Trust
Phone and email fields bring up the right keyboard
trust.form-field-wrong-type
Why this matters
A box expecting an email address should be marked as one. When it is not, a phone shows the ordinary letter keyboard rather than the one with the @ sign on it, and the browser does not check the address looks plausible before the form is sent. The same goes for a phone number, which should bring up the number pad. It is a single word in the markup and it is the most common reason a mobile enquiry form feels awkward to use.
Who fixes it
You can, usually
Roughly how long
15 minutes
Care needed
Low risk to change
How to fix it
Change `type="text"` to `type="email"` or `type="tel"` on the fields named here. Nothing else needs to change — every browser falls back to a plain text box if it does not understand the type, so there is no compatibility risk. Do not add pattern validation to a phone field at the same time: people write phone numbers in a great many valid ways.
On your platform
WordPress
Every form plugin has the right field type in its palette and it is usually a matter of having picked the wrong one. WPForms and Gravity Forms have dedicated Email and Phone fields — swap the field rather than editing the markup, because the plugin's own validation comes with it. In Contact Form 7 the tag itself is the type: `[email* your-email]` rather than `[text* your-email]`.
Shopify
In the theme's form section. Shopify's own themes use the right types on the contact form, so this generally means the section has been edited or the form comes from an app.
Drupal
Webform's element types include Email and Telephone; change the element type rather than the markup, and the validation follows.
Joomla
The forms extension's field type. Joomla's core contact form has fixed field types, so a wrongly typed field there means a template override is in play.
How we score it
Failing this check takes up to 12 points off your trust score. It is a fact about your site rather than a measurement, so it reads the same on every scan until you change something.
Does your site pass this one?
This check runs on every scan, along with the other 106. Free, no account, and you see the evidence for each result.
Check my siteOther trust checks
- Browsers are allowed to fill in your formsSetting autocomplete to off tells the browser not to offer a visitor their own saved details. On a phone that turns a form somebody could have completed with one tap into a dozen fields typed with a thumb, and every extra field measurably costs completions. It is almost always inherited from a template or added years ago to stop a browser suggesting the wrong thing, and on a password field it is worse than useless: password managers ignore it, so the only people it stops are the ones typing by hand, who then choose something they can remember.
- Email cannot be forged from your domain (SPF)There is no record saying which servers are allowed to send email as you. That means someone can email your customers from your address, and it also means your own legitimate email is more likely to land in spam.
- Every form field has a labelA field whose only description is grey text inside the box loses that description the moment somebody starts typing. Anybody who is interrupted half way down a form comes back to a column of filled-in boxes with nothing saying what each one held, and a screen reader announces most of them as "edit text" and nothing else. A visible label also gives the field a bigger target, because tapping a label focuses the box it belongs to.
- Fields tell the browser what they are forAn autocomplete token tells the browser that a box wants an email address or a postcode, so it can offer the visitor the one they have saved. Without it the browser has to guess from the field's name, and it frequently guesses wrong or gives up. It is also a WCAG requirement at AA, because the same information lets assistive software present a field in terms somebody recognises.
- Forms submit over a secure connectionA form that posts to a plain HTTP address sends everything typed into it unencrypted, readable by anything between the visitor and your server. Browsers warn about it directly on the field when the form collects a password or payment details. A page can be served over HTTPS and still have a form that submits insecurely, which is why this is checked separately from the connection itself.
- You are told when someone forges your email (DMARC)DMARC tells mailbox providers what to do with email that fails your other checks, and sends you a report when someone tries. Without it, impersonation attempts happen silently.