.
- Your site's hostname must be in the widget's hostname list in Cloudflare.
- With
fetch, send the wholeFormData, or add thecf-turnstile-responsevalue yourself.
See Cloudflare Turnstile.
You opened the endpoint in the browser, or the form uses method="GET". The endpoint only accepts POST. Set method="POST" on the form.
- Redirects are a Pro feature.
fetchrequests that ask for JSON are never redirected. Redirect in your own code afterokistrue.- A
_redirectURL must be on the site that sent the form or on one of its allowed websites. Otherwise it is ignored.
The Integrations tab shows the reason, like "Slack answered 404". Usually the webhook was deleted, the bot was removed or the URL changed. Fix it on the other side, or reconnect, and choose Send test. The status clears after the next successful delivery. See the page for each integration.
The embed code is a copy of the form at the time you copied it. After you change fields or the design in the builder, save, copy the code again and replace it on your site. Copy it again after turning Turnstile on or changing the redirect URL too, because both are part of the embed. Other settings, like notifications, spam protection and integrations, apply right away without new code.
Still stuck?
Email support@nisuform.com with the form's name, what you expected and what happened. Include the x-request-id response header from your browser's network tab if you have it. A person replies within one business day, usually much faster.