Description
Postkeep sends your WordPress mail through Gmail without an app password: click Connect with Google, sign in, done. The one-click connection is a free service of allinonewpsettings.com (the makers of All-in-One WP Settings): the plugin links your site to a free account there, and that account holds the Google connection on your behalf and hands the plugin a short-lived sending token for each message. Your mail goes from your site to Google; the service never sees a message. One site per free account. The details of what is sent to the service are under “External services” below.
You do not need the service to use the plugin. Every other provider works with a plain SMTP login: Outlook.com and Microsoft 365 (with your own Azure app), Yahoo, Zoho, Yandex, SendGrid, Mailgun, Amazon SES, Brevo, SparkPost, Postmark, your host’s own mail server, or any host and port you type in. Gmail also works with an app password if you prefer not to link the site.
What you get
- One-click Gmail through the Gmail API, with the narrow send-only permission (
gmail.send), never the full mailbox. - Any SMTP server: presets for the common providers, or your own host, port and encryption.
- An email log: every message with its status, and the reason when one failed — which stage broke (name lookup, connection, encryption, sign-in, recipient, transfer) and what the server said, with credentials redacted.
- A retry queue: a message the server refused is queued and tried again hourly.
- A test tool that tells you where a failure happened instead of “could not send”.
- Passwords and tokens encrypted at rest with your site’s security keys.
- A copy-for-support summary on the Help tab: versions, the sending setup and the last failures, with no secret in it, ready to paste into a forum post.
- Every string ready for translation, and German and Turkish already written: they are being imported to translate.wordpress.org, which is where WordPress.org builds and delivers language packs from. Until that import is through, the plugin reads in English.
Postkeep and All-in-One WP Settings
This plugin is the SMTP module of All-in-One WP Settings, offered on its own for free. If you later install the suite, it reads the same settings, log and queue, and this plugin steps aside on its own; you can then deactivate it. Nothing is lost either way.
External services
The one-click Gmail connection uses a service at https://allinonewpsettings.com, operated by the makers of All-in-One WP Settings. It is used only when you click “Connect with Google”; if you never click it, the plugin contacts no external service.
What is sent, and when
- When you click “Connect with Google” on a site that is not yet linked: the site’s URL, a random install identifier, the plugin, WordPress and PHP versions and the site’s language, to obtain a sign-in link. Your browser then opens that link and you sign in to, or register with, allinonewpsettings.com. The plugin then exchanges a one-time code for a licence key and an activation token, which it stores encrypted.
- When the Google sign-in starts: the licence key, activation id and site URL, and the plugin’s capabilities, to obtain the Google consent page. Google’s own consent screen then asks you for permission to send mail as you.
- Every time a message is sent through the connection: the licence key, activation id and site URL, to obtain a short-lived Google access token. The message itself is sent from your site directly to Google’s Gmail API and never passes through the service.
- Once a day: the licence key, activation id and site URL, to confirm the licence is still valid.
- When you click Disconnect: the same identifiers, so the service revokes the Google connection. When you delete the plugin: the same, so your site leaves the free licence.
The service stores your account e-mail address, the site URL, the install identifier and the Google connection (a refresh token and the connected Gmail address). It never receives a message, a recipient or your Gmail password.
Terms of service: https://allinonewpsettings.com/terms-of-service
Privacy policy: https://allinonewpsettings.com/privacy-policy
The mail providers themselves
Sending mail means talking to the provider you chose, with your own account. Those requests go from your site straight to the provider; nothing here passes through allinonewpsettings.com. They happen only for the provider you have configured, and only when your site sends mail or when you connect an account.
- Google — sending. When Gmail is your provider and the account is connected (through the one-click connection above, or through your own Google app), each message is posted to the Gmail API at https://gmail.googleapis.com —
/gmail/v1/users/me/messages/send, or/upload/gmail/v1/users/me/messages/sendwhen the message with its attachments is larger than 4 MB. What is sent is the message itself: your sender name and address, the recipients, the subject, the body and any attachments, with the access token for your account. Google’s terms: https://policies.google.com/terms — Google’s privacy policy: https://policies.google.com/privacy - Google — signing in with your own app. If you enter your own Google Client ID and Secret instead of using the one-click connection, your browser is sent to https://accounts.google.com to approve it, and the plugin then exchanges the result for tokens at https://oauth2.googleapis.com/token, and refreshes them there. What is sent: your Client ID, your Client Secret and the code or refresh token. Same terms and privacy policy as above.
- Microsoft — sending and signing in. With Outlook.com or Microsoft 365 and your own Azure app, your browser is sent to https://login.microsoftonline.com to approve it; the plugin exchanges and refreshes tokens at the same host, reads the mailbox address once from https://graph.microsoft.com/v1.0/me, and posts each message to https://graph.microsoft.com/v1.0/me/sendMail — what is sent: your Client ID and Secret at sign-in, and afterwards the message — sender, recipients, subject, body and attachments. Microsoft Services Agreement: https://www.microsoft.com/en-us/servicesagreement — Microsoft privacy statement: https://www.microsoft.com/en-us/privacy/privacystatement
- Yahoo — signing in. With Yahoo Mail and OAuth2, your browser is sent to https://api.login.yahoo.com to approve your own app, and tokens are exchanged and refreshed at the same host; the mail itself then goes over SMTP to Yahoo’s mail server. What is sent: your Client ID, your Client Secret and the code or refresh token. Yahoo’s terms: https://legal.yahoo.com/us/en/yahoo/terms/otos/index.html — Yahoo’s privacy policy: https://legal.yahoo.com/us/en/yahoo/privacy/index.html
Every other provider — SendGrid, Mailgun, Amazon SES, Brevo, SparkPost, Postmark, Zoho, Yandex, your host’s own mail server, or any host you type in — is reached over plain SMTP at the address you enter, with the credentials you enter, and nowhere else.
The provider list on the settings screen
The settings screen offers thirteen providers to pick from, and each one is a saved set of starting values for the form: a port, an encryption setting, a link to that provider’s own setup documentation — for example https://developers.sparkpost.com/api/smtp/ for SparkPost — and, for the named services, their mail server, such as email-smtp.us-east-1.amazonaws.com for Amazon SES or smtp.sendgrid.net for SendGrid. (“Shared Hosting” fills in mail. and your own domain; “Custom SMTP Server” fills in nothing and waits for you.) Picking a provider fills the form in for you; nothing is contacted when you pick one, and the documentation link only opens in your browser if you click it. The plugin sends mail to the server in the form after you have saved it, with the credentials you entered, and it contacts no other address. So the provider names and hostnames in the plugin’s code are a list of choices available to you, not services this plugin talks to: a site that never picks Amazon SES never reaches Amazon, and the same for every other name on the list.
One more address appears in the plugin’s code and is not a service it contacts: https://api.wordpress.org/secret-key/1.1/salt/ is named in an admin message that tells you where to generate WordPress’s security keys when your wp-config.php has none. It is text in a warning on your own screen; the plugin makes no request to it.
Installation
- Upload the plugin to
/wp-content/plugins/postkeep/, or install it from the Plugins screen. - Activate it. A new menu entry, Postkeep, appears.
- On the Configuration tab, choose a provider. For Gmail, click “Connect with Google” and follow the sign-in; for any other provider, enter the host and login details.
- Turn the SMTP switch on and save.
- Send yourself a message from the Test Email tab.
FAQ
-
Do I need an account for Postkeep to work?
-
Only for the one-click Gmail connection. Every other provider, and Gmail with an app password, works with no account and contacts no service.
-
What does the free account allow?
-
One site connected to Gmail through the service. Connecting a second site from the same account moves the connection to it; the service’s page says so before it does.
-
Which Google permission does the plugin ask for?
-
Send-only (
https://www.googleapis.com/auth/gmail.send). The plugin cannot read, search or delete your mail. -
Microsoft requires OAuth2 and does not allow a shared application for it on the free plan. Choose OAuth2 on the Outlook card and enter the Client ID and Client Secret of an app registered in your own Azure portal; the plugin walks you through it. One-click Microsoft sign-in is part of All-in-One WP Settings.
-
The connection says “not open yet”. What now?
-
The free Gmail connection opens once the plugin is listed and the service has Google’s approval for the send-only permission. Until then, Gmail works with an app password: choose Gmail, enter the address and the app password, save.
-
Where are my passwords stored?
-
In your site’s database, encrypted with your site’s security keys (AES-256-GCM). A backup or export of the database does not contain them in the clear. If the security keys are ever changed, the plugin tells you which credential to enter again.
One exception, and the plugin says so on its own page when it applies: the encryption needs PHP’s openssl extension, which nearly every host has. Without it a password is only encoded, not encrypted, and the Configuration tab shows a warning asking you to have openssl enabled.
-
Can I set the SMTP password in wp-config.php instead?
-
Yes:
define( 'POSTKEEP_SMTP_PASSWORD', 'your password' );takes precedence over the saved one, and the settings page says so. -
Where do I get help?
-
In the plugin’s support forum on WordPress.org. The Help tab has a summary of your setup to paste into your post, with every secret left out.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Postkeep – One Click SMTP Setup and Email Log” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Postkeep – One Click SMTP Setup and Email Log” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0.1
- Fixed a fatal error on activation on WordPress 6.8 and older. Those versions ship PHPMailer without its OAuthTokenProvider interface, and the plugin required that file outright. It is now loaded only when WordPress has it, and declared by the plugin when WordPress does not. Nothing else changed.
1.0.0
- First release: the SMTP module of All-in-One WP Settings on its own, with the free one-click Gmail connection.