{"id":336935,"date":"2026-07-21T16:07:19","date_gmt":"2026-07-21T16:07:19","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/dixonsmtp-for-outlook-microsoft-365\/"},"modified":"2026-07-21T16:06:46","modified_gmt":"2026-07-21T16:06:46","slug":"dixonsmtp-for-outlook-microsoft-365","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/dixonsmtp-for-outlook-microsoft-365\/","author":23527481,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.0.2","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"DixonSMTP for Outlook & Microsoft 365","header_author":"Dixon Cherian","header_description":"Send WordPress emails reliably via Outlook.com \/ Microsoft 365 SMTP with OAuth 2.0. Includes email logging, test email tool, and automatic token refresh.","assets_banners_color":"0c5da3","last_updated":"2026-07-21 16:06:46","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/electronikmedia.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":48,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"dixonem","date":"2026-07-21 16:06:46"}},"upgrade_notice":{"1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3617422,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3617422,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3617422,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3617422,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3617422,"resolution":"1","location":"assets","locale":"","width":1300,"height":666},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3617422,"resolution":"2","location":"assets","locale":"","width":1285,"height":642},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3617422,"resolution":"3","location":"assets","locale":"","width":1289,"height":905},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3617422,"resolution":"4","location":"assets","locale":"","width":1283,"height":383}},"screenshots":{"1":"General tab \u2014 enable mailer, From Email\/Name with force override.","2":"OAuth 2.0 tab \u2014 Azure credentials, redirect URI with copy button, connection status and authorize button.","3":"Test Email tab \u2014 one-click test with full SMTP debug transcript.","4":"Email Log tab \u2014 recent sends with status badges and error details."}},"plugin_section":[],"plugin_tags":[267,186633,2061,36368,6696],"plugin_category":[38,41],"plugin_contributors":[272670],"plugin_business_model":[],"class_list":["post-336935","plugin","type-plugin","status-publish","hentry","plugin_tags-email","plugin_tags-microsoft-365","plugin_tags-oauth","plugin_tags-outlook","plugin_tags-smtp","plugin_category-authentication","plugin_category-communication","plugin_contributors-dixonem","plugin_committers-dixonem"],"banners":{"banner":"https:\/\/ps.w.org\/dixonsmtp-for-outlook-microsoft-365\/assets\/banner-772x250.png?rev=3617422","banner_2x":"https:\/\/ps.w.org\/dixonsmtp-for-outlook-microsoft-365\/assets\/banner-1544x500.png?rev=3617422","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/dixonsmtp-for-outlook-microsoft-365\/assets\/icon-128x128.png?rev=3617422","icon_2x":"https:\/\/ps.w.org\/dixonsmtp-for-outlook-microsoft-365\/assets\/icon-256x256.png?rev=3617422","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/dixonsmtp-for-outlook-microsoft-365\/assets\/screenshot-1.png?rev=3617422","caption":"General tab \u2014 enable mailer, From Email\/Name with force override."},{"src":"https:\/\/ps.w.org\/dixonsmtp-for-outlook-microsoft-365\/assets\/screenshot-2.png?rev=3617422","caption":"OAuth 2.0 tab \u2014 Azure credentials, redirect URI with copy button, connection status and authorize button."},{"src":"https:\/\/ps.w.org\/dixonsmtp-for-outlook-microsoft-365\/assets\/screenshot-3.png?rev=3617422","caption":"Test Email tab \u2014 one-click test with full SMTP debug transcript."},{"src":"https:\/\/ps.w.org\/dixonsmtp-for-outlook-microsoft-365\/assets\/screenshot-4.png?rev=3617422","caption":"Email Log tab \u2014 recent sends with status badges and error details."}],"raw_content":"<!--section=description-->\n<p>WordPress' default PHP mail() delivery is frequently blocked or spam-foldered. <strong>DixonSMTP for Outlook &amp; Microsoft 365<\/strong> routes every email your site sends (core, WooCommerce, WPForms, Contact Form 7, Gravity Forms, and anything else using <code>wp_mail()<\/code>) through Microsoft's SMTP servers \u2014 authenticated, encrypted, and deliverable.<\/p>\n\n<p><strong>100% free.<\/strong> No premium upsell, no paid tiers, no feature gating.<\/p>\n\n<h4>Why OAuth 2.0?<\/h4>\n\n<p>Microsoft has <strong>deprecated Basic Authentication<\/strong> for Exchange Online and is progressively disabling password-based SMTP AUTH (new Microsoft 365 tenants have it off by default). OAuth 2.0 (\"Modern Authentication\") is the supported, secure path forward \u2014 which is why this plugin is <strong>OAuth-only<\/strong> by design. It implements the full Microsoft identity platform authorization code flow with automatic token refresh, so you sign in once and it keeps working.<\/p>\n\n<h4>Features<\/h4>\n\n<ul>\n<li><strong>OAuth 2.0 (Modern Auth)<\/strong> for Microsoft 365 \/ Entra ID \u2014 authorization code flow, automatic access-token refresh, encrypted token storage<\/li>\n<li>From Email \/ From Name with optional force-override (recommended \u2014 Microsoft rejects mismatched senders)<\/li>\n<li><strong>Test email tool<\/strong> with a full SMTP debug transcript<\/li>\n<li><strong>Email log<\/strong> (last 10\u2013500 emails, configurable) with status and error details in a custom table<\/li>\n<li>Optional <strong>fallback to the default PHP mailer<\/strong> when SMTP fails<\/li>\n<li><strong>Failure notifications<\/strong> to the site admin after repeated errors (rate-limited)<\/li>\n<li>Debug mode compatible with <code>WP_DEBUG_LOG<\/code><\/li>\n<li>Multisite compatible (network activation supported; settings are per-site)<\/li>\n<li>Secrets (client secret, OAuth tokens) stored <strong>encrypted<\/strong> (AES-256 keyed from your WordPress salts)<\/li>\n<li>Translation-ready, fully sanitized\/escaped, capability + nonce protected<\/li>\n<\/ul>\n\n<h4>Compatibility<\/h4>\n\n<p>Works with any plugin that sends mail through <code>wp_mail()<\/code>: WPForms, Contact Form 7, Gravity Forms, Ninja Forms, WooCommerce, Easy Digital Downloads, membership and newsletter plugins, etc.<\/p>\n\n<h3>Microsoft 365 \/ Azure OAuth Setup<\/h3>\n\n<p>You need a (free) app registration in Microsoft Entra ID. One-time setup, about 5 minutes:<\/p>\n\n<p><strong>1. Register the application<\/strong><\/p>\n\n<ol>\n<li>Sign in to <a href=\"https:\/\/entra.microsoft.com\">https:\/\/entra.microsoft.com<\/a> (or the Azure Portal \u2192 Microsoft Entra ID).<\/li>\n<li>Go to <strong>Identity \u2192 Applications \u2192 App registrations \u2192 New registration<\/strong>.<\/li>\n<li>Name: e.g. <code>WordPress SMTP<\/code>.<\/li>\n<li>Supported account types:\n\n<ul>\n<li><em>Accounts in this organizational directory only<\/em> \u2014 single company tenant (most common; use your Tenant ID in the plugin).<\/li>\n<li><em>Accounts in any organizational directory and personal Microsoft accounts<\/em> \u2014 needed for personal Outlook.com mailboxes (use <code>common<\/code> in the plugin).<\/li>\n<\/ul><\/li>\n<li>Redirect URI: choose platform <strong>Web<\/strong> and paste the exact Redirect URI shown on the plugin's <strong>OAuth 2.0<\/strong> tab\n(it looks like <code>https:\/\/your-site.com\/wp-json\/dxn-outlook\/v1\/callback<\/code>).<\/li>\n<li>Click <strong>Register<\/strong>.<\/li>\n<\/ol>\n\n<p><strong>2. Collect the IDs<\/strong><\/p>\n\n<ul>\n<li>On the app's <strong>Overview<\/strong> page copy the <strong>Application (client) ID<\/strong> and <strong>Directory (tenant) ID<\/strong> into the plugin's OAuth tab.<\/li>\n<\/ul>\n\n<p><strong>3. Create a client secret<\/strong><\/p>\n\n<ol>\n<li>Go to <strong>Certificates &amp; secrets \u2192 New client secret<\/strong>.<\/li>\n<li>Choose an expiry (set a calendar reminder \u2014 you must rotate it before expiry!).<\/li>\n<li>Copy the secret <strong>Value<\/strong> (not the Secret ID) immediately \u2014 it is shown only once \u2014 and paste it into the plugin.<\/li>\n<\/ol>\n\n<p><strong>4. Add API permissions<\/strong><\/p>\n\n<ol>\n<li>Go to <strong>API permissions \u2192 Add a permission<\/strong>.<\/li>\n<li>Choose <strong>APIs my organization uses<\/strong> and search for <strong>Office 365 Exchange Online<\/strong>\n(or use <em>Microsoft Graph \u2192 Delegated<\/em> if <code>SMTP.Send<\/code> appears there in your tenant).<\/li>\n<li>Select <strong>Delegated permissions \u2192 SMTP.Send<\/strong>, then Add.<\/li>\n<li><code>offline_access<\/code>, <code>openid<\/code>, <code>profile<\/code>, <code>email<\/code> are requested automatically at sign-in; no admin action usually needed. If your tenant requires it, click <strong>Grant admin consent<\/strong>.<\/li>\n<\/ol>\n\n<p><strong>5. Enable SMTP AUTH for the mailbox<\/strong><\/p>\n\n<p>Even with OAuth, Exchange Online requires SMTP AUTH to be allowed for the sending mailbox:<\/p>\n\n<ul>\n<li>Microsoft 365 admin center \u2192 <strong>Users \u2192 Active users \u2192<\/strong> <em>select user<\/em> \u2192 <strong>Mail \u2192 Manage email apps<\/strong> \u2192 check <strong>Authenticated SMTP<\/strong>, or<\/li>\n<li>PowerShell: <code>Set-CASMailbox -Identity user@domain.com -SmtpClientAuthenticationDisabled $false<\/code><\/li>\n<\/ul>\n\n<p><strong>6. Authorize the plugin<\/strong><\/p>\n\n<ol>\n<li>Save the Client ID, Client Secret and Tenant ID on the plugin's <strong>OAuth 2.0<\/strong> tab.<\/li>\n<li>Click <strong>Sign in with Microsoft &amp; Authorize<\/strong> and sign in with the mailbox that should send email.<\/li>\n<li>When you return, the status shows <em>Connected<\/em>. Send a test email.<\/li>\n<\/ol>\n\n<h3>External Services<\/h3>\n\n<p>This plugin connects to Microsoft services in order to authenticate and deliver email. No data is sent to the plugin author or any other third party.<\/p>\n\n<ul>\n<li><strong>Microsoft identity platform<\/strong> (<code>login.microsoftonline.com<\/code>) \u2014 used for OAuth 2.0 sign-in and token refresh. Sends your Azure app Client ID, Client Secret, authorization codes and refresh tokens. Contacted when you click \"Sign in with Microsoft\" and automatically before sending when the access token needs refreshing.<\/li>\n<li><strong>Microsoft SMTP servers<\/strong> (<code>smtp.office365.com<\/code> or the host you configure) \u2014 used to deliver email. Sends the email content, sender and recipient addresses, and an OAuth access token for authentication. Contacted on every outgoing email.<\/li>\n<\/ul>\n\n<p>These services are provided by Microsoft: <a href=\"https:\/\/www.microsoft.com\/legal\/terms-of-use\">Terms of Use<\/a>, <a href=\"https:\/\/privacy.microsoft.com\/privacystatement\">Privacy Statement<\/a>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>dixonsmtp-for-outlook-microsoft-365<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install the ZIP via Plugins \u2192 Add New \u2192 Upload Plugin.<\/li>\n<li>Activate the plugin through the Plugins screen.<\/li>\n<li>Go to <strong>Settings \u2192 Outlook SMTP<\/strong>.<\/li>\n<li>On the <strong>General<\/strong> tab: set your From Email (the Microsoft mailbox you will authenticate) and From Name, and enable the mailer.<\/li>\n<li>Follow the OAuth setup below.<\/li>\n<li>Use the <strong>Test Email<\/strong> tab to confirm delivery.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"which%20smtp%20settings%20do%20i%20use%20for%20microsoft%20365%3F\"><h3>Which SMTP settings do I use for Microsoft 365?<\/h3><\/dt>\n<dd><p>Host <code>smtp.office365.com<\/code>, port <code>587<\/code>, encryption <code>TLS<\/code>. These are the plugin defaults.<\/p><\/dd>\n<dt id=\"i%20get%20%225.7.139%20authentication%20unsuccessful%2C%20smtpclientauthentication%20is%20disabled%22\"><h3>I get \"5.7.139 Authentication unsuccessful, SmtpClientAuthentication is disabled\"<\/h3><\/dt>\n<dd><p>SMTP AUTH is disabled for the tenant or mailbox. Follow step 5 of the OAuth setup above.<\/p><\/dd>\n<dt id=\"i%20get%20%225.7.60%20client%20does%20not%20have%20permissions%20to%20send%20as%20this%20sender%22\"><h3>I get \"5.7.60 Client does not have permissions to send as this sender\"<\/h3><\/dt>\n<dd><p>Your From Email must be the authenticated mailbox itself, or an address that mailbox has <em>Send As<\/em> rights for. Enable \"Force From Address\" and set the From Email to the connected mailbox.<\/p><\/dd>\n<dt id=\"does%20this%20work%20with%20personal%20outlook.com%20accounts%3F\"><h3>Does this work with personal Outlook.com accounts?<\/h3><\/dt>\n<dd><p>Yes \u2014 register the Azure app with support for <em>personal Microsoft accounts<\/em> and set Tenant ID to <code>common<\/code>. Host stays <code>smtp.office365.com<\/code> (or <code>smtp-mail.outlook.com<\/code>).<\/p><\/dd>\n<dt id=\"where%20are%20my%20credentials%20stored%3F\"><h3>Where are my credentials stored?<\/h3><\/dt>\n<dd><p>In your WordPress database, encrypted with AES-256 using a key derived from your site's unique <code>AUTH_KEY<\/code>\/<code>SECURE_AUTH_KEY<\/code> salts. Nothing is sent to any third party except Microsoft's own OAuth\/SMTP endpoints.<\/p><\/dd>\n<dt id=\"the%20oauth%20redirect%20returns%20a%20404\"><h3>The OAuth redirect returns a 404<\/h3><\/dt>\n<dd><p>Your REST API permalinks are disabled or blocked. Enable pretty permalinks (Settings \u2192 Permalinks) and make sure <code>\/wp-json\/<\/code> is reachable, then re-copy the Redirect URI.<\/p><\/dd>\n<dt id=\"is%20multisite%20supported%3F\"><h3>Is Multisite supported?<\/h3><\/dt>\n<dd><p>Yes. The plugin can be network-activated; each site keeps its own settings, connection and log.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release: OAuth 2.0 SMTP for Outlook \/ Microsoft 365, email log, test tool, fallback mailer, failure notifications, encrypted secret storage, multisite support.<\/li>\n<\/ul>","raw_excerpt":"Send WordPress emails reliably through Outlook.com \/ Microsoft 365 SMTP with OAuth 2.0, email logging, and a built-in test tool.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/336935","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=336935"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/dixonem"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=336935"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=336935"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=336935"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=336935"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=336935"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=336935"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}