To send an HTML form to your email without a backend, point the form's action at a form endpoint that emails you. QList provides one for free: add two hidden fields, keep your own inputs, and each submission arrives in your inbox and in a dashboard history. No server, no JavaScript, no monthly cap.
The snippet
Replace YOUR_FORM_ID with the ID from your dashboard and https://yoursite.com/thank-you with your own page. Everything else is your form as it already is.
<form action="https://api.qlist.io/api/formsubmit" method="POST">
<input type="hidden" name="jg_id" value="YOUR_FORM_ID" />
<input type="hidden" name="jg_redirect" value="https://yoursite.com/thank-you" />
<!-- Honeypot: hidden from people, filled in by bots, silently dropped -->
<input type="checkbox" name="jg_botcheck" style="display:none" tabindex="-1" autocomplete="off" />
<!-- Your own fields, any names you like -->
<input type="text" name="name" placeholder="Name" />
<input type="email" name="email" placeholder="Email" />
<textarea name="message"></textarea>
<button type="submit">Send</button>
</form>
Every field you add (name, email, message, or anything else) appears in the email and in the submission history, with the field name as the label.
How it works
- Create a form in QList. Enter the email address that should receive submissions. QList sends a one-time code to that address to confirm it, so submissions can never be routed to an inbox you do not control.
- Paste the snippet into your page and replace the Form ID.
- Submit a test. The email arrives from
forms@qlist.io, and the submission appears in the dashboard.
That is the whole setup. There is no script to load unless you turn on captcha protection, and no API key in your HTML.
Fields QList understands
| Field | Required | What it does |
|---|---|---|
jg_id |
Yes | Your Form ID. Tells QList which form, and therefore which inbox. |
jg_redirect |
No | Where to send the visitor after a successful submission. Any URL on your site. |
jg_botcheck |
No | Honeypot. Keep it hidden with CSS. If a bot ticks it, the submission is dropped without an email. |
_subject |
No | Custom subject line for the notification email. |
g-recaptcha-response or cf-turnstile-response |
Only with captcha on | The token from Google reCAPTCHA v3 or Cloudflare Turnstile. QList generates the complete snippet for you when you enable protection. |
Everything else is treated as form data and forwarded as-is.
Spam protection
Contact forms on public sites get automated submissions within days. QList gives you three layers:
- Honeypot (on by default). The hidden
jg_botcheckcheckbox. Humans never see it; most bots tick every box. - Google reCAPTCHA v3 or Cloudflare Turnstile. Add your own site and secret keys in Settings, enable protection on the form, and QList gives you an updated snippet with the widget included. Submissions arriving without a valid token are dropped and never emailed. Keys stay encrypted in your account; QList does not run a shared key.
- Submission history. Every submission is listed in the dashboard, so you can see what arrived and what was rejected.
One honest caveat: the captcha snippet differs from the plain snippet. If you enable or disable captcha protection later, re-copy the snippet, or submissions will be silently dropped while the visitor still sees the thank-you page. The dashboard says this on the form page too.
Where people use it
- Static sites on GitHub Pages, Netlify, Vercel, Cloudflare Pages, Render or S3, which have no server to handle a form post.
- Page-builder exports from Webflow, Framer or similar, when you leave the builder's hosting but keep the HTML.
- Agency client sites, where one QList account holds a form per client, each routed to that client's inbox, with a history you can show them. QList's own contact form on this site is one of these.
- Landing pages and prototypes that need a working form before there is a backend.
What it does not do (yet)
- No file attachments: file inputs are ignored.
- No auto-reply to the person who submitted.
- No webhooks: submissions go to email and the dashboard only.
These are on the list. When they ship, this page changes.
Compared with other form endpoints
Most form-backend services cap the free tier at a fixed number of submissions per month, with paid plans above it. QList has no cap and no paid plan. The Formspree alternative page sets them side by side with their published numbers.
Frequently asked questions
How do I make an HTML form send an email?
A browser cannot send email on its own, so the form has to post to a server that does. With QList you set the form's action to QList's endpoint and add a hidden field with your Form ID. QList receives the submission and emails it to you.
Does it work on static sites (GitHub Pages, Netlify, Vercel, S3, Render)?
Yes. The form is plain HTML posting to QList, so it works anywhere HTML is served, including sites with no server-side code at all.
Is there a submission limit?
No. QList does not cap submissions per month and does not charge. See pricing.
How is spam handled?
Three layers you can combine: a hidden honeypot field that bots fill in and humans never see; Google reCAPTCHA v3 or Cloudflare Turnstile using your own keys; and the submission history, where blocked attempts are visible. A submission that fails the captcha check is dropped and never emailed.
Can I redirect to my own thank-you page?
Yes. Add a hidden jg_redirect field with the URL of your page. Without it, the visitor sees a plain confirmation.
Can I use it with React, Vue, or a fetch() call?
Yes. Post the same fields with fetch or any HTTP client to the same endpoint. The form tag in the snippet is just the simplest way to do it.
Where are submissions stored?
In the EU, in your QList dashboard, where you can read the history of each form. The privacy policy applies.