Website platform
Shopify contact form spam: not the field you think
Do not use Settings → Notifications → Sender email. Shopify uses that one address for two jobs — where the storefront contact form is delivered, AND the From address your customers see on order confirmations — so pointing it at us would rewrite the sender of every email your store sends.
Not the theme's built-in contact form: that one is delivered to your store's sender address. This is the Shopify Forms app plus a Flow automation, both free on every plan.
Replace whatever is in that field with the address Humainbox generates for you. Nothing else changes: no plugin, no snippet, no DNS record, and nothing on your site to republish. If you want to stop, put your old address back in that field.
Trigger
Form submitted
Action
Send internal email
Email address
change thisSubject
New form submission
Why it is getting through
What Shopify already stops — and where it stops
Shopify stores get a particular flavour of it: supplier pitches, fake invoices, dropshipping offers, and a long tail of people who have worked out that a storefront has money moving through it. All of it lands in the same mailbox as a customer asking where their order is.
hCaptcha is on by default on every Shopify store and covers the contact and comment forms, though it only puts a visible challenge in front of a sender it already finds suspicious. Like every other defence on this list it judges how the form was submitted rather than what the submission says.
What Shopify keeps either way
That depends which form you are using, and it is the same fork as everything else on this page. The theme's built-in contact form is delivery only — Shopify's own documentation describes where it is sent and never a record you can go back to. Submissions through the Forms app are kept in the app.
We check the message itself
A captcha asks whether the sender is a machine. We ask whether the writing could only have been sent to you.
Nothing is deleted
Held mail stays readable in the panel for your whole retention window, and one click sends it on.
If we break, your mail still arrives
If anything breaks on our side, mail goes through. You get the noise back for an afternoon; you never lose an enquiry.
Questions
Shopify, specifically
The ones that come up about this builder rather than about us. If yours is not here, ask it — a person answers.
Why not just put your address in Settings → Notifications?
Because Shopify uses that one field for two different jobs. It is where the storefront contact form is delivered, and it is also the From address your customers see on automatic notifications, order confirmations and marketing email. Point it at an address we generated and you have not filtered your contact form — you have changed who every customer thinks your shop's email comes from. There is no separate setting for the theme's contact form, which is why the answer is a different form rather than a different value in that box.
So what is the route that works?
Shopify Forms and Shopify Flow, both free on every plan including Basic. Put a Forms form on your contact page, then build a Flow automation: the trigger is a form submission and the action is Send internal email, whose Email address field takes a plain address you type. That address is the one we generate for you. Nothing about your store's sender email changes.
Is that still "one field"?
Not on the first day, and we would rather say so than stretch the claim. If you already run Forms with a Flow notification, it is genuinely one field — the Email address on that action. If your contact page is still the theme's built-in form, you are installing two free apps and building one automation before the one field exists. That is a change worth making on its own terms, not only for us.
Will the reply still go to the customer?
Yes. We set the sender's own address as the reply address on what we forward, so answering from your mail client reaches the person who wrote in rather than the automation.
What happens to spam that still reaches the Forms app?
It is recorded there, as everything submitted to a Forms form is, and we are downstream of that. What changes is that the notification stops being a queue of pitches with the occasional customer in it.
Not sure what is already running on your contact page? Paste it into the free check and we will name the builder, the CAPTCHA and what your DNS says. No account, nothing stored.
Cannot find it on your Shopify?
Menus move between versions, themes hide panels, and an agency may have built something on top of the standard one. Send us the address of your contact page and we will look at the install you have rather than the one this page was written about. A person reads it, and replies within a day.
And if the person who can change that field is not you, Humainbox writes to them instead — the field, the address, and nothing else to read.
Checked against Shopify’s own documentation
Using something else?
If a form can send its notification to an address you choose, it works, whether or not it is on this list.