QA Ultimate Stack
Run real form submissions safely
Validate without submitting, submit only with explicit confirmation, keep test hits out of GA4 with Anonymous Run, get past bot protection with an agreed header, and agree the CRM clean-up before the first run.
Validate first; submit only on purpose
The form test has two ways to run:
- Validate Configs opens a real browser, fills every field on the live page and confirms the submit button exists, but never clicks it. Nothing is submitted, and GA4 hits are always blocked. Use it after every config change and whenever a site is updated.
- Run Test submits the real form at the real URL. The brand's CRM or lead system receives it. You have to tick I understand each time.
Two panels comparing Validate Configs, which never submits, and Run Test, which submits real forms after confirmation.
Keep test hits out of GA4 with Anonymous Run
Anonymous Run is on by default for real runs. ODDVX reads each GA4 hit, records its event and parameters for the tag layer, and then aborts the request before it leaves the browser. Google never records the test, so your reports stay clean, and the tag layer is still verified.
Turn it off only when you need the hit to arrive, for example to watch it in GA4 DebugView.
Four steps: the tag fires, ODDVX reads the hit, the request is aborted, and GA4 never receives it.
Agree the clean-up before the first real run
- Tell the client which forms will be tested and when.
- Agree a CRM filter on the QA_TEST_ values and the @qa-test.invalid email domain.
- Mute auto-responders and sales alerts for test leads where possible.
- Keep Anonymous Run on unless GA4 must receive the hit.
Schedules can never submit. A scheduled form test always runs in Validate mode. See Schedule QA that fails loudly.
A checklist of agreements before the first real form submission.
Sites behind bot protection
Some sites sit behind a web application firewall or bot manager that scores automated traffic and challenges or blocks it, even from a trusted IP address. If a run is challenged, ask the site's security team for a bypass header: a header name and secret value their firewall trusts. Add it to that form's config and ODDVX sends it for that config's runs only, never globally. Treat the value like a password.
A diagram of an automated submission passing through a bot manager: blocked without a bypass header, reaching the form with one.
Share the test agent for allowlisting
Each run shows its test agent: the browser (Microsoft Edge), the operating system, the public IP address and the user-agent string. Send these to the site's security team for allowlisting, and to whoever manages GA4 so the IP can be filtered as internal traffic.
A test agent panel showing browser, host OS, IP address and user-agent.
ODDVX for Windows
From the page to the hit, proved.
Start free with one saved form, one page and one parity check. Premium adds batch runs, exports and scheduled QA.