— Validation: happy path — PASS valid lead validates PASS valid lead with only required (no city/message) — Validation: required fields — PASS empty payload fails PASS name error present PASS business error present PASS phone error present PASS email error present — Validation: email format — PASS rejects "not-an-email" PASS rejects "a@b" PASS accepts normal email — Validation: phone format — PASS rejects letters in phone PASS rejects too-short phone PASS accepts +, spaces, parens — Validation: length caps — PASS rejects 151-char name PASS rejects 2001-char message PASS accepts 2000-char message — Honeypot — PASS filled botcheck ⇒ isSpam() PASS empty botcheck ⇒ not spam PASS whitespace botcheck ⇒ spam — toEmailData() shape — PASS contains the 6 lead fields PASS does NOT leak botcheck PASS preserves email value — XSS safety (mail template uses Html::encode on every field) — PASS raw