WP Mail SMTP Setup: Stop WordPress Emails Going to Spam

How do you complete a WP Mail SMTP setup?
A WP Mail SMTP setup replaces the default PHP mail() delivery in WordPress with an authenticated SMTP or API connection. You install the plugin, choose a sending service, enter the connection details, add SPF and DKIM records to your domain, and send a test email. As a result, your messages reach the inbox instead of the spam folder.
We wrote this guide for website and store owners, and for developers who manage their own VPS or cPanel account. In short, our goal is simple. You should understand why your order and form emails disappear, and you should fix the problem in the right order.
We are a digital marketing and web team, not a hosting company. So this guide relies on the WordPress developer documentation, the Google email sender guidelines, RFC 7208 and the plugin page on WordPress.org. So we left out every setting we could not verify. For provider specific values, use the details your hosting or sending provider gives you.
How does WordPress send email: what is the difference between wp_mail and PHP mail()?
WordPress sends every message through the wp_mail() function. For instance, that includes password resets, form notifications and order confirmations. Behind the scenes, the function uses the PHPMailer library. The phpmailer_init hook, which hands the PHPMailer object to developers, shows this clearly.
By default, PHPMailer passes the message to the PHP mail() function on the server. That function then hands the message to the local mail software. In other words, delivery quality depends on the reputation and setup of that one server. For example, on shared hosting, hundreds of sites can use the same IP address.
An SMTP or API connection works differently. Instead, it delivers the message to a sending service that has proven its identity. That service uses IP addresses and signatures that receiving servers already trust. Therefore, deliverability depends on a dedicated infrastructure, not on the luck of your server.
This article does not cover mailbox hosting. We explain how to choose a business mailbox on your own domain in our guide to business email on a custom domain. So here we focus only on the sending side of WordPress.
What does the WP Mail SMTP plugin solve, and what does it not solve?
The plugin changes how WordPress sends email. Its WordPress.org page describes the goal as replacing the default PHP mail() function with a proper SMTP configuration to improve deliverability. In short, the plugin decides how a message leaves your site.
It cannot fix everything, though. First, it does not repair your DNS records on its own. Second, it does not raise the reputation of a poor IP address, and it does not rescue a newsletter that looks like spam. Finally, it does not read incoming mail for you.
- It solves: sending through an authenticated service, sending a test message and checking the connection.
- It does not solve: missing DNS records, poor content, a blocklisted domain and restrictions on the hosting side.
- You still need: correct SPF, DKIM and DMARC records plus a From address on your own domain.
Also, knowing this up front saves time. Many site owners install the plugin, see that the problem remains, and blame the plugin. In most cases, however, a DNS record is missing.
Why do WordPress emails land in spam?
There is rarely a single cause. Still, three problems often combine. The sending domain is not authenticated, the sending IP has a weak reputation, or the content looks like bulk mail. In practice, you find out which one applies by reading the message headers.
- Missing authentication: Without SPF or DKIM, the receiving server cannot confirm that the sender speaks for you.
- A mismatched From address: If you send with an address from a free mail service, filters can read it as spoofing.
- Shared IP reputation: If another site on the same server sends spam, your messages suffer too.
- Header problems: Missing headers, an invalid reply address and wrong encoding all lower your score.
Also, the WooCommerce email troubleshooting guide draws the same picture. It explains that email problems are often deliverability problems: your server sends the message, but the recipient never gets it. The guide suggests a From address that matches your domain, proper authentication and a dedicated SMTP provider.
What do SPF, DKIM and DMARC alignment mean?
SPF lists the servers that may send mail for a domain in DNS. DKIM adds a digital signature to each message, and the receiver checks it against a public key in DNS. DMARC combines both results with the domain in the From address and tells the receiver what to do.
In other words, alignment means that the domain in the From header matches the domain that SPF or DKIM verified. According to the Google sender guidelines, senders of 5,000 or more messages a day must set up SPF and DKIM and publish DMARC. The same page requires the From domain to align with the SPF or DKIM domain.
However, even a small site should aim for this standard. After all, these three records are a trust signal for Gmail and for other large receivers. You can look up your records for free with our SPF, DKIM and DMARC checker.
SMTP or API: which sending method should you choose?
In short, three questions drive the choice. Does your host allow outgoing SMTP connections? Which connection type does your sending service offer? Do you want to keep a password in the plugin settings? Next, the table compares the three methods side by side.
| Method | How it works | Advantage | Watch out for |
|---|---|---|---|
| PHP mail() (default) | Hands the message to the local mail software | Needs no setup | Weak authentication and a shared IP reputation |
| SMTP | The plugin connects with a server address and login | Works with almost every service | Hosts may restrict SMTP ports, and you must store a password |
| API (HTTPS) | The plugin sends a request to the service API | Uses a key or token and avoids port problems | Needs a separate account and key for each service |
As a rule, pick the API if your sending service offers one, and pick SMTP if it does not. The plugin page notes that direct API integrations use tokens or keys instead of stored passwords. Still, whichever you choose, do not fall back to PHP mail().
How do you do the WP Mail SMTP setup step by step?
The setup takes about ten minutes in the admin panel. First, before you start, take a full backup of your site. For a backup plan, read our website backup strategy guide.
- Install the plugin: Go to Plugins, then Add New, search for "WP Mail SMTP", install it and activate it.
- Open the setup wizard: The plugin sends you to the Setup Wizard. If it does not, open Settings under the WP Mail SMTP menu.
- Choose the sending service: Pick a mailer that offers SMTP or an API, and follow your provider documentation.
- Enter the connection details: Paste the API key or the SMTP details into the matching fields and save.
- Set the From fields: Choose an address on your own domain. The next section explains why.
- Send a test email: Use the Email Test tab, send a message to yourself and inspect the headers.
However, tab names in the plugin can change between versions. If you see a different label on your screen, follow the current plugin documentation.
How do you set the From email and name correctly?
The From address is the field where people make the most mistakes in a WP Mail SMTP setup. The address must belong to the domain you authenticate. For example, if your site is example.com, use an address such as notifications@example.com. If you use a free mail address, you break alignment.
- Your sending service may ask you to verify the address or the domain, so sending can fail until you finish that step.
- First, keep the name simple. Your brand or site name is enough, because the recipient sees it in the inbox.
- Also set the reply address separately. When a customer answers, the message must reach a mailbox that someone reads.
- If the plugin offers a way to force the From address, consider it when other plugins add their own addresses.
That way, a form plugin and WooCommerce can differ in style, yet all messages still leave from the same domain. This consistency makes the alignment check much easier to pass.
Which fields do you fill in for a generic SMTP connection?
For the generic SMTP option, the plugin asks for five basic details. Do not guess these values. Every provider has its own server name and credentials, so use the values your hosting or sending provider gives you.
- SMTP host: The host name your provider gives you.
- Encryption: TLS or SSL, depending on what the provider documentation asks for.
- Port: A common pairing is port 587 with STARTTLS or port 465 with implicit TLS. In practice, the value in your provider documentation always wins.
- Authentication: Most services require a username and password.
- Username and password: Avoid your personal mailbox password. If possible, create a separate credential for this job. Then the leak of one key does not expose your mailbox.
If the connection fails, first ask your host whether it blocks outgoing SMTP ports. If it does, then switching to an API based sending service is the most practical fix.
How do API based sending services work in general?
With an API service, the plugin passes the message content to the service in an HTTPS request. The service then delivers the message from its own servers. So in this model you do not need an open SMTP port. Your site only needs to make outgoing HTTPS connections.
The setup flow differs from service to service, but the logic stays the same. You add your domain in the service account, the service gives you DNS records, you add and verify them, and you create an API key. After that, you paste the key into the plugin.
However, we do not promote any particular service. When you compare options, look at these points: whether the free quota fits your needs, whether a dashboard shows delivery status, whether the service supports domain verification and whether the documentation is clear. Prices and offers change often, so check the current terms on the service page.
Can you set up SMTP without a plugin using phpmailer_init?
Yes, you can. According to the official documentation, the phpmailer_init hook fires after PHPMailer is initialized and passes the object by reference. Also, the example below is a short adaptation of the pattern in that documentation. Replace the values with the details from your own provider.
add_action( 'phpmailer_init', 'example_smtp_settings' );
function example_smtp_settings( $phpmailer ) {
$phpmailer->isSMTP();
$phpmailer->Host = 'smtp.example.com';
$phpmailer->SMTPAuth = true;
$phpmailer->Port = 587;
$phpmailer->Username = 'your-username';
$phpmailer->Password = 'your-password-here';
}
The documentation also carries a warning. If you call setFrom(), set the third parameter to false. Otherwise you overwrite the Sender header, and receivers may reject your messages. Treat this code as an alternative to the plugin, and never run both together.
It is safer to put this code in a small separate plugin than in a theme file, because a theme change would remove your settings. Writing a password into code is also risky. In professional projects, keep credentials in a separate configuration.
How do you add SPF and DKIM records to DNS?
You add the records in the DNS management screen of your domain. Open the screen where you buy the domain or where you manage DNS. Your sending service gives you the exact record values, so never guess them.
- SPF: This is a TXT record, and a domain should have only one SPF record. RFC 7208 forbids multiple SPF records that would apply to the same domain.
- DKIM: You add the key name and value from your service as a TXT or CNAME record. The service decides the record type, so follow its instructions.
- DMARC: You add a TXT record under the _dmarc subdomain. You can start in monitoring mode with p=none.
example.com. TXT "v=spf1 include:spf.sending-service.example ~all"
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com"
However, these lines are examples only. Replace the include value with the one your service gives you. If you already have an SPF record, do not create a second one. Add the include term to the existing record.
Why does the 10 DNS lookup limit in SPF matter?
According to RFC 7208, an SPF evaluation may not exceed 10 DNS queries for the include, a, mx, ptr, exists and redirect terms. If you pass the limit, the result is a permerror, and the SPF check fails. Therefore, every new sending service you add raises that count.
So count the services that send mail from your domain. A business mailbox, a WordPress sending service, a newsletter tool and a CRM each add an include. Knowing which tool sends on your behalf is the only way to check the limit. If you are close, remove the records of services you no longer use.
To see whether a record is correct, use a DNS lookup. Our DNS lookup tool shows TXT records, while the checker we mentioned above summarizes the SPF, DKIM and DMARC results.
How do you send a test email and read the result?
On the Email Test tab, WP Mail SMTP sends a trial message to the address you choose. If it reaches your inbox, the connection works. However, the real check happens in the message headers, because a message can arrive even when authentication fails.
- First, send the test message to an account such as Gmail and open it.
- Then open the three dot menu and choose "Show original".
- Next, confirm that the SPF, DKIM and DMARC lines say PASS.
- Finally, check separately whether the message landed in the spam folder.
If all three say PASS, then the technical side is complete. If one says FAIL, fix that record and repeat the test. Also, after a DNS change, a short wait may be necessary.
Also, do not test with only one recipient. Send to two or three mailboxes at different providers, because each provider runs its own filters. Also make the subject and body look like a real notification, since an empty trial message can behave differently.
How do you log emails and debug failures?
When sending fails, you have two options. The first is the plugin log. According to the plugin page, detailed email logs, delivery status and resending belong to the Pro version, while the free version offers basic testing. The second option is to catch errors with your own code.
Since WordPress 4.4, the wp_mail_failed hook fires after PHPMailer catches an exception. It also passes a WP_Error object that carries data such as the recipient and the subject. The example below writes the error message to the PHP error log.
add_action( 'wp_mail_failed', 'example_mail_error' );
function example_mail_error( $error ) {
error_log( 'Mail error: ' . $error->get_error_message() );
}
Do not write the message body to a log. Password reset links and customer details are personal data, so saving the error message and the time is enough.
Why do WooCommerce order emails not arrive?
WooCommerce sends its emails with wp_mail(). So if the plugin settings are correct, order emails leave through the same route. The WooCommerce guide tells you to open WooCommerce, then Settings, then Emails, and to select the relevant template.
- Check that the sender address on the settings screen matches your domain.
- Then place a test order and see whether the matching email fires.
- If the message leaves but never arrives, you have a deliverability problem, so check your SPF, DKIM and DMARC records.
- If the message never leaves, make sure the template is enabled and look for errors in your wp_mail_failed log.
In ecommerce, the order confirmation is the first trust signal for a customer. For the wider picture, read our ecommerce website starter checklist. If you want help, our ecommerce consulting team is available.
Which settings matter for contact form notifications?
Contact form plugins send you a notification when a visitor submits a form. In practice, many sites put the visitor address in the From field. Your server, however, has no right to send mail in the name of that address, so the SPF or DMARC check fails.
In short, the right pattern is simple. The From address belongs to your domain, and the visitor address goes into the Reply To field. As a result, the message passes authentication, and when you press reply, your answer still goes to the visitor.
- Lock the sender field of the form plugin to an address on your own domain.
- Connect the visitor address to the Reply To field.
- Make sure the receiving mailbox is not full and does not filter the notice.
- Send a trial message every time you change a form.
In practice, this small change fixes a large share of "my forms do not work" complaints. The same logic applies to order and membership emails.
How do you avoid lost emails when your sending quota runs out?
Most sending services set a daily or monthly quota. For example, during a campaign week, order volume can rise and fill the quota. When that happens, messages arrive late or get rejected, and you may not notice.
To prepare, learn the quota terms from the service page. Figures change often, so we do not give numbers here. Then, before a campaign, estimate your expected order count and compare it with the quota.
- Prefer a service that warns you before the quota runs out.
- Place a test order before a big campaign and confirm that the message arrives.
- Keep critical messages such as order confirmations in a separate flow from campaign newsletters.
- Show an extra confirmation message on the order screen in case emails arrive late.
Here is a simple planning example, not a measurement. If your site normally sends a few dozen messages a day, assume that campaign day can bring several times that volume.
Should you separate transactional email from marketing email?
Yes, we recommend it. Order confirmations, password resets and form notices are transactional. Newsletters and promotions are marketing. According to the Google sender guidelines, bulk senders must support one click unsubscribe in marketing messages.
The same page asks you to keep the spam rate reported in Postmaster Tools below 0.3 percent, and it names 0.10 percent as the ideal target. If a campaign draws complaints, your order emails from the same domain suffer too. For that reason, teams often run the two flows on separate subdomains.
The design and content side of newsletters is outside this article. Still, if you wonder how AI can help with marketing emails, read our article on AI in email marketing.
What are the most common WP Mail SMTP setup mistakes?
The table collects the problems people see most often. It is a general summary, so you confirm the exact cause on each site by reading the headers and the log.
| Symptom | Likely cause | What you do |
|---|---|---|
| The test message never arrives | Wrong host, port or password | Compare the values with your provider documentation |
| The message arrives but lands in spam | SPF or DKIM is missing | Add the records and verify them with a checker |
| You see DMARC FAIL | The From domain is not aligned | Switch the From address to the verified domain |
| SPF returns a permerror | You passed 10 lookups or have two SPF records | Merge the records and delete unused ones |
| Only WooCommerce emails fail | The template is off or uses a different From address | Check the email settings and the template |
Two more mistakes are worth naming. The first is to activate several SMTP plugins at once. The second is to test right after a DNS change and give up. In the first case, plugins overwrite each other. In the second, the records may not have reached every DNS server yet.
What should you do for security and upkeep after the WP Mail SMTP setup?
However, the job does not end after setup. You need to protect the password and the key, keep the plugin current and test on a schedule. These steps look small, but they reduce the risk of leaks and silent failures.
- Share the API key and password only with authorized people, and never send them by chat or email.
- If you suspect a leak, revoke the key in the service dashboard and create a new one.
- Keep WordPress and plugins current. For the wider security picture, read our OWASP Top 10 guide.
- Send a test email once a month and confirm the PASS results in the headers.
- Recheck SPF and DKIM whenever you change the domain or the DNS provider.
Hosting also affects deliverability. We cover that topic in our guide to choosing web hosting.
When should you leave this to your hosting provider?
However, some jobs are outside your control. The outgoing mail queue of the server, the IP reputation, the reverse DNS (PTR) record and SMTP port restrictions all belong to the hosting provider. Google also expects the sending domain or IP to have valid forward and reverse DNS records.
- Write to your provider if the outgoing SMTP port is closed, if your IP is on a blocklist or if messages pile up in the server queue.
- If your provider manages your DNS, check whether you have permission to add records.
- Mailbox hosting and incoming mail are outside this article, so follow your provider documentation for them.
If you fear breaking something, take a screenshot of your current DNS records before you touch them. If you get stuck, contact our team. We can also settle infrastructure decisions together within our web design service.
Conclusion: in which order should you work?
Let us recap the order. First confirm that the problem really is deliverability, and then choose the sending method. After that, install the plugin, match the From address to your domain and add the DNS records. Finally, test, enable logging and set a regular check.
In short, WordPress email is more than a plugin setting. It is a shared job of hosting, DNS and authentication. If you think about all three together, then your order and form emails arrive safely. For legal or contractual email topics, also seek expert advice.



