How do I stop website form duplicates in HubSpot?
Use the email as the one key, cleaned the same way every time, and match on it before anything is written to HubSpot. HubSpot already updates the existing contact when the email matches. The trouble comes from the gaps around that: submissions without an email, companies another tool creates, and a shared browser that overwrites the last person's record.
You've probably seen it. A lead fills in your form with a work address, books a call with a personal one, and now two people on your side are replying to the same person. The other version is worse: nobody replies, because the record they would have seen got overwritten by someone else's.
The handoff
A lead crosses seven steps between your form and a first reply. Each one has its own way of failing, and several of them fail without telling anyone.
| Step | What does it | Where it breaks |
|---|---|---|
| Form submitted | Your site's form: a HubSpot form, or another form HubSpot collects | HubSpot only collects an outside form that has an email-type field, sits outside any iframe, runs nothing of its own on submit and is on the page when it loads. Hidden fields are never collected, and neither is a visitor whose browser blocks HubSpot's tracking script. |
| Email checked | HubSpot's form, or nothing at all for an outside form | By default, a HubSpot form needs an email to create a contact. If you switch that off, submissions without one are matched by browser cookie, and a visitor HubSpot can't identify can become a new contact. |
| Contact matched | HubSpot, on the Email property | The same person with a second address becomes a second contact. With the form set to use cookies for new emails, a different person on the same device can overwrite the first one. |
| Company matched | HubSpot, on the company domain | Gmail and other free addresses only link to a company when the contact also has a website. Companies another tool creates through HubSpot's API skip the domain check. |
| Owner set | A workflow, the form's simple automation, or a person | Full workflows are on Professional and Enterprise plans. Rotating leads across a team needs Sales Hub or Service Hub Professional or Enterprise, with paid seats. |
| Someone told | A form notification, or a workflow email | Notifying the contact owner sends nothing when the contact has no owner, and a new contact from a form has none until something sets one. |
| First reply | A person, or a follow-up email | HubSpot's form follow-up email doesn't cover a submission from an outside form. |
Where it breaks
HubSpot matches forms and imports on the email, so when you find duplicate contacts, look for the same person under a different key. Someone uses their work address on the form and their personal one somewhere else. A tool you connected creates contacts with only a name, which HubSpot's API allows, and a name matches nothing. Or you've let submissions without an email create contacts, and each new browser looks like a new person.
Some duplicates are submissions, and the contact itself is fine. An outside form with its own validation is collected each time the visitor clicks submit, so a visitor who fixes an error leaves HubSpot a partial submission and a complete one. If you report on submissions, that lead counts twice.
Lost leads are harder to spot. With the cookie fallback on, a second person on a shared laptop can replace the first person's details. An outside form that breaks a capture rule never reaches HubSpot, and neither does a visitor who blocks HubSpot's script, so there's nothing to find later. And a lead with no owner can sit in HubSpot with nobody told.
The source-of-truth and dedupe rule
- The key for a person is the email, lowercased and trimmed. Nothing is written to HubSpot until it has been matched on that key.
- The key for a company is the domain of that email. A free address like Gmail gets no company from the form, and a person links one later if it matters.
- HubSpot is the source of truth for who the contact is, who owns them and what stage they're at. The form owns only what the person typed in that one submission.
- A submission without a usable email is held for a person to look at. It never becomes a contact on its own.
- Every submission carries its own id, so the same one sent twice does nothing the second time.
With native forms, HubSpot adds each new submission to the existing contact. In a system between the form and HubSpot, I'd have it fill only empty fields, plus the message and where the lead came from, so a job title someone corrected in HubSpot stays corrected. It checks the submission id first, then writes by email, creating the contact if it's new and updating it if it isn't.
I tested the submission id rule on a system I built, on 2026-09-16. Replaying the same submission made no second contact and sent nothing.
What stays human
A system can match on a key. Deciding that two different emails belong to one person takes someone who knows the lead, so merging stays with a person. The held submissions stay with a person too, because one look tells you whether it's a lead who mistyped their email or a bot.
When a new submission matches a contact someone else already owns, that owner decides who takes it, since only they know whether they're in the middle of a conversation. If you also want a person to approve the first reply, that's a separate handoff with its own page.
What I'd pick, per situation
| If you | I'd pick |
|---|---|
| Use HubSpot forms on a Professional or Enterprise plan | Stay native. Set the form to create new contacts from unknown emails, assign the owner in a workflow, and send the notification to a named person or team as well as the owner. |
| Use HubSpot forms on the free tools or Starter | Stay native with the same form setting, and send form notifications to a named person, because owner notifications go nowhere until someone owns the contact. |
| Use another form that passes HubSpot's capture rules | Collected forms work for a name, an email and a message. Fields land as plain text, visitors who block HubSpot's script go missing, and the follow-up email has to come from somewhere else. |
| Use a form that fails a capture rule, or rely on hidden fields for where the lead came from | Swap in an embedded HubSpot form, or send the form to a small system in between. |
| Get leads from more than one place, like the site form, a booking tool and a chat | A small system in between, so every source goes through the same email key and the same hold for missing emails before HubSpot sees it. |
| Are on a plan without workflows and want owner assignment you can count on | A small system in between can set the owner and send the alert. Weigh it against the plan upgrade, which also brings everything else workflows do. |
A system in between is one more thing to look after, so I'd build it to log each run and alert a named person when a step fails.
Questions
Do non-HubSpot forms work with HubSpot?
Yes, when the form passes HubSpot's capture rules. It needs an email-type field and HubSpot's tracking code on the page, it can't sit in an iframe or a single-page app, and it can't run anything of its own on submit. Hidden fields are skipped, and every field lands as plain text.
Which HubSpot plan do I need to assign owners automatically?
The full workflows tool starts at Professional, and rotating leads across a team needs Sales Hub or Service Hub Professional or Enterprise with paid seats. Below that, a form's simple automation can assign the contact to a paid user on Starter, and on the free tools it can only send one email.
Does a system in between slow the lead down?
Not in a way a lead would notice. On 2026-09-16, in a system I built that checks the email and the submission before writing to HubSpot, one test lead went from form to scored and drafted in 5.35 seconds. That's a single test lead, so I treat it as a rough guide.
Can I clean up the duplicates I already have?
Yes, but fix the way they're made first, or they come back. Then merge them in HubSpot with a person checking each pair, because deciding two emails are one person is a judgment call.
- HubSpot Knowledge Base, Deduplicate records: contacts match on the email, companies on the domain, and companies created through the API aren't deduplicated by domainREAD
- HubSpot Knowledge Base, Create and edit forms: the email is required by default, and with new contacts from unknown emails switched off, submissions from the same device can overwrite a contactREAD
- HubSpot Knowledge Base, Allow form submissions without email addresses to create contacts: those submissions are deduplicated by cookie, and outside forms still need an emailREAD
- HubSpot Knowledge Base, Use non-HubSpot forms: the capture rules, the tracking code must load, hidden fields skipped, every field mapped to single-line text, and a form with its own validation can leave a partial and a complete submissionREAD
- HubSpot Knowledge Base, Non-HubSpot forms FAQ: forms in an iframe aren't captured, and no follow-up email for these submissionsREAD
- HubSpot Knowledge Base, Set up form submission notifications: a contact with no owner gets no owner notificationREAD
- HubSpot Knowledge Base, Automate form submission actions: actions per form on each plan, and assigning a contact needs paid usersREAD
- HubSpot Knowledge Base, Create workflows: Professional and Enterprise subscriptions onlyREAD
- HubSpot Knowledge Base, Assign and rotate record owners using workflows: Sales Hub or Service Hub Professional or Enterprise, paid seatsREAD
- HubSpot Knowledge Base, Automatically create and associate companies with contacts: free email addresses link only through the Website URLREAD
- HubSpot developer docs, Contacts API: email is the main key against duplicates, a contact can be created with only a name, and an upsert by email creates or updatesREAD
Related
- Dedupe keyA dedupe key is the field a system uses to decide two records are the same person or company. Which key to pick, an example, and what goes wrong without one.
- Source of truthThe one system whose copy of a record wins when two tools disagree. Why it matters for opt-outs and phone numbers, and how a one-way sync keeps it that way.
- Duplicate contacts: why your CRM keeps making two of everyoneDuplicates come back after every cleanup because each intake lane creates its own records. One match rule, checked before any record is created, stops that.
- Two tools, two truths: which system is the source of truthWhen two tools disagree about a client, pick one owner tool for each field, let changes flow one way from it, and send edits made elsewhere back to the owner.
- How do I approve email replies from Slack before they go out?Approving email replies from Slack, Telegram or Google Chat: what the built-in apps do, where an approval loop breaks, the send-once rule, and what I'd pick.
- Where do your leads leak?Twelve yes or no checks across the four places a lead dies: never recorded, answered, followed up or closed out. See your worst leak and what closes it.
- Website form leads, scored and answered with a reply I approveA system I built: each website form lead is checked, added to HubSpot once and scored. Gmail sends the drafted reply when I approve it in Telegram.
- WebhookA webhook is a message one app sends another the moment something happens. What that means in plain English, how it fails, and how a system catches it.