# Troubleshooting

Fixes for the most common problems, from missing submissions and emails to CORS errors, closed forms and failing integrations.

Start with **Send a test** on the form's **Setup** tab. If the test shows up in your inbox and your email, Nisuform is working, and the problem is in how your site sends the form.

<Accordion title="My submission isn't in the inbox">
  * Check the **Spam** filter in the inbox. Messages with many links and exact repeats land there.
  * Check the response. `{ "ok": true }` without a `submissionId` means the submission was dropped on purpose: the hidden `_gotcha` field had a value, `_elapsed` was under 2 seconds, or your IP address or country is blocked for the form. Browser autofill and password managers sometimes fill in a honeypot that isn't hidden with CSS. See [Special fields](/docs/connect/special-fields#_gotcha).
  * Check that you are looking at the right form and the right team. The endpoint in your HTML must match the one on the form's **Setup** tab.
  * Check the response status. Anything other than `200` means it was rejected, and the error says why. See [Errors](/docs/reference/errors).
</Accordion>

<Accordion title="Submissions arrive but some answers are missing">
  * Every input needs a `name` attribute. Inputs without one are never sent by the browser.
  * Disabled inputs are never sent either. Use `readonly` if the visitor shouldn't edit a value.
  * Names that start with an underscore are not stored. Rename the field.
  * File inputs need `enctype="multipart/form-data"` on the form, and uploads turned on for the form, which is Pro.
</Accordion>

<Accordion title="I don't get email notifications">
  * Check your spam or junk folder, and mark the email as not spam.
  * In **Settings**, **Email**, check that **Email me new submissions** is on and **Send to** is right. On the Free plan, emails go to the team owner's account email.
  * Spam submissions never send notifications.
  * See [Email notifications](/docs/submissions/notifications).
</Accordion>

<Accordion title="The browser console shows a CORS error">
  * Send only the `Content-Type` and `Accept` headers. Other headers, like `Authorization` or custom `X-` headers, fail the preflight check.
  * Don't send credentials. Leave `credentials` at its default.
  * Check the URL. A typo in the path answers `404`, which the browser may report as a CORS error.
  * A `403` with `origin_not_allowed` means the site isn't in the form's allowed websites.
</Accordion>

<Accordion title="My form shows This form is closed">
  The form is paused, reached its **Maximum submissions**, or passed its **Close on** date. Check the notice in **Settings**, **Submissions**, **Limits** and in **General**. See [Pause and close a form](/docs/forms/closing).
</Accordion>

<Accordion title="Visitors get 402 or quota_exceeded">
  The team used all of this month's submissions. Usage resets on the first of the month in UTC, or you can [upgrade to Pro](/docs/account/billing) for 5,000 a month.
</Accordion>

<Accordion title="Visitors get 429 or rate_limited">
  Someone sent more than 5 submissions a minute to the form from one IP address, more than 30 a minute to your forms, or the form received more than 200 in an hour. Real visitors rarely hit these limits. If you post from your own server, every request shares your server's IP address. See [Submitting from a server](/docs/connect/javascript#submitting-from-a-server).
</Accordion>

<Accordion title="Every submission fails with captcha_failed">
  * The Turnstile widget must be inside the `<form>` element.
  * The site key in your page and the keys in the form's settings must belong to the same widget.
  * Your site's hostname must be in the widget's hostname list in Cloudflare.
  * With `fetch`, send the whole `FormData`, or add the `cf-turnstile-response` value yourself.

  See [Cloudflare Turnstile](/docs/protection/turnstile).
</Accordion>

<Accordion title="The page shows a 405 error">
  You opened the endpoint in the browser, or the form uses `method="GET"`. The endpoint only accepts `POST`. Set `method="POST"` on the form.
</Accordion>

<Accordion title="The redirect doesn't happen">
  * Redirects are a Pro feature.
  * `fetch` requests that ask for JSON are never redirected. Redirect in your own code after `ok` is `true`.
  * A `_redirect` URL must be on the site that sent the form or on one of its allowed websites. Otherwise it is ignored.
</Accordion>

<Accordion title="An integration shows Failing">
  The Integrations tab shows the reason, like "Slack answered 404". Usually the webhook was deleted, the bot was removed or the URL changed. Fix it on the other side, or reconnect, and choose **Send test**. The status clears after the next successful delivery. See the page for [each integration](/docs/integrations).
</Accordion>

<Accordion title="I changed the form but my site shows the old one">
  The embed code is a copy of the form at the time you copied it. After you change fields or the design in the builder, save, copy the code again and replace it on your site. Copy it again after turning Turnstile on or changing the redirect URL too, because both are part of the embed. Other settings, like notifications, spam protection and integrations, apply right away without new code.
</Accordion>

## Still stuck?

Email [support@nisuform.com](mailto:support@nisuform.com) with the form's name, what you expected and what happened. Include the `x-request-id` response header from your browser's network tab if you have it. A person replies within one business day, usually much faster.
