though you realize that all someone has to do to bypass this is add a query string right? you may be better off just making sure it's coming from your form specifically using $ENV{'HTTP_REFERER'}, which still isnt foolproof
-Robert
Hopefully there will be a witty sig here at some point