Use sessions or (not as secure) pass a hidden form field along from form.php to thankyou.php. You can look for it in thankyou.php and if it's not there then you know something's wrong. You'd check the $_POST array for your secret field and value. \d -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php