What are best practices/methods in preventing ajax requests and or form submisions from pages that my server did not serve?

Verifying the source of the form submission is best done by using cookies/sessions. Authenticating each request is your best protection against such cross-site attacks.

