Beyond spam.
WHAT ELSE HAPPENS
Forms used to send mail to others, if misconfigured Forms used to test stolen card details, on payment forms Repeated submissions to exhaust resources Injection attempts
THE MAIL RELAY RISK
A badly built form allowing the recipient to be set by the submission can be used to send spam from your server.
That gets your server blacklisted.
Recipients must be fixed in configuration, never taken from the form.
RATE LIMITING
Limiting submissions per address per period.
Prevents both abuse and accidental repeated submissions.
FOR PAYMENT FORMS
Card testing is a real problem.
Your gateway should have controls. Enable them.
FOR LOGIN AND REGISTRATION FORMS
Rate limiting and lockout after repeated failures.
WHAT TO MONITOR
Unusual submission volume Submissions from one address Anything in a submission that looks like code
WHAT TO DO IF ABUSED
Add rate limiting, then investigate.