Our own site · AI services
A website chat that turns an email address into a real enquiry
Website chats collect a visitor's details and then nobody sees them, or the bot promises a callback it cannot make.
The chat on this site. An email address typed into it becomes a real enquiry, and it says so plainly when sending fails.
Our own system, used on our own site.
The everyday problem
An email address in the chat becomes an enquiry in our inbox, and the chat tells the truth about it.
The hard part
- A lead that nobody sees
An email address in the chat is sent as an enquiry by the same code as the contact form.
- A promise it cannot keep
If sending fails, the chat says so and gives our email address.
- A flood using up the mail key
Five enquiry sends per IP address per 10 minutes, and 50 a day across the site, counted in memory.
- Header injection
The enquiry is plain text, and every header field is kept to one line.
- A webhook that goes quiet
After 12 seconds, the scripted answer replies.
How it runs
How a chat message becomes an enquiry a person answers.
Sample run- Step 1: Message.
- Step 2: Guards. Same-origin, JSON only, send limits.If this fails: Over the send limit: says it could not pass it on, gives our email.
- Step 3: Intent rules or webhook. Whole-word intents; optional webhook, 12-second timeout.If this fails: Webhook slow: scripted answer.
- Step 4: Email address spotted.
- Step 5: Enquiry sent. Plain text, Reply-To set to the visitor.If this fails: Sending fails: the chat says so.
- Step 6: Transcript follows. Later messages forwarded.
Tap “On fail” to see what happens when a step breaks.
Edge cases we handled
| When | What the system does | Try it |
|---|---|---|
| A visitor types an email address. | It is sent as an enquiry, and the chat says a person will reply. | No phrase to try |
| Sending fails, or no destination is set. | The chat says it could not pass it on and gives our email. | No phrase to try |
| One IP address leaves five enquiries in 10 minutes. | The sixth is not sent. The chat says so and gives our email. | No phrase to try |
| A request comes from another website. | Refused: same-origin only. | No phrase to try |
Guardrails and hand-off
Guardrails
- Same-origin, JSON-only requests.
- Send limits per IP address and per day, counted in memory.
- Plain-text enquiries, with one-line header fields.
- On the scripted path, it promises a reply only once the enquiry was sent.
When a person takes over
An email address in the chat becomes an enquiry to our inbox, with Reply-To set to the visitor. A person replies from there.
Not in this build yet
We would rather you hear it from us.
- Replies are scripted unless the AI webhook is configured, and the deploy does not configure one.
- When the webhook answers, the enquiry step is skipped: it runs only on the scripted path, and with a webhook set every message goes to that workflow.
- The send limits are counted in memory, so they start again when the server restarts.
Built with
- Next.js
- TypeScript