I've just tried adding a hiding form input and check for it in sender page.
Just after a few minutes I received another of that contact mails.
How is it possible for those people to surpass
if(!isset($_POST['pass']) || $_POST['pass'] != 'yes') exit;
I'll try now with referer option.