Why do I keep getting notifications for form submissions that are not mine?

  • SFDCERT
    Asked on July 14, 2015 at 1:42 PM

    At least once a month I get a form submission or question email sent to my account that was originated by a form that is not ours.  This is alarming, as the odds of them just accidentally sending an email to our email account is millions to one.  And if I'm getting follow up emails and questions from others, then that could mean some of my contacts are getting their questions routed to other accounts.

    What gives?

    Jotform Thread 609925 Screenshot
  • BJoanna
    Replied on July 14, 2015 at 2:48 PM

    What I can see from screenshot you provided some one replayed to your email address. Did you also got Email notification from JotForm? Also are you able to see data form that email inside of your Jotform submission? If so can you please provide us ID of your form and ID of that submission.

    I have also checked your email address of your account. That email address was on bounce list. Because of that you did not received email Notifications. Our system gave following result:

    Result: 

    info@sfdcert.com is IN  the bounce list 

    Reason(s) : smtp;550 5.1.0  sender rejected. IB504 - 198.2.128.137

    info@sfdcert.com is NOT in the unsubscribe list

    I have now removed it from our bounce list and you should now receive email Notifications.

    You can follow this guide on how to check and remove the email from bounce list:

    http://www.jotform.com/help/262-How-to-remove-your-email-address-from-bounce-list  

    Hope this will help. Let us know if you need further assistance. 

  • SFDCERT
    Replied on July 14, 2015 at 3:05 PM

    Did you also got Email notification from JotForm?

    No, I only received this email from the submitter.  That is how we usually see it - someone submits an email to change what they put in and it comes to us.

    Also are you able to see data form that email inside of your Jotform submission?

    Well, no...we don't have the form they used to submit the entry, so we wouldn't be able to see the entry.  Our form(s) are much more complex than this one.

  • BJoanna
    Replied on July 14, 2015 at 3:21 PM

    From screenshot provided seems that you did not receive email submission from JotForm.  Some user who submitted form 'Your Uniform Order Confirmation' got submission and user wanted to reply on it. During reply 'To' email is changed to your email address. That is something that you can see from screenshot. Also there is reply message on screenshot. When you are replying to some email you can change 'To' recipient in your email client to what you want. 

    Why do I keep getting notifications for form submissions that are not mine? Image 1 Screenshot 20

    Hope this will help. Let us know if you need further assistance. 

  • SFDCERT
    Replied on July 22, 2015 at 6:43 PM

    That makes NO sense.  How would someone who has ZERO affiliation with our program even get our email address to enter when they reply?  

    And how would DOZENS of people get that email address?

    What is more likeley is your system is somehow mixing 'reply to' information when they send out the email...so 'noreply@jotform.com' sends the email, but somehow puts 'info@sfdcert.com' as the reply to address.

    This scenario you dreamed up would only make sense if there was a virus or something on their computer...and what virus would redirect emails to us at random - the person would send it back to their account.

    What is MUCH more plausible is that your system is somehow sending out bad 'reply to' addresses - jumbling them between accounts - so when the person replies, it doesn't go back to the correct form owner.

    Hope that helps you diagnose the issue.  Let me know if you need further assistance.

    ...you do realize this could happen with someone who is asking for PII in a form, right?  Your system could be inadvertently sending private information to random people.

    Stop assuming it's on the submitter's end and acknowledge there could be an issue on YOUR end and do some work.

  • Chriistian Jotform Support
    Replied on July 22, 2015 at 11:13 PM

    Hi SFDCERT,

     

    I checked the account of the owner of the form and it belongs to account insightci. I checked the form and I noticed that the Reply-To setup of the Auto-Responder email of the form is set to email info@sfdcert.com. See screenshot below:

     

    Why do I keep getting notifications for form submissions that are not mine? Image 1 Screenshot 20

    We would just like to confirm if you are not affiliated to the account insightci and with this form http://www.jotformpro.com/form/51512609503953?

     

    We will wait for your response.

     

    Regards.