# PrestaShop contact form broken or flooded with spam

> A PrestaShop contact form that stops delivering messages, and one drowning in automated submissions: two separate faults with two different diagnoses, often lumped together under the same word, spam or bug.

- Source canonique : [https://allaux.fr/en/prestashop/problemes/formulaire-contact-ne-fonctionne-pas](https://allaux.fr/en/prestashop/problemes/formulaire-contact-ne-fonctionne-pas)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## Direct answer

> Open Shop Parameters > Contact and re-read the address assigned to each contact subject: a closed mailbox or a typo makes messages vanish with no error. Then configure authenticated SMTP under Advanced Parameters > Email. Nothing is native against spam: you have to add a honeypot field or a reCAPTCHA to the contact controller.

## The form stops sending anything

The most common symptom: a customer fills in the form, submits it, and nothing ever reaches the inbox. PrestaShop doesn’t store contact form messages in the database by default, everything relies on sending an email at submission time — if that send fails silently, there’s nowhere to recover the lost message.

Three causes come up most often:

The server’s outbound mail setup, under Advanced Parameters > Email: by default PrestaShop uses the PHP mail() function, which many hosts throttle or block without a clear warning. Switching to an external SMTP server fixes most cases.

A wrong recipient address in Preferences > Contacts: each contact reason (customer service, webmaster…) has its own address, and a typo or a disabled mailbox is enough to drop messages with no visible error.

A contact controller override broken by an update: if the file was customised to add a field or custom logic, a PrestaShop update can make it incompatible without throwing a visible error on the front end.

## The form is flooded with spam

The opposite symptom: the form works, but the inbox fills up with automated messages, often in English, with suspicious links or attachments. PrestaShop ships no native anti-bot protection on this form: without reCAPTCHA or a honeypot field, a bot can submit it hundreds of times a day with no human involved.

Fixing it almost always means development, small but real: adding an invisible honeypot field (a field only bots fill in, so their submission can be silently rejected), or integrating reCAPTCHA on the contact controller. An existing module can be enough if it covers this exact form; otherwise the integration goes directly into the template and controller.

## Configuration or development?

> A silent form is usually a configuration fix: SMTP, contact address, permissions. A spammed form needs development, even a small amount, since anti-bot protection doesn’t exist natively at this exact point in PrestaShop.

## Related pages

- **Order confirmation emails not received** — The same delivery chain is at fault when customers never get their order confirmation: a step-by-step diagnosis. ([/prestashop/problemes/emails-confirmation-commande-non-recus](/prestashop/problemes/emails-confirmation-commande-non-recus))
- **Order statuses and automatic emails** — Every status change can trigger its own email: how that mechanism is configured, and where it breaks. ([/prestashop/problemes/statuts-commande-personnalises](/prestashop/problemes/statuts-commande-personnalises))
- **Custom module development** — Anti-spam protection, a custom field, business logic: when an existing module isn’t enough, I build the missing piece. ([/prestashop/module-sur-mesure](/prestashop/module-sur-mesure))

## FAQ

### How do I know if the problem is the server or PrestaShop?

I test email sending independently of the form, from Advanced Parameters > Email, which offers a direct test send. If that test fails too, the problem is on the server side, not the contact form.

### Could the original contact module be at fault?

Yes, if the native module was uninstalled or updated badly, the form can disappear or lose its sending logic. I always check it’s active before looking further.

### Is a basic CAPTCHA enough against spam?

A visual CAPTCHA slows down some bots but hurts the experience for genuine visitors. I generally prefer an invisible honeypot combined with reCAPTCHA v3, which shows nothing to a legitimate user.

### Can messages sent before the fault be recovered?

No, if email sending was failing silently, no copy was ever kept: PrestaShop doesn’t store contact form messages in the database by default.

### The form works on desktop but not mobile, is that related?

Rarely to the sending itself: it’s more often a display or JavaScript validation issue specific to the mobile theme, worth checking separately from the email diagnosis.
