WP Mail SMTP is one of the most used WordPress plugins for sending email. It replaces WordPress’s default mail function with a proper SMTP connection. Its Other SMTP mailer works with any SMTP server, so you can point it at SecureSMTP and get authenticated sending, an email log for every message, and automatic bounce handling, while keeping the plugin you already know.
Every email WordPress sends then goes through SecureSMTP: contact form notifications from Contact Form 7, WPForms, Gravity Forms or Elementor, WooCommerce order emails, password resets and new-user emails.
Before you start
- A SecureSMTP account with your website added as a site. The free plan includes 5,000 emails a month.
- Admin access to your WordPress site.
- The WP Mail SMTP plugin (the free version is enough).
1. Copy your SMTP password
In the SecureSMTP dashboard, open API keys. The SMTP settings box shows the host, ports and username. The password is the site’s API key, which starts with qcs_live_. Copy it; you paste it into WP Mail SMTP in step 3.
Treat the key like a password
2. Install WP Mail SMTP
- In WordPress, go to Plugins → Add New.
- Search for WP Mail SMTP, then click Install Now and Activate.
- WP Mail SMTP may open its setup wizard. You can choose Other SMTP there and enter the settings below, or close the wizard and use the settings page.
If the SecureSMTP plugin is also installed, deactivate it. Two plugins that both take over WordPress email get in each other’s way.
3. Enter the Other SMTP settings
Go to WP Mail SMTP → Settings → General, scroll to Mailer and choose Other SMTP. Fill in:
| Field | Value |
|---|---|
| SMTP Host | smtp.securessmtp.com |
| Encryption | TLS (or SSL, see below) |
| SMTP Port | 587 for TLS, 465 for SSL |
| Auto TLS | On |
| Authentication | On |
| SMTP Username | securessmtp |
| SMTP Password | Your site’s API key (qcs_live_…) |
TLS on port 587 is the usual choice. If your host blocks port 587, use SSL on port 465 instead. Always keep the encryption and the port together: TLS with 587, or SSL with 465.
Click Save Settings.
4. From Email and From Name
At the top of the same settings page:
- From Email: an address you read, on your own domain, such as
[email protected]. - From Name: your site or business name. This is the name recipients see.
- Turn on Force From Email and Force From Name so every plugin uses the same sender.
What recipients see depends on whether your domain is verified in SecureSMTP:
| Your SecureSMTP setup | Recipients see | Replies go to |
|---|---|---|
| No verified domain (free plan) | Your From Name, sent from SecureSMTP’s shared domain | Your From Email |
| Verified sending domain (Starter plan or higher) | Your From Name and your own address | Your From Email, or the form’s reply-to |
To send from your own address, add your domain in SecureSMTP and publish the DKIM record it gives you. See Domains and DNS.
5. Keep the key out of the database (optional)
WP Mail SMTP can read its settings from wp-config.php instead of the database, so the key is not stored in your WordPress database or shown on the settings page. Add these lines above /* That's all, stop editing! */:
define( 'WPMS_ON', true ); define( 'WPMS_MAILER', 'smtp' ); define( 'WPMS_SMTP_HOST', 'smtp.securessmtp.com' ); define( 'WPMS_SMTP_PORT', 587 ); define( 'WPMS_SSL', 'tls' ); define( 'WPMS_SMTP_AUTH', true ); define( 'WPMS_SMTP_AUTOTLS', true ); define( 'WPMS_SMTP_USER', 'securessmtp' ); define( 'WPMS_SMTP_PASS', 'qcs_live_your_key_here' );
WPMS_ON must be true for WP Mail SMTP to use these values. Settings set here are greyed out on the settings page.
6. Send a test email
- Go to WP Mail SMTP → Tools → Email Test, enter an address you can check and click Send Email.
- WP Mail SMTP should report that the test email was sent. Check the inbox (and the spam folder the first time).
- In the SecureSMTP dashboard, open the Email log. The test is listed with the source
smtp, and its status changes to delivered once the receiving server accepts it.
Then submit one of your site’s forms to check a real notification end to end.
Troubleshooting
“Could not authenticate” or SMTP error 535
- The password must be the whole API key, starting with
qcs_live_, with no spaces or line breaks. - If the key was rotated in SecureSMTP, the old one stopped working at once. Paste the new key.
- If the site is disabled in SecureSMTP, logins are refused. See Blocks.
“SMTP connect() failed” or the test times out
Many hosts block outgoing SMTP ports. Switch to SSL with port 465 (or TLS with 587 if you started with 465). If both are blocked, use the SecureSMTP WordPress plugin instead: it sends over HTTPS, which hosts do not block.
A TLS or certificate error
Check that the encryption matches the port: TLS with 587, SSL with 465, and that Auto TLS is on. The host name must be exactly smtp.securessmtp.com.
The test is sent but never arrives
Look the email up in the SecureSMTP email log. It shows whether it was delivered, bounced or held, and why. Also check that the address is not on your suppression list.
More error messages and fixes: WP Mail SMTP not working? Common errors and how to fix them.
Frequently asked questions
Does this work with the free version of WP Mail SMTP?+
Yes. The Other SMTP mailer is part of the free WP Mail SMTP plugin from WordPress.org. You do not need WP Mail SMTP Pro to send through SecureSMTP.
What do I put as the SMTP username and password?+
The username is securessmtp. The password is the API key of your site in SecureSMTP, which starts with qcs_live_. You find it in the dashboard under API keys, in the SMTP settings box. Each site has its own key.
Should I use TLS on port 587 or SSL on port 465?+
Either works. Use TLS with port 587 first. If your host blocks port 587, switch to SSL with port 465. Do not mix them: TLS with 465, or SSL with 587, fails with a timeout or a TLS error.
Why do recipients see a different From address?+
Until you verify your own sending domain, SecureSMTP sends from its shared, authenticated domain. Recipients see your From Name, and your From Email becomes the reply-to address, so replies still reach you. To send from your own address, verify a domain in SecureSMTP (Starter plan or higher).
Do I still need the SecureSMTP WordPress plugin?+
No. Use either WP Mail SMTP or the SecureSMTP plugin, not both. Our plugin is quicker to set up and sends over HTTPS, so it also works on hosts that block outgoing SMTP ports. WP Mail SMTP is a good choice if you already use it and want to keep its settings and logs.
Does it work with FluentSMTP or Post SMTP?+
Yes. Add an SMTP connection of the type Other SMTP and use the same values: host smtp.securessmtp.com, port 587 with TLS (or 465 with SSL), authentication on, username securessmtp and your API key as the password.
All SMTP settings in one place