Skip to main content
Share an active form as a public link, or show the same form in an iframe on your website. A visitor does not need a Broker Panel account to open or submit it. See Form Center for building forms and for activating, deactivating, or deleting them.

Publish a form

Allow an external embed domain

Only an Admin can change the allowed-domain list. It applies to every form for your broker. A form can always run in a same-origin iframe, but each external website origin must be added before that site can show the form. Manage Embed Domains dialog with allowed domain entries
  1. Select Form Settings in Form Center.
  2. Select Manage Embed Domains.
  3. Enter one origin per line in Allowed Domains.
  4. Select Save Changes.
Use a full HTTPS origin. The saved value keeps the protocol, host, and port when present, and the panel removes any path. This dialog accepts HTTP only for localhost. Add every required origin separately, because a different protocol, subdomain, or port is a different origin. Clearing Allowed Domains stops external websites from framing your forms.

Advanced: trusted IPs and rate limits

Public form submissions have a broker-wide rate limit: one source IP can send five form submissions in a 60-minute window for one broker. Further submissions are blocked until the window permits another. Only an Admin can configure trusted IPs. A trusted IP bypasses only this submission rate limit. It does not bypass form status checks, spam checks, or field validation.
  1. Select Form Settings in Form Center.
  2. Select Trusted IPs.
  3. Enter one IP address per line in Trusted IP Addresses.
  4. Select Save Changes.
The panel accepts individual IPv4 and IPv6 addresses only, not ranges or CIDR notation. Clear the field and save to disable the bypass.
Add only an IP that you control and trust. Do not add a visitor IP to work around a temporary rate limit.

Review submissions

Each successful submission creates a New Service request with Form as its source. The form’s Approval value decides what happens next: Manual keeps the request pending for staff review, and Automatic starts system approval after the request is created. If system approval cannot complete, the request stays pending. To review one form’s submissions, select Manage > View Submissions. The panel opens Requests with the form filter applied. The visitor sees the configured success message and is redirected if the form has a redirect URL.

Troubleshooting

Confirm the row shows the Active status, then use Manage > Open Form to test the current URL. An incorrect broker slug, an incorrect form slug, or an inactive form returns a not-found page.
Open Form Settings > Manage Embed Domains and confirm Allowed Domains contains the exact parent website origin, including protocol, subdomain, and port. Save the change and reload the parent website. If the embed-domain lookup fails, the panel permits same-origin framing only.
Manage Embed Domains needs one full URL per line, HTTPS for an external website, and no path segments. Trusted IPs needs one individual IPv4 or IPv6 address per line, with no ranges, CIDR suffixes, or other text.
The source IP reached five submissions in the 60-minute window for this broker. Wait for the window to permit another submission, and use Trusted IPs only for a fixed source IP that you control.
Confirm the visitor saw the success message, then use Manage > View Submissions to apply the correct form filter. If submission still fails, test the public form and correct the field error it shows.
Last modified on September 8, 2026