Gmcfuerte SMTP Transport

Description

WordPress sends password resets, order confirmations and form notifications with
whatever the server hands it. On most hosting that means unauthenticated mail
from an address the domain never authorised, which spam filters quietly discard.

Gmcfuerte SMTP Transport points the standard wp_mail() pipeline at an SMTP
account you control, so messages leave authenticated and signed by the provider
you already pay for.

It is deliberately small: one settings screen, one test button, no dashboard
widgets, no onboarding wizard.

What makes this one different

Most SMTP plugins stop at configuring PHPMailer. This one also protects the
failure path: if a migration, salt rotation or removed environment secret makes
the saved credential unusable, it stops rewriting the From address instead of
letting fallback mail impersonate the SMTP domain and fail SPF or DKIM. Its test
send reports the mail server’s real refusal and whether SMTP was actually used;
the password is write-only and may stay entirely outside the database. There is
no telemetry, provider account or remote dashboard.

What it does

  • Routes wp_mail() through your SMTP host, with STARTTLS, SSL/TLS, or no
    encryption when a local relay needs it (and “none” really means none: the
    automatic STARTTLS upgrade is switched off, instead of silently overriding
    the choice you made).
  • Rewrites the From address and From name to match the authenticated account
    — and only while that account is really carrying the message. If SMTP stops
    working, the rewrite stops with it, because a rewritten From on mail sent by
    something else is what makes SPF and DKIM fail.
  • Stores the SMTP password encrypted (AES-256-GCM) with a key derived from your
    own site salts, so the value is useless in a database copied elsewhere. The
    field is write-only: it never renders the stored password back to the browser.
  • Accepts a GMCFUERTE_SMTP_PASSWORD constant in wp-config.php instead, for
    sites that keep credentials out of the database entirely. When it is defined,
    the settings field says so and is ignored.
  • Sends a test email and tells you what really happened, including the reason
    the mail server gave when it refused. If the message went out through the
    server default transport rather than your SMTP account, it says that too,
    instead of reporting a pass.
  • Refuses a half-finished configuration rather than saving one that silently
    falls back to unauthenticated mail.
  • Refuses SMTP hosts that are IP literals, loopback names or internal-only
    suffixes, so the mailer cannot be aimed at an internal service.
  • Caps admin-triggered test sends at five per minute per user.

External services

None. This plugin contacts no service of its own: not on activation, not on a
schedule, not ever. The only outbound connection it makes is to the SMTP host
you type into the settings screen, when WordPress sends a message.

Separate GMC catalogue edition

GMC SMTP Mailer, available free from fuerteventuratv.net, includes a mail log (per-recipient delivery
outcome, the real SMTP error, retention, resend, CSV export, a persistent
failure alert), the matching GDPR export/erase handlers and an admin REST API.
It has its own slug and GMC-hosted update channel. This plugin is complete without it, and nothing
here is disabled or time-limited.

Installation

  1. Install through Plugins -> Add New, or upload the gmcfuerte-smtp-transport
    folder to /wp-content/plugins/.
  2. Activate it from the Plugins screen.
  3. Go to Settings -> SMTP Transport, enter the host, port, encryption, username
    and password from your mail provider, and save.
  4. Send a test email from the same screen and confirm it arrives.

FAQ

Where do I get the SMTP details?

From whoever runs the mailbox: your hosting control panel for a mailbox on your
own domain, or the SMTP credentials page of your transactional mail provider.
This plugin does not create accounts and has no provider of its own.

The test says the message was sent, but with a warning. What does that mean?

It means WordPress accepted the message but your SMTP account was not used,
because the settings are incomplete. The mail went out through the server
default transport, which is exactly the situation this plugin exists to fix.
Fill in host, username and password, save, and test again.

Is my password stored in plain text?

No. It is encrypted with AES-256-GCM before it is written, using a key derived
from this site own authentication salt. The field is write-only: it always
renders empty, and submitting it blank keeps the stored value. If you would
rather keep the secret out of the database entirely, define
GMCFUERTE_SMTP_PASSWORD in wp-config.php.

Does it work with the block editor, WooCommerce, contact form plugins?

Yes. It configures the core wp_mail() pipeline, so anything that sends mail
the WordPress way is covered without any integration.

Does it log the messages it sends?

No. SMTP Transport keeps no record of your mail. The separate GMC SMTP Mailer
plugin provides logging and is available free from the GMC catalogue.

I moved the site and mail stopped arriving. What happened?

The password is encrypted with a key derived from this site own salts, so
changing them — a migration, a clone, or wp config shuffle-salts — leaves a
stored value this install can no longer read. The settings screen says so, and
sending falls back to the server default transport with the From address left
alone. Type the SMTP password again and save.

Will it conflict with another SMTP plugin?

Yes, in the sense that two plugins configuring the same mailer will fight over
it. Use one.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Gmcfuerte SMTP Transport” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.0.3

  • Corrected the description of GMC SMTP Mailer: the separate catalogue plugin is free. SMTP Transport remains independent and complete. No mail transport behaviour changed.

1.0.2

  • Fixed: the per-user test-send limit now uses an atomic database increment, so
    concurrent admin requests cannot bypass the five-per-minute cap.
  • Clarified the plugin’s narrow focus: honest failure reporting, safe fallback
    behavior and local credential handling without telemetry or a remote service.

1.0.1

  • Fixed: the From address was rewritten even when the plugin was not actually
    sending the mail. The two filters followed the on/off toggle rather than the
    transport, so when SMTP stopped being usable — the site salts changed after a
    migration or a clone, or the GMCFUERTE_SMTP_PASSWORD constant was removed
    from wp-config.php — WordPress fell back to the server’s default transport
    and still stamped your SMTP domain on the message. SPF and DKIM then fail and
    the mail is filed as spam. The From address is now left alone unless SMTP is
    really carrying the message.
  • Fixed: a stored password that can no longer be decrypted is now reported as
    such. The settings screen used to say a password was stored and that leaving
    the field empty would keep it, and saving that way was accepted — while
    nothing could be sent. The screen now says the value is unusable, and the save
    is refused with the reason.
  • Housekeeping: the absence of a load_plugin_textdomain() call is now
    documented in the source rather than merely absent. WordPress loads the
    translations for a directory-hosted plugin itself, and the call has been
    discouraged since WordPress 4.6.

1.0.0

  • Initial release on WordPress.org.