Site Trusted Domains management breaking our communication form

We have followed official docs and successfully added an embedded HubSpot form into our application:

Our application can be installed in any AWS account with any domain chosen by the customer. In other words we don’t control installations or domains.

After 16th May 2024 (as stated in the link provided) HubSpot started to treat any form submission as spam if the source is not added as a site domain. Since we don’t even know what those domains could be we have no way to overcome this situation.

After talking with HubSpot support apparently there is “no way to adjust this process”. I really think you should allow this behavior since it was the way your platform was working before the change.

I would really love to have a way to configure a form to be public and completed by anyone despite its domain source. In this case the form is for sending newsletters to customers or any person interested in them (we allow to any annonymus person to complete this form from our public website or from their custom installation).

I’m affected by this change too.

My form is public and I have no way of knowing where people are filling it from, but also we are supposed to know where it is embedded from scratch and put other measures into it to avoid multiple spams.

Forcing the embedded to allowlist and avoid every domain should be optional, a blocklist instead in my case is also better.