A contact form is a public endpoint, so it's a target. The server-side defences worth stacking, and the story of a test bypass left running in production.