Website Contact Form Not Working? Here's How to Check

A grey letterbox slot with envelopes stacking up unopened on the ground beside it, one envelope rendered in acid green sliding past the slot into empty space, on a bone-cream ground.

A contact form not working rarely looks broken from the outside. The visitor fills it in, sees a "thanks, we'll be in touch" message, and closes the tab assuming the job's done. Nothing on that screen tells them whether the message actually went anywhere at all, and nothing tells the business it didn't arrive either. Both sides just assume the other one has gone quiet. That's a different problem to whether the website is being found at all, covered in a separate guide on checking whether it's working. A site can rank well, load quickly and get real visitors, and still fail at its one actual job: getting an enquiry back to the business that owns it.

Why is my website contact form not working, even though nothing looks broken?

Because in most cases it isn't broken in the way people expect. The form submits, the confirmation page loads, and the visitor never sees an error. What actually goes wrong happens a step later: the website hands the message to email to deliver it, and email delivery is the part that quietly fails. The enquiry can sit undelivered, or land in a spam folder nobody checks, while the form itself reports a perfect success every single time. No error, no warning, nothing.

What actually stops the email from arriving?

Usually it comes down to authentication the sending domain was never properly given. The NCSC's own guidance on email security sets out three checks a receiving mail server can run before deciding whether to trust a message: SPF, which "allows you to publish IP addresses which should be trusted for your domain"; DKIM, which lets a sender "cryptographically sign email... to show it's from your domain"; and DMARC, which tells the receiving server what to do with anything that fails those checks.

A common pattern: the website platform sends the notification email from its own shared address, rather than one tied to the business's own domain. Even where SPF and DKIM are set up correctly for that shared address, a receiving mailbox has no way of knowing the message is really meant for it, and a spam filter has little reason to trust it over the thousands of other messages leaving the same servers that day. It rarely gets rejected outright. It's more likely to be filed quietly as spam, landing in the folder nobody opens rather than the inbox somebody does.

None of this needs anyone to become an email administrator. The useful part is knowing these settings exist, and that whoever manages the website or the email behind it is responsible for getting them right, the same way they're responsible for the site loading properly in the first place. If a check comes back with a problem, that's a fair thing to hand back to them to fix, not something to work out alone.

How do you check your own form is actually catching enquiries?

Test it yourself, the way a customer would, and do it more than once.

  • Submit a real enquiry. Use the form itself, from a phone, on the live mobile site, not a preview inside a website builder's editor.
  • Check the spam or junk folder, not just the inbox. A form that's been silently filed there for months looks, from its own end, exactly like one that's never had a problem.
  • Confirm the address is still being read. If the business has changed email provider recently, the form may still be pointing at an inbox nobody opens any more.

The NCSC also runs a free email security check that tests whether a domain has SPF, DKIM and DMARC set up correctly. It's worth running once, and again after anything changes about how the business sends mail.

Does the same problem affect booking and quote-request forms?

Yes, often worse, because a booking or quote-request form usually asks for more commitment from a customer than a simple contact form does. A scheduling tool that just fires off a notification email has exactly the same weak point: if that email doesn't land, the business has no idea a booking exists until the customer chases it, or doesn't chase it at all and books somewhere else instead. A tool with its own dashboard, where a booking shows up whether or not the email arrives, removes that single point of failure. It's worth asking, when comparing booking software, whether email is the only record of a booking or just one of several.

Should a form be the only way to get in touch?

No, and this is the cheapest fix available. A phone number printed clearly alongside the form, and a WhatsApp number for anyone who'd rather message than call, gives a customer more than one route the moment a form goes quiet, and neither costs anything extra to add. A form that's failed silently for weeks is usually only discovered by an annoyed customer ringing to ask why nobody replied, or by an owner testing it on a hunch. Neither should be how it's found.

What's worth checking again, not just once at launch?

The same things that broke it the first time can break it again. An SPF or DKIM record can be overwritten by an unrelated change, moving email provider, adding a booking tool, switching to a helpdesk inbox, without anyone connecting it back to the contact form months later. Nobody thinks to check. A quarterly reminder to send one real test enquiry is a five-minute check against the alternative, which is not knowing how many enquiries have actually gone missing.

Checking a form still works, alongside the domain and email settings behind it, is exactly the unglamorous kind of maintenance an ongoing business email setup needs and rarely gets. It's part of what a proper care plan should cover, not something that only gets noticed once a customer complains. Get in touch if it's been a while since anyone actually tested yours.

Frequently asked questions

How do I test whether my contact form is actually working?

Submit a real enquiry through it from a phone, the way a customer would, then check the inbox it sends to and the spam folder next to it. Do this every few months, not just once when the site first goes live.

Why do contact form emails end up in spam?

Usually because the sending domain is missing SPF or DKIM authentication, the checks the NCSC's own guidance says a receiving mail server uses to decide whether to trust a message before deciding where to put it.

What are SPF and DKIM, in plain terms?

Two records added to a domain's settings that let a receiving mail server confirm an email genuinely came from that domain. The NCSC describes SPF as publishing which senders are trusted, and DKIM as a cryptographic signature the receiving server can check.

Should a website show a phone number as well as a contact form?

Yes. It costs nothing to add and gives a customer a second way to reach the business the moment a form goes quiet, whether that's a genuine fault or the enquiry simply landing somewhere unseen.

Does the same risk apply to booking and quote-request forms?

Yes. Any form that hands off to email to notify the business has the same weak point. A booking tool with its own dashboard, where a booking shows up whether or not the notification email arrives, is the safer setup.

Your website is one form away.

Tell us your business name and your town. We build the site, you preview it from your inbox, and the invoice waits for the yes.