我使用以下内容发送联系我们类型的表格,iv 调查了安全性,只发现您需要保护邮件功能的 From: 位,因为我硬编码这意味着脚本是防垃圾邮件/不可劫持的
$tenantname = $_POST['tenan'];
$tenancyaddress = $_POST['tenancy'];
$alternativename = $_POST['alternativ'];
//and a few more
//then striptags on each variable
$to = "hardcoded@email.com";
$subject = "hardcoded subject here";
$message = "$tenantname etc rest of posted data";
$from = "noreply@email.com";
$headers = "From: $from";
mail($to,$subject,$message,$headers);