{"id":379172,"date":"2026-10-02T07:29:18","date_gmt":"2026-10-02T07:29:18","guid":{"rendered":"https:\/\/en-ca.wordpress.org\/plugins\/duva-mail\/"},"modified":"2026-10-02T08:55:04","modified_gmt":"2026-10-02T08:55:04","slug":"duva-mail","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/duva-mail\/","author":23577828,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.1.0","stable_tag":"0.1.0","tested":"7.1.2","requires":"5.9","requires_php":"7.4","requires_plugins":null,"header_name":"Duva Mail","header_author":"Duva","header_description":"Sends all the emails of WordPress (WooCommerce, forms, password resets) through the Duva transactional email API.","assets_banners_color":"134d93","last_updated":"2026-10-02 08:55:04","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/duva.ca","rating":0,"author_block_rating":0,"active_installs":0,"downloads":69,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.0":{"tag":"0.1.0","author":"duvamail","date":"2026-10-02 08:55:04","revision":3724401}},"upgrade_notice":{"0.1.0":"<p>First version.<\/p>"},"ratings":[],"assets_icons":{"icon-256x256.png":{"filename":"icon-256x256.png","revision":3724288,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3724288,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3724288,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3724288,"resolution":"1","location":"assets","locale":"","width":1280,"height":1453},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3724288,"resolution":"2","location":"assets","locale":"","width":1280,"height":1540},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3724288,"resolution":"3","location":"assets","locale":"","width":1280,"height":170}},"screenshots":{"1":"The settings screen: connection status, API address, sending domain, API key (never displayed), default sender, and the buttons to check the connection and send a test email.","2":"The \"Latest failures\" table with the HTTP status, the Duva error code and a message, shown after a failed test email.","3":"The admin notice shown when the plugin is active but not configured."}},"plugin_section":[],"plugin_tags":[267,14860,48586,286,6695],"plugin_category":[41,45],"plugin_contributors":[283969],"plugin_business_model":[],"class_list":["post-379172","plugin","type-plugin","status-publish","hentry","plugin_tags-email","plugin_tags-password-reset","plugin_tags-transactional-email","plugin_tags-woocommerce","plugin_tags-wp_mail","plugin_category-communication","plugin_category-ecommerce","plugin_contributors-duvamail","plugin_committers-duvamail"],"banners":{"banner":"https:\/\/ps.w.org\/duva-mail\/assets\/banner-772x250.png?rev=3724288","banner_2x":"https:\/\/ps.w.org\/duva-mail\/assets\/banner-1544x500.png?rev=3724288","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/duva-mail\/assets\/icon-256x256.png?rev=3724288","icon_2x":"https:\/\/ps.w.org\/duva-mail\/assets\/icon-256x256.png?rev=3724288","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/duva-mail\/assets\/screenshot-1.png?rev=3724288","caption":"The settings screen: connection status, API address, sending domain, API key (never displayed), default sender, and the buttons to check the connection and send a test email."},{"src":"https:\/\/ps.w.org\/duva-mail\/assets\/screenshot-2.png?rev=3724288","caption":"The \"Latest failures\" table with the HTTP status, the Duva error code and a message, shown after a failed test email."},{"src":"https:\/\/ps.w.org\/duva-mail\/assets\/screenshot-3.png?rev=3724288","caption":"The admin notice shown when the plugin is active but not configured."}],"raw_content":"<!--section=description-->\n<p>WordPress sends its emails with the web server's mail function, which is often unreliable and ends up in spam. <strong>Duva Mail<\/strong> replaces that transport: every email sent with <code>wp_mail()<\/code> (WooCommerce orders, contact forms, password resets, comment notifications, any plugin) is submitted to your <a href=\"https:\/\/duva.ca\">Duva<\/a> account over HTTPS.<\/p>\n\n<ul>\n<li>Works with anything that calls <code>wp_mail()<\/code>: the plugin hooks the core <code>pre_wp_mail<\/code> filter, so WordPress keeps its usual contract (<code>true<\/code> on success, <code>false<\/code> and the <code>wp_mail_failed<\/code> action on failure).<\/li>\n<li>Respects the <code>wp_mail_from<\/code>, <code>wp_mail_from_name<\/code> and <code>wp_mail_content_type<\/code> filters, and reads <code>From<\/code>, <code>Reply-To<\/code>, <code>Cc<\/code>, <code>Bcc<\/code> and <code>Content-Type<\/code> headers (strings or arrays, <code>Name &lt;address&gt;<\/code> recipients).<\/li>\n<li>Attachments from local files (10 files and 5 MB in total, as accepted by the Duva API).<\/li>\n<li>No silent fallback: if Duva cannot take the email, <code>wp_mail()<\/code> returns <code>false<\/code>, <code>wp_mail_failed<\/code> fires, and the failure is shown in <strong>Settings &gt; Duva Mail<\/strong> and as an admin notice. The email is never sent by another transport behind your back.<\/li>\n<li>Safe retries: each email carries an idempotency key, so a network timeout is retried without ever creating a duplicate. Quota and client errors are never retried.<\/li>\n<li>API key kept out of the browser: the settings field never displays it, and you can define it in <code>wp-config.php<\/code> instead (<code>DUVA_MAIL_API_KEY<\/code>).<\/li>\n<li>No telemetry, no tracking, no calls to any server other than the API address you configure.<\/li>\n<\/ul>\n\n<h4>What you need<\/h4>\n\n<p>A Duva account with a verified sending domain, and an API key created for that domain in the Duva dashboard.<\/p>\n\n<h4>Things to know before you install<\/h4>\n\n<ul>\n<li><strong>Emails are sent from your Duva domain only.<\/strong> If WordPress (or a plugin) sets a sender on another domain, Duva Mail sends from your default sender address and puts the original sender in <code>Reply-To<\/code>, so contact-form replies still reach the visitor.<\/li>\n<li><strong>Cc and Bcc<\/strong>: the Duva API sends one copy per recipient, each addressed only to its own recipient. Cc and Bcc addresses therefore receive their own copy; the other recipients are not shown on it.<\/li>\n<li><strong>Only <code>text\/plain<\/code> and <code>text\/html<\/code> emails<\/strong> are supported. If an email has only an HTML body, Duva adds a plain-text version generated from it. Raw <code>multipart\/*<\/code> bodies are refused with an explicit error.<\/li>\n<li><strong>PHPMailer is bypassed.<\/strong> Plugins that customize PHPMailer (the <code>phpmailer_init<\/code> action) or that add their own SMTP settings have no effect on emails sent through Duva.<\/li>\n<li>The API refuses some custom headers (for example <code>Return-Path<\/code>, <code>Message-ID<\/code>); the email then fails with a message that names the header. See the FAQ.<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>This plugin sends your site's emails to the Duva API, a third-party service, at the API address set in the settings (default <code>https:\/\/api.duva.ca<\/code>). It is the plugin's only purpose and the only external connection it makes.<\/p>\n\n<ul>\n<li><strong>What is sent, and when:<\/strong> for each email WordPress sends, the sender, the recipients, the subject, the body, any attachments and custom headers are sent to Duva so that it can deliver the email. The \"Check the connection\" and \"Send a test email\" buttons also contact the API. Each request carries your API key, the language of the site (to localize error messages) and a user agent with the plugin, WordPress and PHP versions.<\/li>\n<li><strong>What is not sent:<\/strong> nothing else about your site, your users or your visitors, and nothing is sent when no email is sent.<\/li>\n<li>Duva terms of use: https:\/\/duva.ca\/en\/terms<\/li>\n<li>Duva privacy policy: https:\/\/duva.ca\/en\/privacy<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>duva-mail<\/code> folder to <code>\/wp-content\/plugins\/<\/code>, or install the zip from <strong>Plugins &gt; Add New &gt; Upload Plugin<\/strong>.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Go to <strong>Settings &gt; Duva Mail<\/strong> and enter your sending domain and API key.<\/li>\n<li>Click <strong>Send a test email<\/strong>.<\/li>\n<\/ol>\n\n<p>Optional: to keep the API key out of the database, add this line to <code>wp-config.php<\/code> (it then takes precedence, and the settings field is hidden):<\/p>\n\n<pre><code>define( 'DUVA_MAIL_API_KEY', 'dv_...' );\n<\/code><\/pre>\n\n<!--section=faq-->\n<dl>\n<dt id=\"the%20plugin%20is%20active%20but%20my%20emails%20are%20not%20sent.\"><h3>The plugin is active but my emails are not sent.<\/h3><\/dt>\n<dd><p>Open <strong>Settings &gt; Duva Mail<\/strong>: the status shows whether the plugin is configured, and the failure log shows the latest errors (HTTP status, error code and message). A <code>404<\/code> means the API key is unknown, revoked, expired, or belongs to another domain; a <code>403<\/code> that the domain is not verified yet or the account is not allowed to send; a <code>429<\/code> that a rate limit or your sending quota was reached.<\/p><\/dd>\n<dt id=\"does%20it%20fall%20back%20to%20the%20default%20wordpress%20mailer%20when%20duva%20fails%3F\"><h3>Does it fall back to the default WordPress mailer when Duva fails?<\/h3><\/dt>\n<dd><p>No, on purpose. A silent fallback would send transactional emails from an unverified server and hide the problem. The failure is returned to the caller (<code>wp_mail()<\/code> returns <code>false<\/code>), logged, and displayed to administrators.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20woocommerce%2C%20contact%20form%207%2C%20gravity%20forms...%3F\"><h3>Does it work with WooCommerce, Contact Form 7, Gravity Forms...?<\/h3><\/dt>\n<dd><p>Yes, as long as they send through <code>wp_mail()<\/code>. Check that the sender address they use is on your sending domain; otherwise Duva Mail replaces it by the default sender address of the settings and keeps the original in <code>Reply-To<\/code>.<\/p><\/dd>\n<dt id=\"why%20are%20my%20cc%20and%20bcc%20recipients%20not%20shown%20to%20each%20other%3F\"><h3>Why are my Cc and Bcc recipients not shown to each other?<\/h3><\/dt>\n<dd><p>The Duva API has no Cc or Bcc fields: it sends one copy per recipient. Duva Mail adds your Cc and Bcc addresses as recipients, so each of them receives the email, but nobody sees the others.<\/p><\/dd>\n<dt id=\"why%20was%20an%20email%20refused%20because%20of%20a%20header%3F\"><h3>Why was an email refused because of a header?<\/h3><\/dt>\n<dd><p>The Duva API only accepts <code>X-*<\/code> headers (except the ones reserved by the platform) and a short list of standard ones: <code>List-Unsubscribe<\/code>, <code>List-Unsubscribe-Post<\/code>, <code>List-Id<\/code>, <code>In-Reply-To<\/code>, <code>References<\/code>, <code>Auto-Submitted<\/code>, <code>Precedence<\/code>, <code>Importance<\/code>, <code>Feedback-ID<\/code>. Headers such as <code>Return-Path<\/code>, <code>Message-ID<\/code> or <code>DKIM-Signature<\/code> are refused. Remove them from the code that sends the email.<\/p><\/dd>\n<dt id=\"what%20happens%20with%20attachments%3F\"><h3>What happens with attachments?<\/h3><\/dt>\n<dd><p>Local files are read and sent with the email, up to 10 files and 5 MB in total. Executable and script extensions (<code>.exe<\/code>, <code>.js<\/code>...) are refused. Accounts that are still in the Duva sandbox cannot send attachments. Beyond a limit, the email fails with an explicit error and is not sent.<\/p><\/dd>\n<dt id=\"can%20i%20add%20tags%2C%20metadata%20or%20open%20tracking%3F\"><h3>Can I add tags, metadata or open tracking?<\/h3><\/dt>\n<dd><p>Yes, with the <code>duva_mail_payload<\/code> filter, which receives the request body and the <code>wp_mail()<\/code> arguments just before the request is sent, and returns the body to send: <code>add_filter( 'duva_mail_payload', function ( $payload ) { $payload['tags'] = array( 'wordpress' ); return $payload; } );<\/code><\/p><\/dd>\n<dt id=\"where%20is%20the%20api%20key%20stored%3F\"><h3>Where is the API key stored?<\/h3><\/dt>\n<dd><p>In the <code>duva_mail_settings<\/code> option, or nowhere in the database if you define <code>DUVA_MAIL_API_KEY<\/code> in <code>wp-config.php<\/code> (recommended). The key is never sent to the browser, shown in a page, written to the failure log or included in an error message.<\/p><\/dd>\n<dt id=\"what%20does%20the%20failure%20log%20contain%3F\"><h3>What does the failure log contain?<\/h3><\/dt>\n<dd><p>Error messages only: no API key, no email content, no full email addresses (they are masked). It keeps the 20 latest failures and can be cleared.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20my%20data%20when%20i%20uninstall%3F\"><h3>What happens to my data when I uninstall?<\/h3><\/dt>\n<dd><p>Deleting the plugin removes its options (settings, failure log, status). Emails already submitted to Duva stay in your Duva account.<\/p><\/dd>\n<dt id=\"does%20it%20support%20multisite%3F\"><h3>Does it support multisite?<\/h3><\/dt>\n<dd><p>Settings are per site. Network activation is not specifically supported yet.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>First version: <code>pre_wp_mail<\/code> interception, settings screen, connection check, test email, failure log.<\/li>\n<\/ul>","raw_excerpt":"Sends all the emails of WordPress (WooCommerce, forms, password resets) through the Duva transactional email API, hosted in Canada.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/379172","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=379172"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/duvamail"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=379172"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=379172"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=379172"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=379172"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=379172"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=379172"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}