Trust
Every form field has a label
trust.unlabelled-form-fields
Why this matters
A field whose only description is grey text inside the box loses that description the moment somebody starts typing. Anybody who is interrupted half way down a form comes back to a column of filled-in boxes with nothing saying what each one held, and a screen reader announces most of them as "edit text" and nothing else. A visible label also gives the field a bigger target, because tapping a label focuses the box it belongs to.
Who fixes it
You can, usually
Roughly how long
1–2 hours
Care needed
Low risk to change
How to fix it
Give each field a visible `<label>` with a `for` attribute matching the field's id, and keep the placeholder for an example rather than for the name of the field. Where the design genuinely has no room for a visible label, `aria-label` on the field is an acceptable second best — but a visible one is better for everybody, not only for screen reader users.
On your platform
WordPress
In WPForms and Gravity Forms every field has a Label, and an option to hide it — that option is what usually causes this, because a designer turned it off and used the placeholder instead. Turn it back on. In Contact Form 7 you write the markup, so wrap the field tag in a `<label>`.
Shopify
The theme's contact form section, in Edit code. Shopify's checkout is labelled correctly and is not yours to change, so this is always a theme form or an app form.
Drupal
Webform gives every element a Title and a Title display setting; set to Invisible it produces exactly this finding. Changing it back to Above is usually the whole fix.
Joomla
The forms extension's per-field label and its show/hide switch. Joomla's own contact form labels its fields, so this is nearly always an extension.
How we score it
Failing this check takes up to 12 points off your trust score. It is a fact about your site rather than a measurement, so it reads the same on every scan until you change something.
Does your site pass this one?
This check runs on every scan, along with the other 106. Free, no account, and you see the evidence for each result.
Check my siteOther trust checks
- Browsers are allowed to fill in your formsSetting autocomplete to off tells the browser not to offer a visitor their own saved details. On a phone that turns a form somebody could have completed with one tap into a dozen fields typed with a thumb, and every extra field measurably costs completions. It is almost always inherited from a template or added years ago to stop a browser suggesting the wrong thing, and on a password field it is worse than useless: password managers ignore it, so the only people it stops are the ones typing by hand, who then choose something they can remember.
- Email cannot be forged from your domain (SPF)There is no record saying which servers are allowed to send email as you. That means someone can email your customers from your address, and it also means your own legitimate email is more likely to land in spam.
- Fields tell the browser what they are forAn autocomplete token tells the browser that a box wants an email address or a postcode, so it can offer the visitor the one they have saved. Without it the browser has to guess from the field's name, and it frequently guesses wrong or gives up. It is also a WCAG requirement at AA, because the same information lets assistive software present a field in terms somebody recognises.
- Forms submit over a secure connectionA form that posts to a plain HTTP address sends everything typed into it unencrypted, readable by anything between the visitor and your server. Browsers warn about it directly on the field when the form collects a password or payment details. A page can be served over HTTPS and still have a form that submits insecurely, which is why this is checked separately from the connection itself.
- Phone and email fields bring up the right keyboardA box expecting an email address should be marked as one. When it is not, a phone shows the ordinary letter keyboard rather than the one with the @ sign on it, and the browser does not check the address looks plausible before the form is sent. The same goes for a phone number, which should bring up the number pad. It is a single word in the markup and it is the most common reason a mobile enquiry form feels awkward to use.
- You are told when someone forges your email (DMARC)DMARC tells mailbox providers what to do with email that fails your other checks, and sends you a report when someone tries. Without it, impersonation attempts happen silently.