Home › Guides › Keeping every entry

Exporting contact form entries to a CSV file

A good export gives one row per entry and one column per field, named by the field's label, plus the date and status. It should also be safe to open: a value typed into a public form can start with =, and a spreadsheet will run it as a formula unless the export neutralises it.

One entry: the visitor's answers, the form and page it came from, the mail status with its time, and Resend.
One entry: the visitor's answers, the form and page it came from, the mail status with its time, and Resend.

Why CSV exports need to be careful

Anyone on the internet can type into your contact form. If someone enters =HYPERLINK("http://…","Click") as their name, and the export writes it as-is, Excel or LibreOffice may treat it as a formula when you open the file. This is called CSV or formula injection, and the standard defence is to put an apostrophe in front of any value that starts with =, +, -, @, a tab or a carriage return, so the spreadsheet shows it as text.

One more place counts, and many exports miss it. Excel in Danish, German or French opens a .csv with the semicolon as its separator, so a value such as a;=1+1 becomes two cells there — and the second one starts with =. A quotation mark doesn't hide it either: a;"=1+1 is written to the file as a;""=1+1, and a program that splits on the semicolon can read the "" as an empty quoted start and =1+1 as the cell.

See how a value is written to the CSV export

This tool runs in your browser with JavaScript on; nothing you paste leaves the page.

What Formsafe's export contains

  • One column per field, headed by the field's label — also a field you've since removed or renamed, under the label it had when the entries arrived — then Date and Status.
  • Commas, semicolons, tabs, quotes and line breaks inside values quoted the standard way (RFC 4180), so a message with several paragraphs stays in one cell.
  • UTF-8 with a byte-order mark, so Excel shows names such as Søren or Zoë correctly instead of garbled characters.
  • The apostrophe rule above, at the start of every value — and after every semicolon, tab or line break inside one, where a semicolon Excel would start a new cell. Spaces and quotation marks in front of the formula don't get past it.

Opening it

In Excel, open the file directly or use Data → From Text/CSV. In Google Sheets, use File → Import. If a date column looks odd, set the column's format; the file stores the text as your site showed it.

One form per file

Each form has its own fields, so each export is one form's entries: choose the form at the top of Formsafe → Entries, then press Export these entries as CSV. You get a clean sheet of, say, quote requests only, with that form's labels as the column headings. The file holds exactly the entries the list shows: search first, and only the matches are exported. To move the form itself to another site — not its entries — use the forms file described in copying a form to another site.

Formsafe Contact Form is a free contact form that saves every entry before it sends anything, and shows you what happened to each email.

See what it does