Shouldn't be. I mean you are allowing anyone to send an email to anyone, but you should limit how many recipients there are, filter all input for spam-type data (Content-type headers etc), restrict the length of the user-submitted message, and you could even IP-restrict the use of the form so one IP address can only send out say 2 or three per hour.













Hi
Just wondering - is a 'tell a friend' page, where the user enters a friend's address, inherently able to be spammed?
Is there any way round this, short of a CAPTCHA image confirmation?
Or how about splitting the email field in two, so the user enters each part of the address separately, and the script adds the @ in later/
blessings and thanks
Tony
Online outreach:
Internet Evangelism Day
Helping church websites:
Church Websites