{"id":363065,"date":"2026-10-04T20:06:18","date_gmt":"2026-10-04T20:06:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/gmcfuerte-smtp-transport\/"},"modified":"2026-10-04T20:06:02","modified_gmt":"2026-10-04T20:06:02","slug":"gmcfuerte-smtp-transport","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/gmcfuerte-smtp-transport\/","author":10408525,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.3","stable_tag":"1.0.3","tested":"7.1.3","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Gmcfuerte SMTP Transport","header_author":"gmcfuerte","header_description":"Sends WordPress mail through your own authenticated SMTP account. Write-only encrypted password, and a test send that shows the real SMTP error.","assets_banners_color":"","last_updated":"2026-10-04 20:06:02","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/gmcfuerte-smtp-transport\/","header_author_uri":"https:\/\/profiles.wordpress.org\/gmcfuerte\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":270,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.3":{"tag":"1.0.3","author":"gmcfuerte","date":"2026-10-04 20:06:02","revision":3727775}},"upgrade_notice":{"1.0.3":"<p>Documentation correction for the separate free GMC catalogue plugin; mail transport is unchanged.<\/p>","1.0.2":"<p>The test-send limiter now remains effective when several admin requests arrive\nat the same time.<\/p>","1.0.1":"<p>Important delivery fix: the From address is no longer rewritten when the plugin\nis not actually sending through SMTP.<\/p>","1.0.0":"<p>First release.<\/p>"},"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.3"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Settings -&gt; SMTP Transport: the account fields, the write-only password\nfield, and the test-send form."}},"plugin_section":[],"plugin_tags":[17561,267,450,6932,6696],"plugin_category":[41],"plugin_contributors":[277384],"plugin_business_model":[],"class_list":["post-363065","plugin","type-plugin","status-publish","hentry","plugin_tags-deliverability","plugin_tags-email","plugin_tags-mail","plugin_tags-phpmailer","plugin_tags-smtp","plugin_category-communication","plugin_contributors-gmcfuerte","plugin_committers-gmcfuerte"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/gmcfuerte-smtp-transport.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>WordPress sends password resets, order confirmations and form notifications with\nwhatever the server hands it. On most hosting that means unauthenticated mail\nfrom an address the domain never authorised, which spam filters quietly discard.<\/p>\n\n<p>Gmcfuerte SMTP Transport points the standard <code>wp_mail()<\/code> pipeline at an SMTP\naccount you control, so messages leave authenticated and signed by the provider\nyou already pay for.<\/p>\n\n<p>It is deliberately small: one settings screen, one test button, no dashboard\nwidgets, no onboarding wizard.<\/p>\n\n<p><strong>What makes this one different<\/strong><\/p>\n\n<p>Most SMTP plugins stop at configuring PHPMailer. This one also protects the\nfailure path: if a migration, salt rotation or removed environment secret makes\nthe saved credential unusable, it stops rewriting the From address instead of\nletting fallback mail impersonate the SMTP domain and fail SPF or DKIM. Its test\nsend reports the mail server's real refusal and whether SMTP was actually used;\nthe password is write-only and may stay entirely outside the database. There is\nno telemetry, provider account or remote dashboard.<\/p>\n\n<p><strong>What it does<\/strong><\/p>\n\n<ul>\n<li>Routes <code>wp_mail()<\/code> through your SMTP host, with STARTTLS, SSL\/TLS, or no\nencryption when a local relay needs it (and \"none\" really means none: the\nautomatic STARTTLS upgrade is switched off, instead of silently overriding\nthe choice you made).<\/li>\n<li>Rewrites the From address and From name to match the authenticated account\n\u2014 and only while that account is really carrying the message. If SMTP stops\nworking, the rewrite stops with it, because a rewritten From on mail sent by\nsomething else is what makes SPF and DKIM fail.<\/li>\n<li>Stores the SMTP password encrypted (AES-256-GCM) with a key derived from your\nown site salts, so the value is useless in a database copied elsewhere. The\nfield is write-only: it never renders the stored password back to the browser.<\/li>\n<li>Accepts a <code>GMCFUERTE_SMTP_PASSWORD<\/code> constant in <code>wp-config.php<\/code> instead, for\nsites that keep credentials out of the database entirely. When it is defined,\nthe settings field says so and is ignored.<\/li>\n<li>Sends a test email and tells you what really happened, including the reason\nthe mail server gave when it refused. If the message went out through the\nserver default transport rather than your SMTP account, it says that too,\ninstead of reporting a pass.<\/li>\n<li>Refuses a half-finished configuration rather than saving one that silently\nfalls back to unauthenticated mail.<\/li>\n<li>Refuses SMTP hosts that are IP literals, loopback names or internal-only\nsuffixes, so the mailer cannot be aimed at an internal service.<\/li>\n<li>Caps admin-triggered test sends at five per minute per user.<\/li>\n<\/ul>\n\n<p><strong>External services<\/strong><\/p>\n\n<p>None. This plugin contacts no service of its own: not on activation, not on a\nschedule, not ever. The only outbound connection it makes is to the SMTP host\nyou type into the settings screen, when WordPress sends a message.<\/p>\n\n<p><strong>Separate GMC catalogue edition<\/strong><\/p>\n\n<p>GMC SMTP Mailer, available free from fuerteventuratv.net, includes a mail log (per-recipient delivery\noutcome, the real SMTP error, retention, resend, CSV export, a persistent\nfailure alert), the matching GDPR export\/erase handlers and an admin REST API.\nIt has its own slug and GMC-hosted update channel. This plugin is complete without it, and nothing\nhere is disabled or time-limited.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install through Plugins -&gt; Add New, or upload the <code>gmcfuerte-smtp-transport<\/code>\nfolder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate it from the Plugins screen.<\/li>\n<li>Go to Settings -&gt; SMTP Transport, enter the host, port, encryption, username\nand password from your mail provider, and save.<\/li>\n<li>Send a test email from the same screen and confirm it arrives.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"where%20do%20i%20get%20the%20smtp%20details%3F\"><h3>Where do I get the SMTP details?<\/h3><\/dt>\n<dd><p>From whoever runs the mailbox: your hosting control panel for a mailbox on your\nown domain, or the SMTP credentials page of your transactional mail provider.\nThis plugin does not create accounts and has no provider of its own.<\/p><\/dd>\n<dt id=\"the%20test%20says%20the%20message%20was%20sent%2C%20but%20with%20a%20warning.%20what%20does%20that%20mean%3F\"><h3>The test says the message was sent, but with a warning. What does that mean?<\/h3><\/dt>\n<dd><p>It means WordPress accepted the message but your SMTP account was not used,\nbecause the settings are incomplete. The mail went out through the server\ndefault transport, which is exactly the situation this plugin exists to fix.\nFill in host, username and password, save, and test again.<\/p><\/dd>\n<dt id=\"is%20my%20password%20stored%20in%20plain%20text%3F\"><h3>Is my password stored in plain text?<\/h3><\/dt>\n<dd><p>No. It is encrypted with AES-256-GCM before it is written, using a key derived\nfrom this site own authentication salt. The field is write-only: it always\nrenders empty, and submitting it blank keeps the stored value. If you would\nrather keep the secret out of the database entirely, define\n    GMCFUERTE_SMTP_PASSWORD in <code>wp-config.php<\/code>.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20the%20block%20editor%2C%20woocommerce%2C%20contact%20form%20plugins%3F\"><h3>Does it work with the block editor, WooCommerce, contact form plugins?<\/h3><\/dt>\n<dd><p>Yes. It configures the core <code>wp_mail()<\/code> pipeline, so anything that sends mail\nthe WordPress way is covered without any integration.<\/p><\/dd>\n<dt id=\"does%20it%20log%20the%20messages%20it%20sends%3F\"><h3>Does it log the messages it sends?<\/h3><\/dt>\n<dd><p>No. SMTP Transport keeps no record of your mail. The separate GMC SMTP Mailer\nplugin provides logging and is available free from the GMC catalogue.<\/p><\/dd>\n<dt id=\"i%20moved%20the%20site%20and%20mail%20stopped%20arriving.%20what%20happened%3F\"><h3>I moved the site and mail stopped arriving. What happened?<\/h3><\/dt>\n<dd><p>The password is encrypted with a key derived from this site own salts, so\nchanging them \u2014 a migration, a clone, or <code>wp config shuffle-salts<\/code> \u2014 leaves a\nstored value this install can no longer read. The settings screen says so, and\nsending falls back to the server default transport with the From address left\nalone. Type the SMTP password again and save.<\/p><\/dd>\n<dt id=\"will%20it%20conflict%20with%20another%20smtp%20plugin%3F\"><h3>Will it conflict with another SMTP plugin?<\/h3><\/dt>\n<dd><p>Yes, in the sense that two plugins configuring the same mailer will fight over\nit. Use one.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Corrected the description of GMC SMTP Mailer: the separate catalogue plugin is free. SMTP Transport remains independent and complete. No mail transport behaviour changed.<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Fixed: the per-user test-send limit now uses an atomic database increment, so\nconcurrent admin requests cannot bypass the five-per-minute cap.<\/li>\n<li>Clarified the plugin's narrow focus: honest failure reporting, safe fallback\nbehavior and local credential handling without telemetry or a remote service.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Fixed: the From address was rewritten even when the plugin was not actually\nsending the mail. The two filters followed the on\/off toggle rather than the\ntransport, so when SMTP stopped being usable \u2014 the site salts changed after a\nmigration or a clone, or the <code>GMCFUERTE_SMTP_PASSWORD<\/code> constant was removed\nfrom <code>wp-config.php<\/code> \u2014 WordPress fell back to the server's default transport\nand still stamped your SMTP domain on the message. SPF and DKIM then fail and\nthe mail is filed as spam. The From address is now left alone unless SMTP is\nreally carrying the message.<\/li>\n<li>Fixed: a stored password that can no longer be decrypted is now reported as\nsuch. The settings screen used to say a password was stored and that leaving\nthe field empty would keep it, and saving that way was accepted \u2014 while\nnothing could be sent. The screen now says the value is unusable, and the save\nis refused with the reason.<\/li>\n<li>Housekeeping: the absence of a <code>load_plugin_textdomain()<\/code> call is now\ndocumented in the source rather than merely absent. WordPress loads the\ntranslations for a directory-hosted plugin itself, and the call has been\ndiscouraged since WordPress 4.6.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release on WordPress.org.<\/li>\n<\/ul>","raw_excerpt":"Send WordPress mail through your own authenticated SMTP account, with an encrypted password and a test send that reports the real error.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/363065","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=363065"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/gmcfuerte"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=363065"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=363065"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=363065"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=363065"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=363065"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=363065"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}