OxyPages

OxyPages Forms: Configure Your Form Settings Fully

OxyPages Forms: Configure Your Form Settings Fully

Configure your form in the right order: one attribute, named fields, captcha keys saved in your Form Settings, then what the visitor sees after they press Send.

The OxyPages Team · · 11 min read

You pasted a form onto your page, published it, filled it in yourself and pressed Send.

Nothing arrived.

Or worse, a visitor pressed Send, got a page saying "Forms Not Active", and closed the tab without telling you.

Almost every broken contact form on a static site is not broken at all. It is half finished, and it is usually the same half that is missing. To configure your form so it actually collects something takes five moves, and they have an order: mark the form, name the fields, save your captcha keys, point the notifications at an inbox you read, then choose what the visitor sees after Send.

Three live in your HTML. The other two live in your dashboard, and one of them stops everything.

Captcha keys are not optional and they are not a finishing touch. Until a key pair is saved in your Form Settings, every submission on your website is rejected, however perfect the markup is. That one fact sits behind most "my form does not work" messages.

TL;DR: To configure your form fully you need five things, in this order: data-oxy-form="contact" on the form tag, a name attribute on every field, a captcha Site Key and Secret Key saved in your Form Settings (mandatory - submissions are rejected until they are there), a notification inbox you actually read, and one attribute deciding what happens after Send. You never add an endpoint, a script tag or captcha markup yourself. Forms submit only on the published site, never in the editor preview, and each visitor is rate limited per hour, so a burst of test sends starts failing.

What Does It Take To Configure Your Form Fully?

Five things, and only three are code you write.

Here is the order, and what a visitor gets when you skip one:

StepWhere you do itIf you skip it
Mark the formYour HTMLThe page reloads and nothing is stored
Name every fieldYour HTMLThe entry arrives with that answer missing
Save captcha keysForm Settings, in your dashboardEvery submission is rejected, visitors see "Forms Not Active"
Check the notification inboxYour account settingsEntries pile up unseen while your inbox stays quiet
Choose the after-Send behaviourYour HTMLThe visitor gets the plain default message

The order matters because of row three. You can configure your form perfectly in HTML, publish it, test it and still collect nothing, because the captcha check runs before a submission is ever stored. Do that step early and the rest is typing.

1. Mark The Form With One Attribute

Add data-oxy-form to the form tag and stop there. No action, no method, no endpoint to paste, no script tag.

<form data-oxy-form="contact">
  <input name="email" type="email" required>
  <textarea name="message"></textarea>
  <button type="submit">Send</button>
</form>

OxyPages spots that attribute when the page is served and wires the form to its submission endpoint on the way out, adding the captcha and anti-spam pieces for you. So there is no endpoint to copy and nothing to keep in sync when you republish.

The value of the attribute is the form's name, "contact" above. Use letters, numbers, hyphens or underscores, and keep it short, because entries are grouped under that name in your dashboard.

A site with a contact form and a newsletter signup wants two names, not one. The full attribute reference is in the help centre.

2. Give Every Field A Name

A field with no name attribute is not captured. It renders, the visitor fills it in, and it is silently absent from the entry.

It is the failure that wastes the most time, because nothing looks broken: the form submits, the entry arrives, and one answer is just not in it.

So check that every input, select and textarea has a name. That name is also the label you read in your inbox, so name="budget" beats name="field3" at two in the morning. MDN's reference for the name attribute covers the rules the browser applies.

One limit to know now rather than later: file uploads are not supported. A file input's contents are discarded and only the filename is recorded, so a form asking for a CV collects the words "cv-final.pdf" and nothing else. Ask for a link to the file instead.

3. Put The Captcha Keys In Your Form Settings Before You Test

3. Put The Captcha Keys In Your Form Settings Before You Test - OxyPages

Captcha is mandatory on every plan, and until a provider is saved in your Form Settings, every submission on your website is rejected and the visitor is shown a "Forms Not Active" page.

You bring your own keys, from one of two providers:

  • Cloudflare Turnstile: free at any volume, no puzzle for the visitor, no Google account needed. It is the one I would pick.
  • Google reCAPTCHA v3: invisible scoring from Google, and you need a Google account to register your domain.

Each provider hands you two keys and both go into your Form Settings, which you reach from your website's Forms page. The Site Key is public and runs in the visitor's browser. The Secret Key is checked server-side on every submission and is never shown again once you save it, so keep a copy before you paste it.

Press Save and your published forms accept submissions from that moment.

Register the address your form lives on with the provider too: your subdomain, plus your custom domain if you use one. A key pair registered for the wrong address, or a Site Key from one provider with a Secret Key from the other, shows visitors "Couldn't Confirm You're Human".

Each signup takes a couple of minutes, and the captcha setup article has the steps for both.

One thing you never do here is add captcha markup. The widget is inserted for you, and a hidden honeypot field goes onto every form with no setup at all. A submission that fills the honeypot is still stored and labelled Spam, and no notification email is sent for it.

4. Point The Notifications At An Inbox You Read

Every submission is emailed to your account's login email address. The email shows the form name, the website and the submitted fields, with a button through to the full list.

There is no per-form or per-website recipient. If notifications belong somewhere else, change the account email; that is the only lever there is.

The emails share one monthly allowance across your whole account and every website in it, and it rises with each paid plan. The pricing page carries the current figures. Cross the line and you get one last email titled "Form Email Limit Reached For This Month", then silence until the 1st of the following month.

Nothing is lost when that happens, and this is the part people misread as a broken form. Submissions keep being stored and stay readable in your dashboard while the emails are paused, and the allowance per plan is listed in the help centre.

Entries are kept either way: the newest 5,000 per website, newest first, grouped by form name. Treat the email as a convenience and the dashboard as the record.

5. Choose What Happens After Send

By default the form submits in the background, the page does not reload, the fields clear and the words "Message sent." appear just under the submit button. Fine for a side project, thin for anything commercial.

Four attributes change it, and all four go on the same form tag you started with:

What you wantAttributeWhat the visitor gets
The defaultnoneFields clear, "Message sent." appears under the button, no reload
Your own wordingdata-oxy-success="Thanks, we reply within a day."The same, with your text instead
A thank-you pagedata-oxy-redirect="/thanks.html"Sent to that page after a successful send
A hidden block revealeddata-oxy-success-selector="#thanks"The form disappears, your element appears in its place
Friendlier failure textdata-oxy-error="Sorry, that did not send."Replaces the default "Could not send - please try again."

The redirect takes a path on your site starting with / or a full https:// address, so the thank-you page can live anywhere.

The reveal option needs one extra thing in your HTML: give the target element the hidden attribute so it stays invisible until the form succeeds.

<form data-oxy-form="contact" data-oxy-success-selector="#thanks">
  <input name="email" type="email" required>
  <button type="submit">Send</button>
</form>

<div id="thanks" hidden>
  <p>Thanks. We will reply to that address within a day.</p>
</div>

For analytics or your own confirmation screen, the form fires oxy:submitted and oxy:error events you can listen for, and data-oxy-native opts a form out of the background submit so the browser posts it natively. Most sites need neither.

The Finished Form, Ready To Paste

The Finished Form, Ready To Paste - OxyPages

Here is every decision above in one block: this is what it looks like to configure your form fully. Change the labels and the two messages, paste it in, publish.

<form data-oxy-form="contact"
      data-oxy-success="Thanks. We reply within one business day."
      data-oxy-error="Sorry, that did not send. Please email hello@example.com.">

  <label for="name">Your name</label>
  <input id="name" name="name" type="text" required>

  <label for="email">Email</label>
  <input id="email" name="email" type="email" required>

  <label for="topic">What is this about?</label>
  <select id="topic" name="topic">
    <option value="quote">A quote</option>
    <option value="support">Help with something I bought</option>
    <option value="other">Something else</option>
  </select>

  <label for="message">Message</label>
  <textarea id="message" name="message" rows="5" required></textarea>

  <button type="submit">Send</button>
</form>

Notice what is not in there: no action, no method, no script tag, no captcha widget and no honeypot field. Those are added when the page is served, so leaving them out is correct, not an omission.

How Do You Test It Without Locking Yourself Out?

Publish first, then submit once on the real address. Forms submit only on the live website and never in the editor preview, so a preview test proves nothing.

Once, not over and over, is the important part. Each visitor gets a limited number of submissions per hour per website, and you are a visitor while testing. A burst of test sends hits that ceiling and hands you "Too Many Submissions", which reads exactly like a broken form and is not one. There is a daily ceiling per website too, across all visitors.

A clean test run:

  1. Publish the site.
  2. Open the live address, not the preview.
  3. Submit the form once, with a real address in the email field.
  4. Open the website's Forms page in your dashboard. The entry should be at the top, under your form name.
  5. Check your inbox for the notification email.
  6. If step 4 worked and step 5 did not, the form is fine: it is the email allowance or a Spam flag.

When nothing arrives at all, the causes come in a reliable order: no captcha keys, then testing too fast, then a site that was never published, then a field with no name. The form troubleshooting guide walks them in that order, and the first one resolves most cases.

What To Do Once Entries Are Landing

A form that emails you is a to-do list. A form that sends people to a thank-you page with a next step on it is a funnel, and the difference is one attribute you have already seen.

So configure your form once, properly, then set the redirect and write a real thank-you page. After that, make the rest of the site work as hard as the form does: custom domains, password protection, version history and visitor statistics are all on the OxyPages features page, and none of them need a build step any more than the form did.

Let AI Do It For You

Rather not hand-write any of it? Paste the prompt below into the code editor AI on your site, or into any agent that can edit your files.

Add a fully configured contact form to index.html on my OxyPages site.

Requirements:
- A normal HTML form tag carrying data-oxy-form="contact", with no action
  attribute, no method attribute and no script tag.
- Fields: name (text), email (type="email"), topic (a select with three
  options) and message (a textarea). Every field must have a name attribute
  and a visible label tied to it with for/id. Mark name, email and message
  required.
- No file input: file uploads are not supported, only the filename is kept.
- Add data-oxy-success="Thanks. We reply within one business day." and
  data-oxy-error="Sorry, that did not send. Please email hello@example.com."
- Do not add any captcha markup, honeypot field or third-party form script.
  OxyPages inserts those automatically when the page is served.
- Style it to match the existing page and keep the labels visible.

Then remind me to save a Cloudflare Turnstile or Google reCAPTCHA v3 Site Key
and Secret Key in Form Settings before I test, because every submission is
rejected until those keys are saved.

Do the captcha step yourself: it lives in your dashboard and no agent can reach it.

FAQ

Do I Have To Use A Captcha On My Form?

Yes. It is mandatory on every plan, including the free one, and there is no setting that turns the requirement off. Until a Site Key and Secret Key are saved in your Form Settings, submissions are rejected and visitors see a "Forms Not Active" page. The Turn Forms Off button stops submissions entirely rather than skipping the captcha.

Where Do Submissions Go If I Never Read The Email?

They go to the website's Forms page in your dashboard, newest first and grouped by form name. The newest 5,000 entries per website are kept. Spam-flagged entries are stored too, labelled as Spam, and simply skip the email.

Can I Send Notifications To A Different Address Per Form?

No. Notifications go to the account owner's login email address and cannot be redirected per form or per website. If you need them elsewhere, change your account email, which moves them for every website at once.

Can My Form Accept File Uploads?

No. A file input's contents are discarded and only the filename is recorded on the entry, so you would receive "portfolio.pdf" with no file attached. Ask for a link to a shared file instead, or reply and ask for the attachment by email.

Do I Have To Set Everything Up Again When I Republish?

Your captcha keys and your form settings live in your dashboard, not in your files, so uploading a new version of the site does not clear them. What does need to survive is the HTML: if you regenerate a page with AI, check that data-oxy-form and every name attribute are still on the form before you publish. Keep those in place and you never have to configure your form from scratch twice.

Try It Now

Still Here? Drop It In.

The whole pitch fits in one sentence: your HTML, on a link, in seconds.

Drag and drop your HTML file(s), folders, or ZIP file

or ·

No account needed. Your unclaimed website stays live for 30 minutes on a free subdomain. Claim it to your account to keep it permanently.

  • No Account Needed
  • Free SSL
  • 30-Minute Unclaimed Link, Claim To Keep It