QA Ultimate Stack

Run real form submissions safely

Validate without submitting, submit only with explicit confirmation, keep test hits out of GA4 with Anonymous Run, get past bot protection with an agreed header, and agree the CRM clean-up before the first run.

Validate first; submit only on purpose

The form test has two ways to run:

  • Validate Configs opens a real browser, fills every field on the live page and confirms the submit button exists, but never clicks it. Nothing is submitted, and GA4 hits are always blocked. Use it after every config change and whenever a site is updated.
  • Run Test submits the real form at the real URL. The brand's CRM or lead system receives it. You have to tick I understand each time.
Validate fills and checks; Run Test submits and needs explicit confirmation.

Two panels comparing Validate Configs, which never submits, and Run Test, which submits real forms after confirmation.

Keep test hits out of GA4 with Anonymous Run

Anonymous Run is on by default for real runs. ODDVX reads each GA4 hit, records its event and parameters for the tag layer, and then aborts the request before it leaves the browser. Google never records the test, so your reports stay clean, and the tag layer is still verified.

Turn it off only when you need the hit to arrive, for example to watch it in GA4 DebugView.

The hit is read, verified and then stopped before GA4 sees it.

Four steps: the tag fires, ODDVX reads the hit, the request is aborted, and GA4 never receives it.

Agree the clean-up before the first real run

  • Tell the client which forms will be tested and when.
  • Agree a CRM filter on the QA_TEST_ values and the @qa-test.invalid email domain.
  • Mute auto-responders and sales alerts for test leads where possible.
  • Keep Anonymous Run on unless GA4 must receive the hit.

Schedules can never submit. A scheduled form test always runs in Validate mode. See Schedule QA that fails loudly.

Five agreements before anything is submitted.

A checklist of agreements before the first real form submission.

Sites behind bot protection

Some sites sit behind a web application firewall or bot manager that scores automated traffic and challenges or blocks it, even from a trusted IP address. If a run is challenged, ask the site's security team for a bypass header: a header name and secret value their firewall trusts. Add it to that form's config and ODDVX sends it for that config's runs only, never globally. Treat the value like a password.

Without the agreed header the run is challenged; with it, the form is reached.

A diagram of an automated submission passing through a bot manager: blocked without a bypass header, reaching the form with one.

Share the test agent for allowlisting

Each run shows its test agent: the browser (Microsoft Edge), the operating system, the public IP address and the user-agent string. Send these to the site's security team for allowlisting, and to whoever manages GA4 so the IP can be filtered as internal traffic.

Browser, OS, IP and user-agent: what a security team needs to allow the tests.

A test agent panel showing browser, host OS, IP address and user-agent.

ODDVX for Windows

From the page to the hit, proved.

Start free with one saved form, one page and one parity check. Premium adds batch runs, exports and scheduled QA.