{"id":350970,"date":"2026-09-03T00:34:17","date_gmt":"2026-09-03T00:34:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/mailkite-smtp-multi-provider-smtp-with-failover-email-logs-inbound-email\/"},"modified":"2026-09-03T00:34:02","modified_gmt":"2026-09-03T00:34:02","slug":"mailkite-smtp","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/mailkite-smtp\/","author":23545114,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.4.2","stable_tag":"0.4.2","tested":"7.1","requires":"6.2","requires_php":"8.1","requires_plugins":null,"header_name":"MailKite SMTP \u2013 Multi-Provider SMTP with Failover, Email Logs & Inbound Email","header_author":"MailKite","header_description":"Fix WordPress email delivery: MailKite, SendGrid, Brevo, Mailgun or any SMTP, with free logs, automatic failover, alerts, and inbound email.","assets_banners_color":"0f172a","last_updated":"2026-09-03 00:34:02","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/mailkite.dev\/docs\/integrations\/wordpress","header_author_uri":"https:\/\/mailkite.dev","rating":0,"author_block_rating":0,"active_installs":0,"downloads":42,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","faq","changelog"],"tags":{"0.4.2":{"tag":"0.4.2","author":"mailkite","date":"2026-09-03 00:34:02","revision":3678823}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3678823,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3678823,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3678823,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3678823,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.4.2"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Settings \u2014 choose your mailer; only the relevant section is shown.","2":"Email log with statuses, failure reasons, redaction, and resend.","3":"Inbound email webhook configuration.","4":"Domain Health \u2014 SPF\/DMARC checks with weekly drift alerts."}},"plugin_section":[],"plugin_tags":[17561,267,26736,6696,41812],"plugin_category":[41],"plugin_contributors":[278938,278937],"plugin_business_model":[],"class_list":["post-350970","plugin","type-plugin","status-publish","hentry","plugin_tags-deliverability","plugin_tags-email","plugin_tags-email-log","plugin_tags-smtp","plugin_tags-wp-mail","plugin_category-communication","plugin_contributors-bucabay","plugin_contributors-mailkite","plugin_committers-mailkite"],"banners":{"banner":"https:\/\/ps.w.org\/mailkite-smtp\/assets\/banner-772x250.png?rev=3678823","banner_2x":"https:\/\/ps.w.org\/mailkite-smtp\/assets\/banner-1544x500.png?rev=3678823","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/mailkite-smtp\/assets\/icon-128x128.png?rev=3678823","icon_2x":"https:\/\/ps.w.org\/mailkite-smtp\/assets\/icon-256x256.png?rev=3678823","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>WordPress sends email through PHP <code>mail()<\/code> by default \u2014 unauthenticated, often blocked, and invisible when it fails. MailKite SMTP replaces it with reliable delivery, a free email log, automatic failover, and inbound email.<\/p>\n\n<p><strong>Free forever. No Pro tier. No locked features. Open source.<\/strong><\/p>\n\n<h4>Send through any provider<\/h4>\n\n<ul>\n<li><strong>MailKite<\/strong> (recommended): free tier, ~2-minute setup, open\/click tracking, and <strong>inbound email<\/strong>. Sign up at <a href=\"https:\/\/mailkite.dev\">mailkite.dev<\/a>.<\/li>\n<li><strong>SendGrid, Brevo, Mailgun<\/strong> \u2014 bring your own API key.<\/li>\n<li><strong>Any SMTP server<\/strong> \u2014 host, port, TLS\/SSL, credentials.<\/li>\n<li><strong>Routing rules<\/strong>: send WooCommerce receipts via one provider and newsletters via another, by subject or recipient.<\/li>\n<\/ul>\n\n<h4>Never lose an email<\/h4>\n\n<ul>\n<li><strong>Automatic failover<\/strong> \u2014 if the API provider fails, the email retries through your SMTP server or PHP mail, free.<\/li>\n<li><strong>Instant failure alerts<\/strong> \u2014 email, Slack, Discord, or any webhook, the moment a send fails (rate-limited, no alert storms).<\/li>\n<li><strong>Email log with resend and CSV export<\/strong>, configurable retention, and one-click resend of failures.<\/li>\n<li><strong>Weekly summary<\/strong> \u2014 sent\/failed counts, top errors, and DNS status in your inbox.<\/li>\n<\/ul>\n\n<h4>Private by design<\/h4>\n\n<ul>\n<li><strong>Auth-email redaction (on by default)<\/strong>: bodies of password-reset and verification emails are never stored, so a leaked database or log page can never leak reset links.<\/li>\n<li>Stored credentials are <strong>encrypted at rest<\/strong> (AES-256-GCM keyed from your wp-config salts).<\/li>\n<li>No telemetry. No external calls until you connect a provider.<\/li>\n<\/ul>\n\n<h4>Receive email in WordPress<\/h4>\n\n<p>Send email and receive it too. Turn inbound on (one click \u2014 the webhook and its signature verification are installed on your MailKite domain automatically) and you get three things:<\/p>\n\n<ol>\n<li><strong>Turn an email into a WordPress action.<\/strong> Every message fires <code>do_action( 'mailkite_smtp_inbound', $message, $payload )<\/code>, so your plugins and theme can act on it: open a support ticket, attach a customer's reply to their WooCommerce order, post to a forum, hand it to an AI agent.<\/li>\n<li><strong>Nothing vanishes.<\/strong> Your site sends from a no-reply address and people reply anyway; bounces and out-of-office notices come back too. Without inbound those are lost silently \u2014 with it they land in the Email Log next to the message they answer, and you can <strong>reply from WordPress<\/strong>, in-thread, as your own domain.<\/li>\n<li><strong>Or just forward it.<\/strong> No code: send a copy of everything to an address you already read.<\/li>\n<\/ol>\n\n<h4>For professionals<\/h4>\n\n<ul>\n<li><strong>One-click migration<\/strong> from WP Mail SMTP, Easy WP SMTP, FluentSMTP, and Post SMTP.<\/li>\n<li><strong>WP-CLI<\/strong>: <code>wp mailkite status|test|log|purge<\/code>.<\/li>\n<li><strong>Site Health<\/strong> integration and a <strong>Domain Health<\/strong> tab (SPF\/DMARC checks with weekly drift alerts).<\/li>\n<li>Settings export\/import (secrets excluded) and <code>wp-config.php<\/code> constants (<code>MAILKITE_API_KEY<\/code>, <code>MAILKITE_DEFAULT_MAILER<\/code>) for automated provisioning.<\/li>\n<li>Works with WooCommerce, Contact Form 7, WPForms, and anything using <code>wp_mail()<\/code>.<\/li>\n<\/ul>\n\n<h4>External services<\/h4>\n\n<p>This plugin does not contact any external service until you choose a mailer and enter its credentials. Out of the box, with the built-in PHP mailer or your own SMTP server, no data leaves your site to any third party.<\/p>\n\n<p>When you select an API-based mailer, the email you send \u2014 sender, recipients, subject, body, and any attachments \u2014 is transmitted to that provider at the moment the email is sent, because that provider is what delivers it. Each service, the host it contacts, and what is sent:<\/p>\n\n<ul>\n<li><strong>MailKite<\/strong> \u2014 host <code>api.mailkite.dev<\/code> (configurable; the plugin contacts whatever host is set as the API base). Used to deliver outbound email through your MailKite account, to report delivery events back into the Email Log, and \u2014 if you turn inbound on \u2014 to register a webhook so MailKite can deliver received email to your site. Sent when you send mail: the message and its attachments. Sent when you connect your account: your email address (to create an account) or an OAuth authorization, and the domain id you pick for inbound. Received from MailKite: inbound email addressed to your domain. <a href=\"https:\/\/mailkite.dev\/terms\">Terms of service<\/a> \u00b7 <a href=\"https:\/\/mailkite.dev\/privacy\">Privacy policy<\/a><\/li>\n<li><strong>SendGrid<\/strong> \u2014 host <code>api.sendgrid.com<\/code>. Used to deliver outbound email with your SendGrid API key. Sent when you send mail: the message and its attachments. <a href=\"https:\/\/www.twilio.com\/legal\/tos\">Terms of service<\/a> \u00b7 <a href=\"https:\/\/www.twilio.com\/legal\/privacy\">Privacy policy<\/a><\/li>\n<li><strong>Brevo<\/strong> \u2014 host <code>api.brevo.com<\/code>. Used to deliver outbound email with your Brevo API key. Sent when you send mail: the message and its attachments. <a href=\"https:\/\/www.brevo.com\/legal\/termsofuse\/\">Terms of use<\/a> \u00b7 <a href=\"https:\/\/www.brevo.com\/legal\/privacypolicy\/\">Privacy policy<\/a><\/li>\n<li><strong>Mailgun<\/strong> \u2014 host <code>api.mailgun.net<\/code>, or <code>api.eu.mailgun.net<\/code> when you select the EU region. Used to deliver outbound email with your Mailgun API key. Sent when you send mail: the message and its attachments. <a href=\"https:\/\/www.mailgun.com\/legal\/terms\/\">Terms of service<\/a> \u00b7 <a href=\"https:\/\/www.mailgun.com\/legal\/privacy-policy\/\">Privacy policy<\/a><\/li>\n<li><strong>Your own SMTP server<\/strong> \u2014 the host, port, and credentials you configure. Used to deliver outbound email. Sent when you send mail: the message and its attachments. This is your own or your host's server; no third-party terms apply.<\/li>\n<\/ul>\n\n<h4>Failure alerts (optional, off unless you configure them)<\/h4>\n\n<p>If you enter an alert webhook URL, the plugin sends a notification to that URL, and only when an email fails to send. What is sent: your site's hostname, the failed message's subject line, and the error text reported by the mailer. The message body is never included, and recipients are not sent as a field \u2014 though a provider's error text can itself quote an address it rejected. The URL is yours to choose, so the receiving service is whichever one you point it at \u2014 commonly:<\/p>\n\n<ul>\n<li><strong>Slack<\/strong> \u2014 host <code>hooks.slack.com<\/code>, when you paste a Slack incoming-webhook URL. <a href=\"https:\/\/slack.com\/terms-of-service\">Terms of service<\/a> \u00b7 <a href=\"https:\/\/slack.com\/trust\/privacy\/privacy-policy\">Privacy policy<\/a><\/li>\n<li><strong>Discord<\/strong> \u2014 host <code>discord.com<\/code>, when you paste a Discord webhook URL. <a href=\"https:\/\/discord.com\/terms\">Terms of service<\/a> \u00b7 <a href=\"https:\/\/discord.com\/privacy\">Privacy policy<\/a><\/li>\n<li><strong>Any other endpoint<\/strong> you supply, including one on your own infrastructure, which receives the same JSON payload.<\/li>\n<\/ul>\n\n<p>Leaving the alert webhook field empty means no request is ever made.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20this%20plugin%20really%20free%3F\"><h3>Is this plugin really free?<\/h3><\/dt>\n<dd><p>Yes. Every feature is free and always will be \u2014 including logs, failover, and alerts. MailKite (the email service) has free and paid plans, but the plugin works fully with your own SMTP server or SendGrid\/Brevo\/Mailgun keys and never requires a MailKite account.<\/p><\/dd>\n<dt id=\"why%20are%20some%20log%20entries%20missing%20a%20body%3F\"><h3>Why are some log entries missing a body?<\/h3><\/dt>\n<dd><p>Password-reset, login, and verification emails are stored without their body by default, so a compromised database can never leak reset links. Disable in Settings if you accept the risk.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20woocommerce%20%2F%20contact%20form%207%20%2F%20wpforms%3F\"><h3>Does it work with WooCommerce \/ Contact Form 7 \/ WPForms?<\/h3><\/dt>\n<dd><p>Yes \u2014 the plugin intercepts <code>wp_mail()<\/code>, which they all use.<\/p><\/dd>\n<dt id=\"how%20do%20i%20receive%20email%20into%20wordpress%3F\"><h3>How do I receive email into WordPress?<\/h3><\/dt>\n<dd><p>Open the Inbound tab, pick your domain, and press \"Turn on inbound\" \u2014 the plugin installs the webhook and its signature verification on your MailKite account for you. Nothing to copy, paste, or configure by hand. Then read arriving mail in the Email Log, handle <code>mailkite_smtp_inbound<\/code> in your code, or set a forwarding address.<\/p><\/dd>\n<dt id=\"can%20i%20reply%20to%20email%20from%20wordpress%3F\"><h3>Can I reply to email from WordPress?<\/h3><\/dt>\n<dd><p>Yes. Received messages get a Reply action in the Email Log. The reply goes out as the address the message was delivered to \u2014 your own verified domain, never a spoofed sender \u2014 and it threads correctly, so the conversation stays together in the recipient's mail client. Both halves show under Conversation on the message.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.4.2<\/h4>\n\n<ul>\n<li>The REST email-log endpoint returns site mail only. It previously selected the log table directly and so could return metadata \u2014 recipient, sender, subject \u2014 for mail owned by a user's personal mailbox, which the admin screen and the CSV export already excluded.<\/li>\n<li>The same site-mail restriction now applies to the WP-CLI log listing, the Site Health failure count and the weekly summary digest.<\/li>\n<li>Every read of the log tables goes through the log store, where ownership is part of the query, so no caller can drift from the restriction again.<\/li>\n<\/ul>\n\n<h4>0.4.1<\/h4>\n\n<ul>\n<li>The inbound webhook route now authenticates in its <code>permission_callback<\/code> rather than inside the handler, so an unauthenticated request is rejected before any handler code runs.<\/li>\n<li>Settings input is sanitized field by field as it arrives, with the function appropriate to each field's type, in addition to the existing validation before storage.<\/li>\n<li>Imported settings JSON is sanitized after decoding \u2014 <code>json_decode()<\/code> parses but does not clean.<\/li>\n<li>The OAuth connect callback carries a WordPress nonce through the <code>state<\/code> round-trip and verifies it, alongside the existing single-use, user-bound state transient.<\/li>\n<li>Every REST route states its capability check inline.<\/li>\n<li>Readme documents each external service's host, what is sent and when, and its terms and privacy links \u2014 including the optional failure-alert webhooks.<\/li>\n<\/ul>\n\n<h4>0.4.0<\/h4>\n\n<ul>\n<li>Received mail is now stored in WordPress, so it stays readable after MailKite's retention window ends.<\/li>\n<li>One inbound webhook serves this plugin and MailKite Mailboxes, writing to one set of tables instead of two.<\/li>\n<li>Mail belonging to a user's personal mailbox no longer appears in the site-wide Email Log \u2014 ownership is enforced in the query, not in the template.<\/li>\n<li>Retention purges site mail only; personal mailbox mail is never deleted by it.<\/li>\n<li>A send that falls back to another mailer is labelled as such in the log, instead of reporting plain success.<\/li>\n<li>Inbound webhooks are registered on the connected MailKite account automatically \u2014 no copying URLs by hand.<\/li>\n<\/ul>\n\n<h4>0.3.0<\/h4>\n\n<ul>\n<li>Inbound: reply to received mail from the Email Log, threaded (From is forced to the address it was delivered to).<\/li>\n<li>Log stores the real sender, conversation id and message id; conversation view groups both sides of an exchange.<\/li>\n<li>Inbound tab explains what inbound is for, with the developer hook, log link and forwarding in one place.<\/li>\n<li>User mailboxes moved to their own plugin, <strong>MailKite Mailboxes<\/strong> \u2014 real addresses for WordPress users, an Inbox screen and <code>[mailkite_inbox]<\/code>.<\/li>\n<\/ul>\n\n<h4>0.2.0<\/h4>\n\n<ul>\n<li>SendGrid, Brevo, and Mailgun mailers (bring your own key).<\/li>\n<li>Automatic failover to SMTP\/PHP mail when an API send fails.<\/li>\n<li>Instant failure alerts: email + Slack\/Discord\/webhook.<\/li>\n<li>Routing rules by subject\/recipient.<\/li>\n<li>Inbound email webhook + <code>mailkite_smtp_inbound<\/code> hook + forwarding.<\/li>\n<li>Domain Health (SPF\/DMARC) with weekly drift alerts; weekly summary email.<\/li>\n<li>Site Health tests, WP-CLI commands, settings export\/import.<\/li>\n<li>Open\/click tracking toggles for MailKite sends; large attachments upload by URL.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial release: MailKite API mailer, generic SMTP mailer, email log with redaction and resend, test emails, force-from, REST API.<\/li>\n<\/ul>","raw_excerpt":"Reliable WordPress email: MailKite, SendGrid, Brevo, Mailgun or any SMTP \u2014 free logs, automatic failover, instant alerts, inbound email.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/350970","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=350970"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/mailkite"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=350970"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=350970"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=350970"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=350970"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=350970"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=350970"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}