Form Spam: The Open Door on Your Contact Page

An unprotected intake form is a delivery mechanism — and it delivers to the people trained to be helpful.

Law Firm Cybersecurity · Chapter 3~6 min read

Here's an uncomfortable way to look at your contact page.

It is a channel that lets any stranger on earth put text directly into the inbox of a staff member whose job requires them to open it, read it carefully, and respond helpfully to people they've never met.

You built that on purpose. It's how clients find you. But an unprotected intake form is also a near-perfect delivery mechanism for anyone who wants to reach your people — and the staff most exposed to it are typically the ones with the least security training and the strongest professional instinct to be accommodating.

Why forms get abused

Three properties, and your form has all of them:

  • It's public. Bots crawl the web specifically looking for form fields to submit.
  • It accepts free text. Anything a person can type, including links.
  • It reaches a human who is obligated to engage. Unlike a cold email that gets ignored, a legal inquiry gets read. That's the whole point of intake.

Most of what arrives is worthless SEO junk. That's the noise. The signal problem is what hides inside the noise.

The spectrum, from annoyance to actual harm

Volume that buries real intake. The genuine prospective client's message arrives on page three of the junk, at 4:55pm on a Friday. The cost here isn't security — it's the case you never knew you lost.

Phishing aimed at your staff. A message with a link to "the documents for my matter," addressed to someone whose job is to click links from strangers. The pretext writes itself, because you told them the pretext on your own website.

Reconnaissance and targeting. This is where it connects to the rest of the guide. Your site already tells an adversary who your people are, what you practice, and how to reach you — the raw material for building a picture of your organization.1 The form is where they use it. A message referencing a real matter type, a real attorney's name, and plausible local specifics doesn't read as spam. It reads as a client.

Resource abuse. Forms that send mail can be exploited to send mail as your domain — meaning your firm's domain reputation takes the damage, and your legitimate email starts landing in clients' junk folders.

FIGURE 1 — THE UNTRUSTED-INPUT PIPELINE
Anyone on the internet
Your contact form
Your mail server
Intake inbox
A human paid to open it
The firm's network
Lawyers understand chain of custody. At most firms, this pipeline has none — nothing between the open internet and a paralegal's inbox but hope.

Why this is a security question, not an IT annoyance

Reframe the form as what it technically is: an untrusted-input pipeline that terminates in your staff's inboxes and, from there, your network.

Every other untrusted channel at your firm has controls. Mail gets opened at reception. Walk-ins get met at a desk. Your contact form, at most firms, has nothing between the open internet and a paralegal's inbox but hope.

What this means for your professional obligations

In the United States

Two threads converge here. Rule 1.6(c) requires reasonable efforts to prevent unauthorized access to client information2 — and an unfiltered pipeline into staff inboxes is a live path toward exactly that. Separately, Rules 5.1 and 5.3 put the supervision of lawyers and of nonlawyer assistants squarely on the firm's managing and supervising lawyers.3 Formal Opinion 483 leans on both when it discusses a firm's obligation to monitor for intrusion.4

Your intake staff are the people most frequently exposed to hostile messages and least likely to have been trained for it. That gap is a supervision question, not a technology question.

In Canada

Same structure. The competence commentary asks you to understand the risks of the technology your practice uses,5 and the confidentiality duty is what's exposed if the risk lands.6

What actually fixes this

1. Modern bot mitigation, correctly configured. Invisible CAPTCHA (reCAPTCHA v3 or equivalent) scores submissions without making a real client solve a puzzle. Honeypot fields catch the naive bots for free. The word "correctly" is doing real work in that sentence — a large share of the firm sites we audit have a CAPTCHA installed that is misconfigured, expired, or silently failing open. It's on the page, but it's either not doing anything or it's preventing real leads from filling out the form.

2. Rate limiting. One IP submitting forty times an hour is not a lead.

3. Server-side validation. Never trust that the browser enforced anything. Validate and sanitize at the server, always.

4. Lock the mail path. Proper SPF, DKIM, and DMARC records so nobody can send mail as your domain, and so your legitimate mail is trusted.

5. Train the humans — briefly. Intake staff need one rule, not a curriculum: treat every form message as untrusted, and never open an attachment or click a link from an unverified inquiry. If a message claims to be about an existing matter, verify through a channel you already have on file.

6. Audit what you already have. Most firms are not starting from zero. They're starting from something a web developer installed in 2019 that has since stopped working. Check.

Interactive — spot the hostile inquiry

Four messages, as they'd land in an intake inbox. Call each one.

All names and firms invented. Runs entirely on this page; nothing you tap is recorded.

How we can help

We audit what's actually on your contact page right now — whether the CAPTCHA is live or decorative, whether validation happens server-side, whether your mail records let a stranger send as your domain — and we fix what's broken. Then it stays fixed, because it's monitored.

The specific deliverable: a reCAPTCHA and intake-form audit. It's usually a short report, and it usually finds something.

Request the intake-form audit

Your firm's intake form checklist

Spencer McLennan
Spencer McLennan is the founder and lead webmaster of LegalWebmasters, and has handled websites, hosting, and security for law firms and professional practices across the United States and Canada since 2007. He holds an MBA, a PCM from the American Marketing Association, and is a graduate student in intelligence studies. He writes the Law Firm Cybersecurity and Law Firm SEO & Design guides. Connect on LinkedIn.

Footnotes

  1. Rae Baker, Deep Dive: Exploring the Real-World Value of Open Source Intelligence 209–25 (Wiley 2023).
  2. Model Rules of Pro. Conduct r. 1.6(c) (Am. Bar Ass'n 2023).
  3. Id. rr. 5.1, 5.3.
  4. ABA Comm. on Ethics & Pro. Resp., Formal Op. 483 (2018).
  5. Model Code of Pro. Conduct r. 3.1-2 cmts. [4A]–[4B] (Fed'n of L. Soc'ys of Can. 2019).
  6. Id. r. 3.3-1.

Trusted by professionals like you.

Crease Harman LLP Borders Law Group David Aujla, Immigration Lawyer