Contact Form 7 · Fix & Harden

Contact Form 7 That Actually Delivers the Enquiry

Contact Form 7 does not save your submissions anywhere. It builds an email and hands it to WordPress, and if that email fails the enquiry is gone with no record that anyone tried to contact you. Most CF7 problems are that, wearing a disguise. We fix the delivery first, then make sure it can never happen silently again.

Ask about your contact form

Australian team

Based here, working your hours — not a timezone away

144+ projects delivered

Over 10+ years building and maintaining sites for Australian businesses

One developer, start to finish

The same person every time — no re-explaining your site

Straight answers, on your terms

We only take work we can finish. Ask us anything first — no obligation

This is about making CF7 reliable, not about replacing it — it is a good plugin and on most sites it is the right one. If you need payments, conditional logic across notifications, or submissions stored and reported on, that is the Gravity Forms page and an honest comparison lives there. If the form works and you are simply drowning in spam, start with the Cloudflare page.

Nothing is saved, which is why enquiries vanish without trace

This is the fact that explains most of the support requests this plugin generates. CF7 composes an email and passes it to WordPress to send; it writes nothing to the database. So a mail that silently fails, is rejected by the receiving server, or lands in a junk folder nobody checks does not leave a failed record — it leaves no record. Businesses discover this when a customer rings to ask why nobody replied to the message they sent three weeks ago. The first thing we do on any CF7 site is make that impossible.

Your host is probably sending your mail badly

By default WordPress hands mail to the server's own sending function, which typically sends from an address your domain has never authorised. Modern mail providers treat that as forgery and either bin it or file it as junk, and increasingly they reject it outright. The fix is to send through an authenticated service and to line up the domain records that vouch for it. It is unglamorous, it takes under an hour, and it resolves the majority of "our form does not work" reports without touching the form at all.

A copy of every submission, kept in the site

Once mail is reliable, the next step is to stop depending on it entirely. A submission log inside WordPress means an enquiry exists whether or not the email arrived, survives a staff member leaving, and gives you something to search when a customer says they contacted you in March. CF7's own companion plugin does this, it is free, and it takes minutes to set up. That it is not installed by default is the single biggest gap between CF7 as shipped and CF7 as it should be run.

The form is loading on every page of your site

CF7 enqueues its stylesheet and JavaScript everywhere by default, including on pages with no form on them. On a small site that is a minor cost; combined with a sitewide captcha script it becomes one of the more noticeable easy wins available on an otherwise fine site. Restricting the assets to the pages that actually have a form is a small change, and it is the sort of thing that quietly improves the numbers Google is measuring.

Validation and conditional behaviour need help

CF7 ships with basic required-field checking and very little else, so a phone field will accept anything typed into it and a form cannot show a section only when it is relevant. Both are solvable — real validation through the plugin's filter hooks, and conditional sections through a well-maintained companion plugin — and both are worth doing on any form longer than four fields, because the alternative is staff retyping bad data and customers abandoning forms that ask irrelevant questions.

Spam handling that does not cost you a real enquiry

The consequence of spam on CF7 is different from other form plugins, because you cannot review what was blocked — there is no rejected pile to check. That makes aggressive filtering genuinely risky: a false positive is a lost customer you will never learn about. So the order matters. Stop the automated volume at the edge, keep the in-form checks conservative, and always have the submission log running first so that anything the mail layer loses is still recoverable.

When you have outgrown it, and when you have not

CF7 is free, stable and maintained, and it will keep working. The honest signals that you have outgrown it are specific rather than general: you need to take payment, you need one form to behave several ways, you need submissions reported on rather than read, or you are maintaining five near-identical forms because it cannot do conditional logic. Wanting a nicer-looking form is not one of them — that is CSS. We will tell you which side of that line you are on rather than quoting a migration by reflex.

What this costs

The core job — authenticated sending configured, domain records set, submission logging installed, a real delivery test from outside — starts at $300 and is usually the whole job. If you would rather have the current setup diagnosed and written up first, that is $249. Anything further, such as custom validation or rebuilding several forms into one, is $165 an hour or $750 for a five-hour block.

Care plans

Plans, and what each one actually includes.

Month to month, no lock-in — change or cancel any time. Prices in AUD.

Essential

$159 /mo AUD

Keeping a site secure, updated and online. No development time included.

What is covered

  • WordPress core, theme & plugin check
  • Weekly off-site backupsA full copy of your site and database taken every week and stored on separate infrastructure, not on your own server — so a failure, a hack or a bad update cannot take the backups with it., restorable on request
  • Uptime & SSL monitoringYour site is checked from outside every few minutes. If it goes down, or the security certificate is about to expire, the alert reaches us — you are not the monitoring system. — alerts come to us, not you
  • Malware checkFiles and database are scanned for injected code, so anything that has been planted is found rather than waiting to be noticed. maintained
  • Broken-link and 404 checks
  • Monthly report of site status
  • Email support included
Start with Essential

Billed monthly in AUD. Cancel any time — no lock-in.

Dev

$700 /mo AUD

Your site stays up, stays secure and stays current — and when something breaks, a developer fixes it rather than logging it.

What is covered

  • Critical security & performance checksThe checks that catch the things that actually take a site down: outdated core and plugins with known vulnerabilities, injected code, error rates, and pages that have become slow enough to lose visitors. every week
  • Uptime & SSL monitoringYour site is checked from outside every few minutes. If it goes down, or the security certificate is about to expire, the alert reaches us — you are not the monitoring system. — alerts come to us, not you
  • Weekly off-site backupsA full copy of your site and database taken every week and stored on separate infrastructure, not on your own server — so a failure, a hack or a bad update cannot take the backups with it., restorable on request
  • Your developer emails you every month with what changed and what needs attention
  • Staging site for development changesA private copy of your site where changes are built and checked before anyone else sees them. Updates, new sections and design work go there first, get looked at on phone, tablet and desktop widths, and only reach the live site once you have said so. It matters most on page-builder sites, where a bad update does not error — it re-renders, and the page looks subtly wrong on a screen size nobody checked. — nothing reaches the live site unapproved
  • 5 hours of developer time a month
  • Fixes and small changes — not a build. Content, layout and design edits, plugin and integration setup (included in dev hours)
  • 1 basic page built to match your existing design (included in dev hours)
  • Weekly WordPress core, theme & plugin updates (included in dev hours)
  • Weekly malware and virus check, and fix (included in dev hours)
  • Speed & Core Web VitalsCore Web Vitals are the three loading and stability measures Google uses as a ranking signal — how fast the main content appears, how quickly the page responds to a tap, and whether it jumps around while loading. We measure and fix all three. check and fix (included in dev hours)
  • Priority queue — a developer is assigned and contacts you within 48 hours
  • Urgent issues covered for 1 hour of immediate debugging — you are told what we found, while we work and once it is fixed
Choose Dev

Billed monthly in AUD. Cancel any time — no lock-in.

Most popular

Master

$1,300 /mo AUD

Where Dev fixes and maintains, Master builds — pages, integrations, and the email and domain problems nobody else will own.

Everything in Dev Plan included +

  • Staging site for development changesA private copy of your site where changes are built and checked before anyone else sees them. Updates, new sections and design work go there first, get looked at on phone, tablet and desktop widths, and only reach the live site once you have said so. It matters most on page-builder sites, where a bad update does not error — it re-renders, and the page looks subtly wrong on a screen size nobody checked. — nothing reaches the live site unapproved
  • 10 hours of developer time a month
  • Everything in Dev — the same checks, monitoring, backups and monthly email
  • Up to 3 pages designed and built (included in dev hours)
  • CRM, accounting and API integrationsConnecting your site to the systems you already run — a CRM like HubSpot, accounting like Xero, or any service with an API — so data moves between them without anyone retyping it. (included in dev hours)
  • Email deliverability problemsWhen forms stop arriving, or your mail lands in spam. We work through the sending records — SPF, DKIM and DMARC — and the mail service itself, rather than telling you to check your junk folder. diagnosed and fixed (included in dev hours)
  • Domain and DNS issuesExpiring domains, records pointing at the wrong place, certificates that will not renew, a migration that left half the traffic behind. The infrastructure layer most agencies hand back to you. handled (included in dev hours)
  • Custom features and functionality (included in dev hours)
  • WooCommerce & payment gateway work (included in dev hours)
  • Same-day response on anything urgent — a developer will work outside business hours if needed
  • Quarterly performance and security checksEvery three months we re-run the full audit: load times and Core Web Vitals, plugin and PHP versions, user accounts and permissions, backup restores, and anything flagged since the last review. You get the findings in writing. (included in dev hours)
Choose Master

Billed monthly in AUD. Cancel any time — no lock-in.

Ultimate

Quoted scoped to the work

When the roadmap needs more than Master, or the work is better run as a project.

Get a quote

Everything in Master Plan included +

  • 20+ hours a month, or a fixed-price project
  • A standing slot in our schedule
  • Multi-site and white-label arrangementsWe look after several sites under one agreement, and — if you are an agency or consultancy — we can work under your brand, so your client only ever deals with you.
  • Architecture, infrastructure and hosting work
  • Direct access, no ticket queue
  • We will tell you honestly whether a retainer or a fixed quote costs you less
Why CloudyWP

Why Most Contact Form 7 Problems Are Mail Problems

It stores nothing. If the email fails, the enquiry did not go to junk — it ceased to exist.

The Silent Failure Closed

A success message means the mail was handed off, not delivered. We fix the gap between those two things first, because it is the one that costs you customers who think they contacted you.

Mail That Is Authorised

Sending moves to an authenticated service with the domain records that vouch for it. Unauthenticated mail from your own domain is treated as forgery by every major provider, and increasingly refused outright.

A Copy Kept On Site

A submission log inside WordPress means the enquiry exists whether or not the email arrived, survives a departure, and is searchable when a customer says they wrote to you in March.

Assets Only Where Needed

The plugin loads its script and stylesheet on every page by default, form or no form. Restricting them to pages that have one is small work that shows up in the numbers Google measures.

Filtering Kept Conservative

You cannot review what was blocked, so a false positive is a customer lost without trace. Volume is stopped at the edge and the in-form checks stay cautious — deliberately, and in that order.

Told When To Stay Put

CF7 is free, stable and maintained, and for most sites it is the right choice. The signals that you have outgrown it are specific, and wanting a better-looking form is not one of them — that is CSS.

What Contact Form 7 users ask

Our form says it sent successfully but nothing arrives.

That message means CF7 handed the mail off without an immediate error — it is not a delivery confirmation, and the distinction is the whole problem. What happens after the handoff is invisible to the plugin. Nine times in ten this is the site sending unauthenticated mail from an address the domain does not vouch for, and the receiving server is discarding it silently. It is fixable in well under an hour and it stays fixed.

Can we recover the enquiries we have already missed?

Almost certainly not, and it is better to hear that plainly. CF7 stored nothing and the mail was never delivered, so there is nothing to restore from — this is the cost of the default configuration rather than anything you did wrong. Occasionally a server-level mail log still holds a few days of history and it is worth one look. Then we make sure the next one is never lost.

Should we just switch to a different form plugin?

Not for this. Every form plugin on WordPress hands mail to the same underlying function, so a site with unauthenticated sending will lose enquiries from any of them — you would be paying to move a problem. Fix delivery and add logging, then decide about plugins later on features, calmly, rather than in the middle of a crisis.

Is Contact Form 7 insecure?

No. It is actively maintained and has a long, unremarkable security record, which is more than can be said for many plugins that come bundled with themes. What it is, is minimal — it does exactly what it says and nothing else, and most of the trouble people attribute to it comes from the things it deliberately does not do. Those gaps are worth filling, and none of them is a reason to distrust the plugin.

We are getting hundreds of spam submissions a day.

Stop them before they reach WordPress rather than filtering them afterwards, because a submission CF7 evaluates has already cost you server work and a filtered one leaves no evidence you can review. A challenge at the edge removes the bulk of it. Get the submission log running first, though — if an over-eager filter does catch a real customer, that log is the only way you would ever find out.

Can a copy of the enquiry go to the customer as well?

Yes, through the plugin's second mail template, and it is worth setting up because it reassures the sender that the form worked. Two cautions: it must send from an authenticated address or it will be junked exactly like the notification, and it should not echo back everything they typed if the form collects anything sensitive.

Our form looks broken on mobile.

Usually the theme, not CF7 — the plugin outputs plain markup and inherits whatever the theme says about inputs, and builder modules frequently style the fields while forgetting the error and success messages. The practical consequence is that a visitor whose submission fails validation sees nothing explaining why, so they give up and you never hear about it. We check the form in its failure state, which is the state nobody tests.

Can you add a file upload?

Yes, and the parts that need thought are what the size limit should be, what file types you will accept, and where the uploads end up. CF7 attaches the file to the notification email, which means a large attachment can push the message over the receiving server's limit and the whole enquiry disappears with it. On forms that genuinely need big files, the better pattern is storing the upload and sending a link.

How do we know it is still working in six months?

Send a real test through the public form periodically and confirm it arrives from outside your own network — sending to yourself from the same server proves less than people think. This is one of the checks included in a care plan from $159/mo, because a form that quietly stops delivering is one of the few site faults that costs money continuously while showing no symptom at all.

Ask about your contact form

A short call, a fixed quote, and no obligation either way.

Get a fixed quote

Why CloudyWP

Contact Form 7 stores nothing, so mail that fails is gone with no record. We fix delivery, add a submission log and stop the spam. Melbourne-based, from $300.

Get a fixed quote

02 — How we work

From first call to live — four steps, no surprises.

Every CloudyWP project runs the same way, whether it is a one-page site or a store with a thousand SKUs. Here is exactly what happens.

01

We map what you actually need.

A single scoping call, then a written plan: what gets built, what it costs, and when it ships. No discovery-phase invoices, no moving targets.

Typically 48 hours

02

We design and build it properly.

Custom WordPress or Shopify on clean code you own outright. Every build ships fast, passes Core Web Vitals, and is handed over documented.

2–6 weeks typical

03

We automate the busywork.

Your site talks to the tools you already run — CRM, invoicing, email, stock. The repetitive admin stops being someone's job and starts running itself.

Average 15 hrs saved weekly

Scope A fixed quote, in writing

Deliverables, price and dates agreed before a line of code is written.

  • Free scoping call
  • Written scope document
  • Fixed price, no hourly creep

48 hrs to your quote

Get a quote