How it works

Why an upload form rejects your PDF

Why does the application form keep rejecting my PDF?

Short answer

Size is the most common reason and far from the only one. Forms also refuse files that are encrypted, files whose form fields were never flattened, files with too many pages or the wrong page size, files a stricter parser considers damaged, files that are not really PDFs despite the extension, files carrying attachments, and scans where the form needed text it could read. The message rarely says which, so the useful thing is to check them in the order that costs least.

First work out where it failed

An upload passes two quite different sets of checks, and knowing which one refused you throws out most of the list before you change anything.

1234

Where an upload can be refused

  1. Your file, before anything has been sent.
  2. Checks the page can make on your own machine: the extension, and often a size limit. These fail instantly — the upload never starts.
  3. The upload itself. Everything below this line happens after the file has left, which is why those failures come with a progress bar first.
  4. A check on the server: opening the file, decrypting it, counting pages. Encrypted and damaged PDFs are refused here, and the message is usually least helpful here too.

Rejected instantly, before any progress at all. That was your own browser. The page looked at the file you chose — its name, its extension, sometimes its size — and refused without sending a byte. Nothing about the contents of the PDF is involved, because nothing has read them. So this is size or extension, and nothing else on the list.

Rejected after the progress bar finishes, or after a pause. The file arrived and something on the other end tried to open it. Everything that depends on what is inside the file lives here: encryption, damage, page counts, attachments, live form fields, and whether there was readable text.

The upload stalls, hangs or times out. Usually a size limit somewhere between you and the application that nobody advertised, or a slow connection against a short timeout. Try a smaller file before you conclude anything else.

Then work through the causes in this order, because that is roughly the order of how likely they are and how cheap they are to rule out: size, encryption, unflattened form fields, page count and page size, and then the file itself.

Size, and the limit that is not the one on the page

Start here, but do not stop here if the numbers say you are already under.

Unlike email, an HTTP upload does not inflate your file. A form posts the bytes as they are inside a multipart/form-data body, with a few hundred bytes of boundary and headers around them — so the 33% expansion that catches people out with email attachments does not apply. If your file is 4.6 MB and the stated limit is 5 MB, size is probably not your problem.

What does catch people out:

  • The limit may be for the whole submission, not each attachment. Three documents of 4 MB against a 10 MB total is a rejection that looks like nothing is wrong with any individual file.
  • A server or proxy in front of the application may cut off lower than the form says. This is the case that presents as a timeout rather than a message.
  • Megabytes are counted differently. A limit of “5 MB” may mean 5,000,000 bytes or 5,242,880. A file at 5.01 MB by your file manager’s reckoning can be over one and under the other.

If it genuinely is size: compress to 1 MB, 2 MB or compress with a quality setting. Before you do, find out why the file is large, because that decides whether it can shrink at all — a scan has a great deal of slack in it (why a scanned PDF is so large), while a text document with a few diagrams may already be as small as it gets (why some PDFs cannot be compressed).

A password you did not know was there

This is the cause people least expect, because the file opens perfectly well on their own machine.

123

Two passwords that do different jobs

  1. The open password. Without it the file cannot be read at all — the contents are encrypted.
  2. The permissions password. The file opens for anyone; it is printing, copying and editing that are marked as not allowed.
  3. Both can sit on one document, and they are not the same protection. Only the first keeps anybody out.

A PDF can carry two passwords. An open password makes a reader ask for it before showing you anything. A permissions password sets restrictions — no printing, no copying, no editing — and does not prompt at all: the document opens, and your reader quietly agrees to the restrictions on your behalf. Both are encryption as far as the file format is concerned.

Server-side PDF libraries do not quietly agree to anything. Many refuse to parse an encrypted document at all, whether or not the open password is empty. So a bank statement or a payslip that opens with a double-click on your laptop can be, to the thing on the other end of the upload, an encrypted file it will not touch.

How to tell: your reader’s document properties has a security section, and will say Security: Password Protected or list permissions as “Not Allowed”. If any tool reports the file as encrypted while it opens without prompting you, that is exactly the situation.

The fix is to produce a copy without the encryption — Unlock PDF, for documents you are entitled to open, which runs on a server and therefore uploads the file. If the document came from an account you control, downloading it again from a setting that does not apply a password is cleaner. What a PDF password actually protects covers the two kinds and what each is worth.

You filled the form in and it arrived blank

Not strictly a rejection, but the same afternoon wasted, and the mechanism is worth seeing because it explains a whole family of complaints.

123

Why a filled form arrives blank

  1. Your reader shows the form filled in, and the page looks complete.
  2. The text is not on the page. It is held in the field object beside it, with a ready-made picture of itself that a reader may or may not draw.
  3. Anything that renders the page and ignores the fields gets the blank form. Flattening writes the values into the page, after which nothing can lose them.

An interactive PDF form keeps what you typed in a field object, alongside the page rather than in it, with a small generated picture of the value attached. A reader draws the page and then draws the fields on top. A program that draws the page and does not care about fields — which describes a good many conversion and preview pipelines — produces the empty form.

Flatten PDF writes the values into the page content itself. After that there are no fields to ignore, every reader shows the same thing, and the document is what it appears to be. Do it last: once flattened, the answers cannot be edited again, which is usually the point. How PDF forms work and what flattening means go further into it.

The same applies to a signature placed with Sign PDF and to annotations generally. If it matters that the recipient sees it, make it part of the page.

The rest of the list

  • Too many pages, or the wrong page size. Portals that print what you send often cap both, and mixed page sizes in one document break the ones that do not. Page count and file info reports both; extract pages or split if you need to cut it down, resize if the sizes are inconsistent.
  • The file is damaged and your reader was being generous. Desktop readers repair a great deal of minor corruption silently; a server library usually refuses. If the file has been through email, a USB stick and three re-saves, run it through repair PDF, which rebuilds the cross-reference table around the objects that are still intact. Why a PDF will not open covers the failure in detail.
  • It is not a PDF. Renaming a file does not convert it. A .docx saved as report.pdf fails the moment anything reads the first few bytes, and a file called report.pdf.pdf or report.PDF trips some forms’ extension checks even when the contents are fine.
  • It contains other files. A PDF with attachments, or a PDF Portfolio — a wrapper whose real content is a set of embedded documents — is often refused outright, and when it is accepted the reviewer may see only the cover page.
  • It is a scan when text was required. Some systems parse the document to pull out names, dates or reference numbers. A scan passes every technical check and is rejected on content, because there is no text in it. OCR is the fix, and it runs on a server, so the file is uploaded.

If you have worked through all of that and it still fails, stop guessing. The people running the form can see the actual error, and “what did your validator say?” is a much shorter conversation than another six attempts. A form that refuses a valid PDF without saying why is their bug, not your file.

Tools this article covers

Sources

Primary documentation for the claims above.

Last reviewed: September 28, 2026

Published by iBuildPDF.

More from the knowledge base

Browse the knowledge base