INTEGRATIONS · Published 2026-10-06 · Updated 2026-10-06 · SecureSMTP

WordPress plugin

Install the plugin, paste your key, and every wp_mail() email goes through SecureSMTP.

The Technologia SecureSMTP plugin sends every email your WordPress site sends — WooCommerce receipts, password resets, form notifications — through SecureSMTP. It also embeds forms you build in the SecureSMTP dashboard. The current version is 1.23.0. It needs WordPress 6.0 or later and PHP 8.0 or later.

Install

  1. Download the plugin zip from securessmtp.com/download.
  2. In wp-admin open Plugins → Add New Plugin → Upload Plugin, choose the zip, click Install Now, then Activate.
  3. A SecureSMTP menu appears with: All Forms, Add New, Submissions, Blocks, Mail Log, SMTP, Spam Protection and Settings.

Add your API key

  1. In the SecureSMTP dashboard, add the site under Sites (/app/forms/sites) and copy its API key. It starts with qcs_live_. See Sites and API keys.
  2. In wp-admin open SecureSMTP → Settings, paste the key into API Key.
  3. Click Save and test connection. You should see “Connection OK — site is verified.”

Turn on Email Delivery

Adding the key alone does not change how WordPress sends email. To route it through SecureSMTP:

  1. On SecureSMTP → Settings, under Email Delivery, tick Route outgoing email through SecureSMTP. The same switch is on the SecureSMTP → SMTP page.
  2. Choose the sender (below) and click Save.

While Email Delivery is off, the plugin still records every email in the Mail Log, but WordPress sends it with its own mailer.

Sender mode

OptionWhat happens
Use SecureSMTP as the senderRelay mode, the default. No DNS changes. Email goes out from [email protected] with your From name. The original From address becomes the Reply-To (unless the email already has one), so replies still reach the right person.
Send from my own domainDomain mode. Email goes out from the address on your verified sending domain. Until the domain is verified, email is sent in relay mode, so nothing is delayed. Add and verify the domain in the dashboard (/app/forms/email) — see Domains and DNS — then click Check domain status in the plugin.

If the email has no From name, the plugin uses the site title. Relay-mode emails count toward the monthly email limit; emails sent from a verified domain do not. See Plans and limits.

Test buttons

ButtonWhat it does
Save and test connectionChecks that the key works and the site is verified.
Save and send test emailSends one email straight through the API to your own user email. Works even while Email Delivery is off, so you can check delivery before switching it on.
Check domain statusFetches the status of your sending domain from SecureSMTP.
Send a real wp_mail() testSends a real wp_mail() to the site’s admin email through the full WordPress pipeline, including other plugins that hook into mail. The result says whether it went through SecureSMTP, was taken by another plugin, or fell back. Needs Email Delivery on.

What gets sent through SecureSMTP

  • Every wp_mail() call. The plugin hooks pre_wp_mail (priority 1), so core emails, WooCommerce and most form plugins (Contact Form 7, WPForms, Elementor and others) are covered.
  • Plugins that use PHPMailer directly. Some plugins, such as Gravity Forms, build their own PHPMailer message and skip wp_mail(). The plugin catches these through phpmailer_init.
  • What is passed on: To, Cc, Bcc, Reply-To, the From name, HTML or plain text (from the Content-Type, as WordPress decides it), X- headers and List-Unsubscribe headers.
  • Attachments are sent through SecureSMTP since version 1.23.0, up to 15 MB in total. If the files are larger or cannot be read, WordPress’s own mailer sends that email instead.

When WordPress’s own mailer sends instead

The plugin only takes over an email when SecureSMTP confirms it was accepted. In every other case it hands the email back to WordPress, which sends it the way it did before the plugin was installed. This is on purpose: an email is never dropped because of the plugin. It happens when:

  • Email Delivery is off, or no API key is saved.
  • Attachments are over 15 MB in total or a file cannot be read.
  • No valid recipient address could be read.
  • SecureSMTP cannot be reached or does not answer in time.
  • The API refuses the email: rate limit (rate_limited), monthly limit (over_quota), send failure or any other error.

An email sent by WordPress’s own mailer does not get SecureSMTP’s checks, tracking or entry in the dashboard email log. If many emails fall back, find out why in the Mail Log.

A contact-form notification that SecureSMTP judges to be spam is held: the API accepts it (so WordPress does not send it either) and it shows as flagged in the dashboard email log. See Spam protection.

Mail Log

SecureSMTP → Mail Log lists every wp_mail() call on the site, with time, source plugin, recipient, subject, status and what the plugin did with it. It keeps the latest 5,000 entries.

Note in the logMeaning
Routed via SecureSMTPSent through SecureSMTP.
Routed (PHPMailer)Sent through SecureSMTP, caught on the direct PHPMailer path.
Skipped: relay offEmail Delivery is off. WordPress sent it.
Skipped: no API keyNo key saved. WordPress sent it.
Skipped: has attachmentsThe attachments were over 15 MB in total or could not be read. WordPress sent it.
Fell back: API errorSecureSMTP refused the email or could not be reached. WordPress sent it.
Claimed by another pluginAnother plugin handled the email first.

What happened after SecureSMTP accepted an email — delivered, bounced, opened — is in the dashboard email log (/app/forms/email-log).

Other SMTP plugins

Only one plugin can send a site’s email. If any of these is active while Email Delivery is on, the plugin shows a warning on its Settings and SMTP pages: WP Mail SMTP, Post SMTP, FluentSMTP, Easy WP SMTP, SMTP Mailer, WP SMTP, Brevo (formerly Sendinblue) and SendGrid. Deactivate the other plugin under Plugins → Installed Plugins. If you keep it, emails it takes first show in the Mail Log as “Claimed by another plugin”.

Hosted forms

Build a form in the dashboard (/app/forms/builder) and put it on any page or post with its slug:

Shortcode
[securessmtp_form slug="contact"]

The plugin caches the form for 5 minutes, so changes made in the dashboard can take up to 5 minutes to show. Forms built in WordPress under SecureSMTP → Add New use [securessmtp_form id="123"]. Captcha settings are under SecureSMTP → Spam Protection. See Hosted forms.

Update the plugin

The plugin does not update itself. To update, download the new zip from securessmtp.com/download, upload it under Plugins → Add New Plugin → Upload Plugin and click Replace current with uploaded. Your key and settings are kept.

Staging: change the API address

The plugin sends to https://securessmtp.com/api/v1. To point it somewhere else, for example a staging server, add this to wp-config.php above the line /* That’s all, stop editing! */:

wp-config.php
define( 'SECURESSMTP_API_BASE', 'https://staging.example.com/api/v1' );

The address in use is shown on the Settings page under Endpoint. Leave this out on a live site.

Next