keepp.

What Are Verified Forms? (And Why Some 'Verified' Options Aren't)

A verified form confirms the person submitting it controls the email address they typed — not just that it's shaped like one. Here's what that actually requires, and why most tools that claim to offer it don't quite.

By Keepp Team

A “verified form” is a form where a submission only counts once the person filling it out has confirmed they actually control the contact info they typed in. Not that it’s formatted like a real email address — an email validator can check that in a fraction of a second and still let notreal@fake.com straight through — but that a real message reaches a real inbox someone controls, or a real account confirms it’s them.

That distinction matters more than it sounds like it should, because most tools that advertise some version of “verified” don’t actually clear that bar. This post covers what real verification requires, how Keepp’s forms do it, and where the gap shows up in the tools people usually compare it to.

The two things “verified” has to mean

For a submission to actually be verified, two things both have to be true:

  1. It works for the email address the person typed, not a different identity the platform happens to already trust. A form that can only “verify” people who already have an account with the platform isn’t verifying the submission — it’s checking a login.
  2. It doesn’t depend on which email provider the person uses. Gmail, Outlook, a work address, a domain email for a business — verification has to work the same way for all of them, or it’s not really form verification, it’s account verification for one provider wearing a form’s clothes.

A form block on Keepp verifies against either standard: a one-time 6-digit code sent to whatever address was typed (works for any provider, expires in 10 minutes, up to 5 attempts), or a one-click “Continue with Google” sign-in when a form has a single field that needs verifying. Either way, the thing getting confirmed is the actual address in the actual field — not a proxy for it.

Why most “verified” options aren’t

Google Forms has a “Verified” setting under email collection, and it sounds like the real thing. It isn’t, for one specific reason: it doesn’t check the email field at all. It records whichever Google account the respondent happened to be signed into when they filled out the form. If that person uses Outlook, Yahoo, or a work domain email day to day, Google Forms has no way to verify that address — the only “verified” email it can ever produce is a @gmail.com one, or whatever address that Google account happens to be tied to. A business collecting leads from people who don’t all live in Gmail is, for a real chunk of its audience, not verifying anything.

Typeform doesn’t have a built-in verification option at all. It’s a long-standing request in their own community forum, not a shipped feature — the workarounds people use today are third-party spam-checking tools bolted on after the form already collected the (unverified) submission.

Beacons, which — like Keepp — bundles a store, a page, and lead capture into one platform rather than being a single-purpose form tool, handles spam through account policy: rules against fake information in its terms of use, not a step that checks a submission before it’s recorded.

None of that is a knock on what those tools are for. It’s just that “verified” is doing different amounts of work depending on which one you’re looking at, and it’s worth knowing which kind you’re actually getting.

Side by side

KeeppTypeformGoogle FormsBeacons
Verification method6-digit code (any provider) or Google sign-inNone built inGoogle sign-in onlyNone
Works for non-Google addressesYesNot applicableNoNot applicable
Confirms the typed email field itselfYesNot applicableNo — confirms the login, not the fieldNot applicable
Unverified submissions still recordedYes, labeledNot applicableNot applicableNot applicable

What real verification is actually for

The point isn’t to make every form harder to fill out — it’s off by default, field by field, so you only pay the friction where it earns something back. It’s for anything where “one real person, one submission” matters: a feedback score you’re going to average, a giveaway you’re capping at one entry per person, a lead list your team is actually going to spend time working through. Collecting leads and feedback from your page covers the form block itself in full — presets, custom questions, where submissions land — and why some of your leads are fake goes deeper on what unverified submissions actually cost you.

Common questions

Does verification only work with a Gmail address? No — the 6-digit code path works for any email provider. Google sign-in is the faster option when it applies, but it’s never the only one.

What happens to a submission if someone doesn’t finish verifying? It’s kept, not discarded — marked unverified in your Data view so you can still see it and decide whether to follow up.

Is this only useful for high-volume forms? No — even a single padded feedback score or a competitor scraping a form once is worth catching. Verification doesn’t need scale to matter.


Add a verified form to your keepp.link page — free to start. See pricing for the full plan breakdown.