Making WordPress send e-mail properly, with SMTP

The site’s form messages never arrive. Password recovery never arrives. Shop notifications never arrive. And there is no error at all: WordPress says it sent them.

The reason is nearly always the same. Out of the box, WordPress sends through PHP’s mail function, authenticating against no mailbox at all, often with an invented sender such as wordpress@asuaempresa.co.mz. The receiving side cannot confirm the message really was yours, so it files it as spam or refuses it.

The cure is simple and permanent: make WordPress sign in to a mailbox of yours and send from there, the way any mail program would. Now there is authentication, the sender is real, and the messages get accepted.

Step 1: the mailbox

You need a mailbox on your own domain, just for the site. If you do not have one yet, create it: how to create an e-mail account in cPanel.

1 Pick a name that makes sense, such as site@asuaempresa.co.mz or noreply@asuaempresa.co.mz.
2 Generate a long password and keep it: password generator.
3 If you want to read the replies, create it as a real mailbox. If not, forward it to the mailbox you actually use.

Step 2: the plugin and the settings

Install an SMTP plugin from the official repository. There are several good free ones. Pick one, and once it is configured do not install another: two plugins handling delivery give unpredictable results.

These are the settings for our server. Do not copy values from other providers’ guides:

Field Value
Outgoing server mail.asuaempresa.co.mz, with your own domain
Encryption SSL
Port 465
Authentication On
Username The full mailbox address, for example site@asuaempresa.co.mz. Not just the part before the at sign.
Password That mailbox’s password
From address Exactly the same address as the mailbox above
From name Your company name, which is what the recipient sees first
The From address has to be the mailbox that authenticates. This is the mistake that ruins everything else: the authentication is set correctly and the «From» field is left holding a free webmail address, or the address of the visitor who filled in the form. That domain does not authorise our server to send on its behalf, and the message lands in spam or is refused. The visitor’s address goes in Reply-To, never in From.

Most plugins let you keep the password in wp-config.php rather than in the database, using a constant of their own. It is cleaner: anyone who gets into the dashboard no longer sees it written in a field.

Step 3: test, and test properly

1 Use the plugin’s test message. If it fails, it nearly always says why: wrong password, incomplete username, or a closed port.
2 Send the test to an address outside your own domain. A message to yourself never leaves the server, so it proves nothing.
3 See where it landed: inbox or spam. If it went to spam, sending works and what is missing is the domain authentication: SPF, DKIM and DMARC.
4 Only then test what matters: the contact form, password recovery and, if you have a shop, a test order.

If it still fails

What you see What it is
Authentication refused Username or password. The username is the full address. If you are unsure of the password, change it in cPanel and use the new one.
Connection timed out Check port 465 and SSL encryption. If the plugin defaulted to TLS on 587, correct it to what the table above says.
It sends, but nothing arrives The message was accepted and refused further along. The route is why your e-mail is not sending or receiving.
It works and then stops You may have reached the plan’s hourly sending limit. The limits of each plan are on hosting plans.
All correct and the form is still silent The problem is not SMTP, it is the form: a contact form that actually reaches your inbox.
To READ the mail in that box, on a phone or in a mail program, the values are different: IMAP on port 993 with SSL, on the same mail.asuaempresa.co.mz. The step by step for each program is in the e-mail setup articles in this Knowledge Base.

Once it works

Sending is half the job; the other half is being accepted. Check the domain has SPF and DKIM, and that the sender is the same across everything the site sends: SPF, DKIM and DMARC and how to write an e-mail that does not land in spam.

Set it all up and the test fails? Send us the plugin’s error message.

Open a request

SEE ALSO

Professional e-mail

WordPress hosting

Support Policy

RECOMMENDED PRODUCT

WordPress hosting

One-click install, updates handled, and speed that holds up.

See plans
  • 0 Users Found This Useful
Was this answer helpful?