You need to name your contact page with a .php extenstion, not a .html
the PHP code will not be visible to the browser at all. It will just send the mail, if a sendMail server is set up(it should be).
I'll expand it a bit for you.
file name: contact.php