The Code Arrived but Autofill Did Not Fill It: What to Check

The Code Arrived but Autofill Did Not Fill It: What to Check

The message is right there on screen. Six digits, sent seconds ago. But the field on the site stays empty, no suggestion appears above the keyboard, and the code that was supposed to save you a few seconds now has to be read, remembered and retyped — which is exactly when people transpose two digits and conclude something is broken.

TL;DR: If you can see the code, the message was delivered, and what failed is entry rather than delivery. Autofill is a convenience the phone or browser layers on top of a message that has already arrived, and it only appears when several separate things line up. On Android, Chrome asks permission the first time it recognises a one-time-code field and then fills only when you tap a prompt. A missing suggestion is not a verdict about a site’s authenticity. Check the service, account and current challenge before entering the code, and do not bypass a mismatch between the domain named in the message and the page you are using.

Autofill is a convenience, not the delivery path

It helps to be clear about which part of the chain has actually failed.

A verification code reaches you through a message. Whether that message arrives at all depends on the number it was sent to and the line that owns it — a different subject with its own causes, and one that matters if you are, for instance, expecting a code on a data-only travel plan.

Autofill sits on top of that. Once a message has landed somewhere the operating system can read, the system may offer to put the code into a field for you. If that offer does not appear, nothing about the message itself has changed — though that is not the same as saying the code is still good. A visible message can be an old one, a superseded one, or an answer to a different challenge than the one on screen. And where a code is bound to a domain, a missing suggestion can reflect that the page does not match the domain the code names, which is worth checking rather than overriding.

So the first thing to settle is simply whether you can see a code. If you can, a message was delivered, and everything below is about the last few centimetres between the message and the box — after you have checked that the code in front of you belongs to the service, account and challenge you are actually completing.

What has to line up before a code is offered

Several independent conditions have to hold at once, which is why this feature is more fragile than it looks.

The system has to recognise the field as a one-time-code field. A box that looks obvious to you is not necessarily recognised as one. How a site signals that is the service’s own implementation, and it is not something you can supply or alter from your side.

Permission has to exist. On Android, Google documents that Chrome asks for permission the first time it identifies a one-time SMS verification code field. Google’s page also covers the case where that access was previously denied, which is worth checking before concluding the feature is unavailable.

You have to act. Filling is not silent. Chrome’s documented behaviour is that a prompt is displayed and the code goes in when you tap it. On iPhone, Apple’s guidance on automatically filling in SMS passcodes describes a detected code being suggested above the keyboard for you to tap. In both cases the code is offered, not inserted on your behalf.

The message has to be somewhere the feature is looking. This condition has its own section below.

For domain-bound codes, the domain named in the message has to match. Apple documents AutoFill for domain-bound SMS codes, in which a code carries the domain it belongs to and AutoFill matches that against Safari’s current domain or an app’s associated domain. Apple presents this as a protection against phishing. Where they do not correspond, no suggestion is offered.

Android also exposes settings for this. Google’s page describes verification-code autofill options covering codes in apps and sites and codes in your default browser, which is worth knowing before concluding that a phone simply cannot do it.

Where the code is, and where autofill is looking

This distinction is not a settings question, and it is worth checking early for that reason.

The SMS features described here read messages that have arrived in the phone’s own messaging system. If a code reached you somewhere else, those particular features have nothing to act on. This is a statement about the SMS autofill documented above and not a claim about every integration: Apple, for instance, documents verification-code AutoFill from Mail in Safari, so other channels are not categorically excluded and capabilities differ between browsers, password managers and devices.

The clearest case is a rented verification number. When you order a number from us, the messages for that order appear in the order’s own inbox in your account, on whatever screen you have open. That is a web page showing the content of a message received by a number you rented, rather than a message in your handset’s own messaging app. The SMS autofill described here reads the phone’s messages, so it has nothing to act on there, and moving the code across is a copy you make yourself. That is a statement about this feature and not about every integration a browser or password manager might offer.

Something similar applies when a code arrives into a service’s own app or a chat platform rather than as an SMS. The feature is looking in one specific place, and if the code is not there its silence carries no information about the code itself. Email is not a clean example of this, since Apple documents code AutoFill from Mail in Safari; what an unrelated channel supports depends on that combination of app, browser and system.

What the symptom points at

What you see What it is consistent with First thing to check
Code visible in the phone’s messages, no prompt at all Permission not granted or previously denied, or the field not recognised Whether verification-code autofill is enabled for apps and for your browser
Prompt appears but the field stays empty Focus is on a different field, or the page changed as you tapped Tap directly into the code box, then follow whatever the flow offers next
Code is in a rented number’s order page Expected — that message did not arrive in the phone’s messaging app Copy it from the order page yourself
A suggestion appears with an older code More than one code is present and the newest may not be the one offered Read the code in the message itself and compare before tapping
No suggestion on one site, suggestions elsewhere Possibly a domain-bound code with no matching site, or an unmarked field Whether you reached this site yourself rather than through a link

That last row is the one to be careful with in both directions. A missing suggestion does not establish that a site is fraudulent, and a present one does not establish that it is safe. Having started the flow yourself is necessary but does not settle it either. Domain binding is a real protection, so where a code names a domain that does not match the page you are on, that mismatch is the thing to take seriously rather than to route around.

Two situations worth walking through

Both are hypothetical, written to show the reasoning rather than to report a case.

The code that never touched the phone. Someone rents a number to register with a service, keeps the order page open on a laptop, and works through the signup on that same laptop. The code arrives and is visible in the order’s inbox. They then spend some time looking for why their phone is not offering to fill it. The handset never received that message: it was delivered to a rented number and displayed on a web page. The SMS autofill described here has nothing to read, so copying the code from the order page is the straightforward answer. If the code has not appeared there at all, that is a delivery question rather than an autofill one, and what a temporary number can and cannot do about a second code is the relevant reading.

The absent suggestion that was read as a warning. Someone opens a familiar service, requests a code, receives it, and notices that the suggestion they usually get above the keyboard does not appear this time. Their first thought is that the site might be fake. That inference is not supported: a suggestion can be missing because the field is not marked as a code field, because permission was declined at some point, or because the code is bound to a domain that does not correspond to the page they are on — and none of those distinguishes a genuine site from a fraudulent one. How they arrived still matters — following a link from a message or an email is a reason to stop, leave the page and reach the service the way they normally would before starting again. But typing an address or opening a saved bookmark is not itself proof that a destination is genuine, so it does not settle the question either. Before entering the code, the things worth confirming are that it names the service and account they expect, that it answers the challenge in front of them, and that the page they are on is the one the code was issued for. A domain mismatch is not something to work around because the flow was self-started.

Typing a code by hand without creating a new problem

Entering a code manually is a normal thing to do, and the caution attached to it is narrow and specific.

Type it into a flow you started, having first checked that the code names the service and account you expect and answers the challenge on screen. Reaching the site yourself is necessary but not sufficient on its own. Do not read a code aloud to anyone, forward it, paste it into a chat, or enter it on a page that someone else directed you to — a point covered at more length in what to do about a code you did not request.

Read the code from the message rather than from a notification preview if more than one has arrived, since the most recent notification is not always the most recent code.

If the code is rejected after a careful retype, check that it is for the service and account you are signing in to, that it answers the challenge currently on screen, and whether it has passed whatever expiry the service states. Follow the instructions the flow itself displays; requesting another code is only available where that flow offers it. If the number may have been entered incorrectly at some earlier point, checking the number format and how it was entered is the place to look.

One thing not to do: do not grant broad access to your messages to an unrelated app in the hope of making autofill work. The feature does not need it, and the trade is a poor one.

Limitations of this guide

This describes the conditions under which a phone or browser offers a code, drawing on Google’s documentation for Chrome on Android and Apple’s material for iPhone. It does not cover every device, launcher or keyboard, and the settings screens differ between manufacturers even when the underlying behaviour matches.

Whether a particular site’s field is recognised is the service’s own implementation. A reader may be able to observe it but cannot change it, and settings on your own device do not substitute for it.

This guide is scoped to the SMS autofill features named in it. Other integrations exist — Apple documents code AutoFill from Mail in Safari — and what any given browser, password manager or device combination supports is outside what is described here.

Autofill behaviour on its own is not a reliable way to tell a genuine site from a fraudulent one, and this guide does not offer it as one. Domain binding is a real protection, so a mismatch deserves attention rather than a workaround; what it does not provide is a verdict you can read off a missing prompt.

Our help answers cover the ordering side, and a support ticket is the route for anything specific to an order you placed with us.

FAQ

The code is in my messages but nothing is offered. Is the code broken?

The absence of a prompt does not say anything decisive about the code. A visible message was delivered, and the convenience layer failing does not change that. It also does not establish that the code is still current — it could be an earlier one, or an answer to a different challenge. Check which service, account and challenge it belongs to, then type it in.

Why does autofill work on some sites and not others?

Because part of the requirement belongs to the site rather than to your phone. The field has to be recognised as a one-time-code field, and a domain-bound code is matched against the domain named in the message. Both depend on the service’s own implementation, which is why the same phone behaves differently in different places.

Does a missing suggestion mean the page is fake?

Not on its own, and the reverse is not safe either: a suggestion appearing is not a guarantee. A prompt can be missing because permission was declined, because the field is not recognised, or because the code is bound to a domain that does not match the page. Apple presents domain matching as a protection against phishing, so a mismatch is worth taking seriously rather than working around. Treat the absence as a reason to check what service and account the code is for and whether the page matches, not as a verdict in either direction.

Why does my phone never offer codes that arrive on a rented number?

Because that message does not arrive in your handset’s messaging app. A code sent to a rented number is received by that number and displayed in the order’s inbox in your account, which is a web page. The SMS autofill feature described here reads the phone’s own messages, so it has nothing to offer from that page, and copying the code across is a separate action you take yourself.

Is it safe to type a verification code by hand?

Yes, within a flow you started, once you have checked that the code names the service and account you expect and answers the challenge in front of you. Starting the flow yourself is necessary but does not on its own establish that a destination is genuine. Never relay a code to a person who contacts you about it, however plausible the reason sounds.

Should I give an app permission to read all my messages so autofill works?

No. Code suggestion does not require handing broad message access to an unrelated app, and doing so exposes far more than the one code you were trying to enter. If the built-in feature is not offering a code, entering it manually is the better trade.

Ready to try SMSCode?

Create an account and get your first virtual number in under two minutes.

Get started →