WordPress cannot send email reliably: use SMTP, not PHP mail()

WordPress sends mail through PHP's built-in mail() function unless you tell it otherwise. That still works, in the sense that the message leaves the server – but it arrives poorly authenticated, and on a domain with a strict DMARC policy it can be quarantined or refused outright. Order confirmations, password resets and contact form notifications are exactly the messages you cannot afford to lose.

This article explains why it fails, which is worth two minutes because the reason is not obvious, and then what to do about it.

Every email has two "from" addresses

This is the part almost nobody knows, and everything else follows from it.

A message carries the From: address your reader sees, and separately an envelope sender used by mail servers to route it and to return failures. They are set independently, and receiving servers check the envelope, not the visible header.

When WordPress uses mail(), the envelope sender is whatever the hosting account defaults to – the cPanel username at the server's own hostname. So the two disagree:

PHP mail() — fails alignment From: [email protected] Envelope: [email protected] The two domains differ, so the SPF check passes for the wrong domain. DMARC counts that as a failure. SMTP — aligns From: [email protected] Envelope: [email protected] Both are your domain. SPF passes for the domain the reader actually sees, which is what DMARC requires. What the receiving server decides Policy p=none delivered, but recorded as a failure Policy p=quarantine sent to the spam folder Policy p=reject refused — the message never arrives A correct DKIM signature can rescue a misaligned envelope. Do not rely on it: it is one DNS record away from silently not working, and then nothing is left.

Why SMTP is the fix

An SMTP plugin makes WordPress log in to a real mailbox and send the message exactly as Outlook or Apple Mail would. The envelope sender becomes that mailbox, on your own domain, and the two addresses agree.

What you gain, beyond authentication:

  • The message is actually authenticated. SPF passes for the domain the reader sees, so DMARC is satisfied and the mail is treated as legitimate.
  • Failures become visible. With mail() a rejected message usually disappears; a bounce goes to an address nobody reads. Sending through a mailbox means bounces arrive somewhere you can see them.
  • A copy in Sent. You can confirm what the site sent, and when.
  • Retries. If the receiving server is temporarily unavailable the message is queued and tried again, rather than lost.
  • Better reputation. Authenticated mail from a consistent address builds a sending history. Unauthenticated mail from a server hostname does not.
  • It keeps working when DNS changes. Alignment through SPF does not depend on a DKIM key staying in step with the server.

Setting it up

  1. Create a mailbox in cPanel on your own domain – Email Accounts → Create. Something like noreply@yourdomain or orders@yourdomain. Give it a strong password and keep it.
  2. Install an SMTP plugin. WP Mail SMTP, FluentSMTP and Post SMTP are all sound and all have free versions.
  3. Enter the settings. Choose the "Other SMTP" or "Custom" option rather than a third-party service, and use:
    • Host: mail.yourdomain
    • Port 587 with TLS, or port 465 with SSL
    • Authentication on, with the full mailbox address as the username
    • From address: the mailbox you just made. Tick the option to force it on all mail.
  4. Send the plugin's test email to an address at a different provider – Gmail or Outlook, not another mailbox on the same domain. Local delivery can succeed while external delivery fails, so testing to yourself proves very little.

Always send from your own domain

Contact form plugins often default to putting the visitor's address in From:, so the reply button works. That guarantees an authentication failure, because our server is not allowed to send as somebody else's domain, and it is a common reason contact forms quietly stop arriving.

Set From: to your own address and put the visitor's in Reply-To. Hitting reply still goes to them, and the message actually gets delivered.

If you use Google Workspace or Microsoft 365

If your mail is hosted elsewhere, the SMTP details are theirs, not ours – and their servers must be listed in your SPF record, or you have moved the problem rather than solved it. Google Workspace needs include:_spf.google.com, Microsoft 365 needs include:spf.protection.outlook.com. Both also offer their own DKIM signing, which is worth switching on. Open a ticket if you would like us to check the records.

If mail still does not arrive

  • Check the spam folder first
  • Confirm the plugin's test succeeded, and to an external address
  • Check the mailbox is not over quota
  • See SPF, DKIM and DMARC explained for what the three records do
  • If the site sends in volume, that is a separate problem – bulk mail from shared hosting has its own limits

If you would rather we set this up for you, or you want us to check how a domain's mail is currently authenticated, open a ticket and we will look at it with you.

  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

Why email still bounces for a while after a domain is renewed

Your domain has been renewed, the website is back, but messages to some of your addresses still...

How do I add / configure an email address through cPanel

Steps Set the following in the "Add a New Email Account" section: E-mail - Enter...

How do I delete an email address

WARNING: If you delete an email account, the system automatically deletes all email...

How to cut down on spam email

We are always trying to stay one step ahead of the spammers by implementing measures on the...

Check Email Using Webmail

Webmail is a way of accessing your mailbox using a browser which therefore means that you can...