Trust
Browsers are allowed to fill in your forms
trust.autofill-blocked
Why this matters
Setting autocomplete to off tells the browser not to offer a visitor their own saved details. On a phone that turns a form somebody could have completed with one tap into a dozen fields typed with a thumb, and every extra field measurably costs completions. It is almost always inherited from a template or added years ago to stop a browser suggesting the wrong thing, and on a password field it is worse than useless: password managers ignore it, so the only people it stops are the ones typing by hand, who then choose something they can remember.
Who fixes it
You can, usually
Roughly how long
15 minutes
Care needed
Low risk to change
How to fix it
Delete `autocomplete="off"` from the form tag and from the fields. If it was added because the browser kept suggesting the wrong value, the fix is a specific token rather than none at all — `autocomplete="email"`, `autocomplete="postal-code"`, `autocomplete="current-password"` — which tells the browser exactly what to offer.
On your platform
WordPress
Where the form came from decides where the attribute is. Contact Form 7 puts the markup in the form template, so it is visible and editable there. WPForms and Gravity Forms generate the markup, so look instead for an autocomplete or browser-autofill setting on the field's Advanced tab — and check the plugin's global settings, because some disable it site-wide in one switch.
Shopify
A theme form rather than the checkout — Shopify's checkout fields are its own, correctly configured, and not editable. Online Store → Themes → Edit code and find the form section, then remove the attribute from the form tag.
Drupal
Webform sets this per element under the element's Advanced settings. If it is on the form tag rather than the field, it is in the form's own settings or in a template override.
Joomla
In whichever forms extension built the form — RSForm, Breezing Forms and Convert Forms all expose per-field attributes in the form builder.
How we score it
Failing this check takes up to 12 points off your trust score. It is a fact about your site rather than a measurement, so it reads the same on every scan until you change something.
Does your site pass this one?
This check runs on every scan, along with the other 106. Free, no account, and you see the evidence for each result.
Check my siteOther trust checks
- Email cannot be forged from your domain (SPF)There is no record saying which servers are allowed to send email as you. That means someone can email your customers from your address, and it also means your own legitimate email is more likely to land in spam.
- Every form field has a labelA field whose only description is grey text inside the box loses that description the moment somebody starts typing. Anybody who is interrupted half way down a form comes back to a column of filled-in boxes with nothing saying what each one held, and a screen reader announces most of them as "edit text" and nothing else. A visible label also gives the field a bigger target, because tapping a label focuses the box it belongs to.
- Fields tell the browser what they are forAn autocomplete token tells the browser that a box wants an email address or a postcode, so it can offer the visitor the one they have saved. Without it the browser has to guess from the field's name, and it frequently guesses wrong or gives up. It is also a WCAG requirement at AA, because the same information lets assistive software present a field in terms somebody recognises.
- Forms submit over a secure connectionA form that posts to a plain HTTP address sends everything typed into it unencrypted, readable by anything between the visitor and your server. Browsers warn about it directly on the field when the form collects a password or payment details. A page can be served over HTTPS and still have a form that submits insecurely, which is why this is checked separately from the connection itself.
- Phone and email fields bring up the right keyboardA box expecting an email address should be marked as one. When it is not, a phone shows the ordinary letter keyboard rather than the one with the @ sign on it, and the browser does not check the address looks plausible before the form is sent. The same goes for a phone number, which should bring up the number pad. It is a single word in the markup and it is the most common reason a mobile enquiry form feels awkward to use.
- You are told when someone forges your email (DMARC)DMARC tells mailbox providers what to do with email that fails your other checks, and sends you a report when someone tries. Without it, impersonation attempts happen silently.