Perl & CGI

Perl-based Form Mail (Feedback) Script

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (9 sections)

For years, the usual way to add a feedback form to a website was a Perl "form mail" script in the cgi-bin folder: the form posted to a .pl file, and the script piped the fields to sendmail. Many old sites still have one. This guide explains why those scripts are now a liability, how to retire one safely, and what to use in its place in 2026.

Key takeaways

Do not install a new Perl FormMail script, and replace any old one you still run. Most were written before modern spam and email-authentication rules, and many let anyone change the recipient or headers, which turns your site into a spam relay. Use a secure PHP form or a WordPress form plugin instead, send from a mailbox on your own domain, and set up SPF and DKIM so your enquiries reach the inbox.

1. How the old Perl form mail scripts worked

A classic setup had two parts:

  • An HTML form that posted to something like cgi-bin/formmail.pl, with hidden fields such as recipient, subject, email and redirect.
  • A Perl script that read those fields, opened sendmail, wrote the headers and body, and redirected the visitor to a thank-you page.

The weak point: the recipient and other settings lived in hidden fields in the visitor's browser, which anyone can edit.

2. Why FormMail scripts are a spam risk

The best-known form mail scripts from the late 1990s had widely published vulnerabilities, and spammers still scan websites for them today. Even home-made versions usually share the same design problems.

WeaknessWhat an attacker doesResult for you
Recipient in a hidden fieldChanges recipient to thousands of other addressesYour server sends their spam
No header checksAdds line breaks and a Bcc: header to a field such as email or subjectHidden copies go to anyone they choose
Visitor address in FromNothing, it fails by itselfSPF and DMARC fail, so real enquiries land in spam
No spam protectionBots submit the form non-stopYour inbox fills with junk
Open redirect fieldPoints redirect at a phishing siteYour domain is used to send visitors elsewhere

When a form is abused, the messages go out under your hosting account. They count against your sending limit (section 7), they can get the server's address listed on spam blocklists, and your own legitimate email can stop going out until the problem is fixed.

Diagram: an edited hidden recipient field makes an old Perl form mail script send spam; a PHP handler with a fixed recipient prevents it
Why an editable recipient field makes a spam relay
Do not install a FormMail script from an old tutorial

Older versions of this article included a sample Perl script and a form with a hidden recipient field. We have removed them on purpose. Copying that pattern today puts your domain's email reputation at risk.

3. Signs your old form is being abused

  • You receive bounce messages for email you never sent.
  • Customers say your messages arrive in spam, or stop arriving.
  • Your account hits its sending limit although you send little email yourself.
  • Support finds many messages sent from your account to addresses you do not know when they search the server's mail logs for you.

If you see any of these, retire the script straight away (next section), then check the site for other signs of compromise with our security checklist for hacked websites.

4. How to retire an old Perl form

  1. Find it.
    In File Manager or over SFTP, look in public_html/cgi-bin and your site folders for .pl and .cgi files with names like formmail, mail, feedback or contact. Search your HTML for action="cgi-bin/.
  2. Take it offline.
    Download a copy for your records, then delete the script from the server. Renaming it inside a web folder is not enough if it can still be run.
  3. Remove the form's action.
    Edit the page so it no longer posts to the old script, or take the form down until the replacement is ready.
  4. Check your mail.
    Look through bounces for mail you did not send, and ask support to search the server's mail logs for anything sent from your account that you did not expect.
  5. Put a modern form in place.
    Use one of the options in the next sections.
  6. Test it.
    Send yourself a message and confirm SPF and DKIM pass in the received headers.
cPanel Track Delivery page with a Recipient Email search, Run Report button and an empty Delivery Report table
Track Delivery lists where your account's mail went.

5. Option 1: a secure PHP contact form

For a normal website, a PHP form is the direct replacement. Our guide Secure PHP contact form: complete code and instructions gives you a copy-paste form and handler that fixes every weakness in the table above:

  • the recipient is fixed in the server-side code, never in the form;
  • name and email are checked for line breaks, so headers cannot be injected;
  • From is a mailbox on your own domain, and the visitor goes in Reply-To;
  • a CSRF token, a hidden honeypot field and a per-IP rate limit stop most bots;
  • the message is sent with PHP mail() and the -f envelope sender, so SPF passes.

6. Option 2: a WordPress form plugin

On WordPress, do not add custom scripts. Use a long-established form plugin such as Contact Form 7 or WPForms, which handle validation and spam protection for you. Set the From address to a real mailbox on your domain, map the visitor's email to Reply-To, and turn on the plugin's anti-spam options or a CAPTCHA.

For a comparison of the main plugins, see Top WordPress plugins for contact forms.

What about SMTP plugins?

Authenticated SMTP works well on a VPS or the App Platform. On shared hosting, some servers disable the PHP socket functions SMTP needs, and on at least one of our cPanel servers they are disabled for every account. There, use mail() with -f, or a mail plugin that talks to an email service over its HTTPS API. PHP disabled functions on shared hosting and Sending email from PHP on shared hosting explain both routes.

7. Sending limits and email authentication

Every message a form sends counts against your hosting account's outgoing limit, together with webmail and email programs. The limits differ by control panel (measured on our servers, 22 September 2026):

HostingOutgoing email limit
cPanel shared hosting200 per hour per account
DirectAdmin shared hosting1,000 per day
Webuzo and Windows hostingAsk support for your account's limit

A contact form rarely comes near these numbers; if yours does, it is almost certainly being abused. For newsletters, use a dedicated email delivery service. See Do you limit the amount of mails I can send per hour.

For delivery, your domain needs SPF (which servers may send for it), DKIM (a signature proving the message was not altered) and ideally DMARC (what receivers do when those checks fail). In cPanel, Email → Email Deliverability checks and installs these records. For all panels, read Email authentication: SPF, DKIM, DMARC.

8. Where Domain India fits

Our cPanel, DirectAdmin and Webuzo shared hosting plans include email accounts on your own domain for the From mailbox, free SSL for a secure form page and PHP mail() for sending, which is everything the PHP form guide needs. WordPress installs in a few clicks with Softaculous.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details

If your old form was abused, or messages from a new form do not arrive, open a support ticket with the page address and the time you tested, and our team can check the mail log for your account.

Is Perl FormMail safe to use?

Old FormMail scripts are not safe. Many let anyone change the recipient through a hidden form field or inject extra headers, which turns the website into a spam relay. Replace them with a PHP form that fixes the recipient in server-side code, or a WordPress form plugin.

What should I use instead of a Perl feedback form?

For a normal website, use a secure PHP contact form that validates every field, sends from a mailbox on your own domain and puts the visitor in Reply-To. On WordPress, use an established form plugin such as Contact Form 7 or WPForms.

How do I know if my contact form is sending spam?

Look for bounce messages for email you never sent, a sending limit reached although you send little mail, or support finding many unknown recipients when they search the server's mail logs for you. If you see these, remove the form script and check the site for compromise.

How many emails can my contact form send?

Form messages count against your hosting account's outgoing limit. On Domain India cPanel hosting that is 200 per hour per account; on DirectAdmin it is 1,000 per day. For other hosting types, ask support.

Why do my form emails go to spam?

Usually because the form sends with the visitor's address in From, or your domain has no SPF and DKIM records. Send from a mailbox on your own domain, put the visitor in Reply-To, use the -f envelope sender with PHP mail(), and set up SPF, DKIM and DMARC.

Ready to replace an old form? Follow Secure PHP contact form: complete code and instructions, compare cPanel hosting, DirectAdmin hosting and Webuzo hosting, or open a support ticket if you think your form has been abused.

Hosting where your contact form just works

Email accounts on your own domain, free SSL and PHP mail() that works out of the box, so your enquiries reach your inbox.

See hosting plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Perl FormMail Scripts: Risks and Safer Alternatives