I have a question about stopping spoofed form submissions. How about if by using the $_SERVER[\'HTTP_REFERER\'] I only allow submissions to my forms coming from
$_SERVER[\'HTTP_REFERER\']
Let us be clear: it's technically impossible to prevent spoofed form submissions. Summing it up in one sentence:
If your browser can do it, everyone can do it.