WordPress sends mail through PHP's built-in mail() function unless you tell it otherwise. That still works, in the sense that the message leaves the server – but it arrives poorly authenticated, and on a domain with a strict DMARC policy it can be quarantined or refused outright. Order confirmations, password resets and contact form notifications are exactly the messages you cannot afford to lose.
This article explains why it fails, which is worth two minutes because the reason is not obvious, and then what to do about it.
Every email has two "from" addresses
This is the part almost nobody knows, and everything else follows from it.
A message carries the From: address your reader sees, and separately an envelope sender used by mail servers to route it and to return failures. They are set independently, and receiving servers check the envelope, not the visible header.
When WordPress uses mail(), the envelope sender is whatever the hosting account defaults to – the cPanel username at the server's own hostname. So the two disagree:
Why SMTP is the fix
An SMTP plugin makes WordPress log in to a real mailbox and send the message exactly as Outlook or Apple Mail would. The envelope sender becomes that mailbox, on your own domain, and the two addresses agree.
What you gain, beyond authentication:
- The message is actually authenticated. SPF passes for the domain the reader sees, so DMARC is satisfied and the mail is treated as legitimate.
- Failures become visible. With mail() a rejected message usually disappears; a bounce goes to an address nobody reads. Sending through a mailbox means bounces arrive somewhere you can see them.
- A copy in Sent. You can confirm what the site sent, and when.
- Retries. If the receiving server is temporarily unavailable the message is queued and tried again, rather than lost.
- Better reputation. Authenticated mail from a consistent address builds a sending history. Unauthenticated mail from a server hostname does not.
- It keeps working when DNS changes. Alignment through SPF does not depend on a DKIM key staying in step with the server.
Setting it up
- Create a mailbox in cPanel on your own domain – Email Accounts → Create. Something like noreply@yourdomain or orders@yourdomain. Give it a strong password and keep it.
- Install an SMTP plugin. WP Mail SMTP, FluentSMTP and Post SMTP are all sound and all have free versions.
- Enter the settings. Choose the "Other SMTP" or "Custom" option rather than a third-party service, and use:
- Host: mail.yourdomain
- Port 587 with TLS, or port 465 with SSL
- Authentication on, with the full mailbox address as the username
- From address: the mailbox you just made. Tick the option to force it on all mail.
- Send the plugin's test email to an address at a different provider – Gmail or Outlook, not another mailbox on the same domain. Local delivery can succeed while external delivery fails, so testing to yourself proves very little.
Always send from your own domain
Contact form plugins often default to putting the visitor's address in From:, so the reply button works. That guarantees an authentication failure, because our server is not allowed to send as somebody else's domain, and it is a common reason contact forms quietly stop arriving.
Set From: to your own address and put the visitor's in Reply-To. Hitting reply still goes to them, and the message actually gets delivered.
If you use Google Workspace or Microsoft 365
If your mail is hosted elsewhere, the SMTP details are theirs, not ours – and their servers must be listed in your SPF record, or you have moved the problem rather than solved it. Google Workspace needs include:_spf.google.com, Microsoft 365 needs include:spf.protection.outlook.com. Both also offer their own DKIM signing, which is worth switching on. Open a ticket if you would like us to check the records.
If mail still does not arrive
- Check the spam folder first
- Confirm the plugin's test succeeded, and to an external address
- Check the mailbox is not over quota
- See SPF, DKIM and DMARC explained for what the three records do
- If the site sends in volume, that is a separate problem – bulk mail from shared hosting has its own limits
If you would rather we set this up for you, or you want us to check how a domain's mail is currently authenticated, open a ticket and we will look at it with you.