You should allways do basic checks when accepting data via a form, even if not entering that data into a database.
Code:
$toemail = $_POST['toemail'];
$subject = $_POST['subject'];
$message = $_POST['message'];
-//--------------------------//-
$toemail = strip_tags($_POST['toemail']);
$subject = strip_tags($_POST['subject']);
$message = strip_tags($_POST['message']);