Description
WordPress sends password resets, order confirmations and form notifications with
whatever the server hands it. On most hosting that means unauthenticated mail
from an address the domain never authorised, which spam filters quietly discard.
Gmcfuerte SMTP Transport points the standard wp_mail() pipeline at an SMTP
account you control, so messages leave authenticated and signed by the provider
you already pay for.
It is deliberately small: one settings screen, one test button, no dashboard
widgets, no onboarding wizard.
What makes this one different
Most SMTP plugins stop at configuring PHPMailer. This one also protects the
failure path: if a migration, salt rotation or removed environment secret makes
the saved credential unusable, it stops rewriting the From address instead of
letting fallback mail impersonate the SMTP domain and fail SPF or DKIM. Its test
send reports the mail server’s real refusal and whether SMTP was actually used;
the password is write-only and may stay entirely outside the database. There is
no telemetry, provider account or remote dashboard.
What it does
- Routes
wp_mail()through your SMTP host, with STARTTLS, SSL/TLS, or no
encryption when a local relay needs it (and “none” really means none: the
automatic STARTTLS upgrade is switched off, instead of silently overriding
the choice you made). - Rewrites the From address and From name to match the authenticated account
— and only while that account is really carrying the message. If SMTP stops
working, the rewrite stops with it, because a rewritten From on mail sent by
something else is what makes SPF and DKIM fail. - Stores the SMTP password encrypted (AES-256-GCM) with a key derived from your
own site salts, so the value is useless in a database copied elsewhere. The
field is write-only: it never renders the stored password back to the browser. - Accepts a
GMCFUERTE_SMTP_PASSWORDconstant inwp-config.phpinstead, for
sites that keep credentials out of the database entirely. When it is defined,
the settings field says so and is ignored. - Sends a test email and tells you what really happened, including the reason
the mail server gave when it refused. If the message went out through the
server default transport rather than your SMTP account, it says that too,
instead of reporting a pass. - Refuses a half-finished configuration rather than saving one that silently
falls back to unauthenticated mail. - Refuses SMTP hosts that are IP literals, loopback names or internal-only
suffixes, so the mailer cannot be aimed at an internal service. - Caps admin-triggered test sends at five per minute per user.
External services
None. This plugin contacts no service of its own: not on activation, not on a
schedule, not ever. The only outbound connection it makes is to the SMTP host
you type into the settings screen, when WordPress sends a message.
Separate GMC catalogue edition
GMC SMTP Mailer, available free from fuerteventuratv.net, includes a mail log (per-recipient delivery
outcome, the real SMTP error, retention, resend, CSV export, a persistent
failure alert), the matching GDPR export/erase handlers and an admin REST API.
It has its own slug and GMC-hosted update channel. This plugin is complete without it, and nothing
here is disabled or time-limited.
Installation
- Install through Plugins -> Add New, or upload the
gmcfuerte-smtp-transport
folder to/wp-content/plugins/. - Activate it from the Plugins screen.
- Go to Settings -> SMTP Transport, enter the host, port, encryption, username
and password from your mail provider, and save. - Send a test email from the same screen and confirm it arrives.
FAQ
-
Where do I get the SMTP details?
-
From whoever runs the mailbox: your hosting control panel for a mailbox on your
own domain, or the SMTP credentials page of your transactional mail provider.
This plugin does not create accounts and has no provider of its own. -
The test says the message was sent, but with a warning. What does that mean?
-
It means WordPress accepted the message but your SMTP account was not used,
because the settings are incomplete. The mail went out through the server
default transport, which is exactly the situation this plugin exists to fix.
Fill in host, username and password, save, and test again. -
Is my password stored in plain text?
-
No. It is encrypted with AES-256-GCM before it is written, using a key derived
from this site own authentication salt. The field is write-only: it always
renders empty, and submitting it blank keeps the stored value. If you would
rather keep the secret out of the database entirely, define
GMCFUERTE_SMTP_PASSWORD inwp-config.php. -
Does it work with the block editor, WooCommerce, contact form plugins?
-
Yes. It configures the core
wp_mail()pipeline, so anything that sends mail
the WordPress way is covered without any integration. -
Does it log the messages it sends?
-
No. SMTP Transport keeps no record of your mail. The separate GMC SMTP Mailer
plugin provides logging and is available free from the GMC catalogue. -
I moved the site and mail stopped arriving. What happened?
-
The password is encrypted with a key derived from this site own salts, so
changing them — a migration, a clone, orwp config shuffle-salts— leaves a
stored value this install can no longer read. The settings screen says so, and
sending falls back to the server default transport with the From address left
alone. Type the SMTP password again and save. -
Will it conflict with another SMTP plugin?
-
Yes, in the sense that two plugins configuring the same mailer will fight over
it. Use one.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Gmcfuerte SMTP Transport” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Gmcfuerte SMTP Transport” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0.3
- Corrected the description of GMC SMTP Mailer: the separate catalogue plugin is free. SMTP Transport remains independent and complete. No mail transport behaviour changed.
1.0.2
- Fixed: the per-user test-send limit now uses an atomic database increment, so
concurrent admin requests cannot bypass the five-per-minute cap. - Clarified the plugin’s narrow focus: honest failure reporting, safe fallback
behavior and local credential handling without telemetry or a remote service.
1.0.1
- Fixed: the From address was rewritten even when the plugin was not actually
sending the mail. The two filters followed the on/off toggle rather than the
transport, so when SMTP stopped being usable — the site salts changed after a
migration or a clone, or theGMCFUERTE_SMTP_PASSWORDconstant was removed
fromwp-config.php— WordPress fell back to the server’s default transport
and still stamped your SMTP domain on the message. SPF and DKIM then fail and
the mail is filed as spam. The From address is now left alone unless SMTP is
really carrying the message. - Fixed: a stored password that can no longer be decrypted is now reported as
such. The settings screen used to say a password was stored and that leaving
the field empty would keep it, and saving that way was accepted — while
nothing could be sent. The screen now says the value is unusable, and the save
is refused with the reason. - Housekeeping: the absence of a
load_plugin_textdomain()call is now
documented in the source rather than merely absent. WordPress loads the
translations for a directory-hosted plugin itself, and the call has been
discouraged since WordPress 4.6.
1.0.0
- Initial release on WordPress.org.