Here's a list of the sites that have pages using a template-contact.php page template:
[1786] => http://acert.commons.gc.cuny.edu
[925] => http://trial1.commons.gc.cuny.edu
[979] => http://cynthiatobar.commons.gc.cuny.edu
[1259] => http://irnweb.commons.gc.cuny.edu
[1620] => http://shareling.commons.gc.cuny.edu
[1930] => http://testhelp.commons.gc.cuny.edu
[2097] => http://acertdev.commons.gc.cuny.edu
[2104] => http://acertdev2.commons.gc.cuny.edu
[2451] => http://cunysteam.commons.gc.cuny.edu
[2772] => http://jasonmleggett.commons.gc.cuny.edu
A couple of these are non-production sites (acertdev and acertdev2, maybe others) and one is the one from the original report (cynthiatobar). So we're looking at a small number. My suggestion is to send out an email to the admin of each site, encouraging them to move to Contact Form 7. Here's a first go at a draft:
Hello [name],
This email is to let you know about a change in policy regarding contact forms on CUNY Academic Commons sites. You're getting this email because your site [url] is using a contact form powered by your theme, [theme name]. The Commons has recently experienced a number of instances where these contact forms have been used to generate spam emails. Unfortunately, the nature of this specific contact form is such that it's difficult for the Commons team to introduce additional layers of anti-spam protection. As a precautionary measure, outgoing emails from all contact forms of this type - including yours at [url] - have been disabled.
We understand that a contact form is an important part of your website. As such, we are recommending the Contact Form 7 plugin as an alternative. It is much more flexible and feature-rich, in addition to having better anti-spam technology built in. You'll find Contact Form 7 at [link to site's plugin page]. Visit [some documentation url] for a brief walkthrough of how to set up a contact form using CF7.
We're very sorry for this inconvenience. If you need help setting up a new contact form, please reach out to the Commons team at [email or url], and we'll be glad to provide assistance.
Contact Form 7 has some decent Getting Started documentation, which we could link to: https://contactform7.com/getting-started-with-contact-form-7/ We could also perhaps offer our own Help page that summarizes the process, which might then point out to more detailed information.
Any thoughts or suggestions about the strategy or draft I've posted here? Adding Scott and Marilyn as watchers, for thoughts on the documentation/support aspects.