{"id":381359,"date":"2026-10-08T07:07:18","date_gmt":"2026-10-08T07:07:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/codo-mailer\/"},"modified":"2026-10-08T07:07:04","modified_gmt":"2026-10-08T07:07:04","slug":"codo-mailer","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/codo-mailer\/","author":18270956,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.1.3","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"Codo Mailer","header_author":"Codo Digital","header_description":"Secure-by-default email delivery for WordPress: SMTP, Amazon SES, Postmark, Mailgun, Brevo and SendGrid, with an email log, resend, backup connection and failure alerts. Free, no upsells.","assets_banners_color":"3b6c7f","last_updated":"2026-10-08 07:07:04","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/Codo-Digital-Ltd\/codo-mailer","header_author_uri":"https:\/\/cododigital.co.uk","rating":0,"author_block_rating":0,"active_installs":0,"downloads":39,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"cododigital","date":"2026-10-08 07:07:04","revision":3733839}},"upgrade_notice":{"1.0.0":"<p>First release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3733839,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3733839,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3733839,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3733839,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3733839,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[265,17561,267,26736,6696],"plugin_category":[41],"plugin_contributors":[284951],"plugin_business_model":[],"class_list":["post-381359","plugin","type-plugin","status-publish","hentry","plugin_tags-amazon-ses","plugin_tags-deliverability","plugin_tags-email","plugin_tags-email-log","plugin_tags-smtp","plugin_category-communication","plugin_contributors-cododigital","plugin_committers-cododigital"],"banners":{"banner":"https:\/\/ps.w.org\/codo-mailer\/assets\/banner-772x250.png?rev=3733839","banner_2x":"https:\/\/ps.w.org\/codo-mailer\/assets\/banner-1544x500.png?rev=3733839","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/codo-mailer\/assets\/icon.svg?rev=3733839","icon":"https:\/\/ps.w.org\/codo-mailer\/assets\/icon.svg?rev=3733839","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Codo Mailer makes sure the email your WordPress site sends (password resets, order confirmations, form notifications) actually arrives. It routes every <code>wp_mail()<\/code> call through a proper email provider instead of your server's unauthenticated PHP mail.<\/p>\n\n<p>It is built by <a href=\"https:\/\/cododigital.co.uk\">Codo Digital<\/a>, a UK web development and managed hosting company, and is the mailer we use on our own clients' sites. Everything is free. There is no Pro version, no upsell, no account to create and no tracking.<\/p>\n\n<h4>Providers<\/h4>\n\n<ul>\n<li>Any SMTP server (STARTTLS or SSL\/TLS)<\/li>\n<li>Amazon SES (API, any region, including London <code>eu-west-2<\/code>)<\/li>\n<li>Postmark<\/li>\n<li>Mailgun (EU and US regions)<\/li>\n<li>Brevo<\/li>\n<li>SendGrid<\/li>\n<\/ul>\n\n<p>API providers are used over HTTPS, so blocked SMTP ports on your host don't matter.<\/p>\n\n<h4>Features<\/h4>\n\n<ul>\n<li><strong>Backup connection<\/strong> used automatically when the primary fails.<\/li>\n<li><strong>Email log<\/strong> filtered by status, with full details and <strong>resend<\/strong>.<\/li>\n<li><strong>Failure alerts<\/strong> by email and\/or webhook (a Slack incoming webhook works as-is), at most one per hour.<\/li>\n<li><strong>Send a test email<\/strong> from the settings screen.<\/li>\n<li><strong>From address control<\/strong>, with an option to override other plugins' senders.<\/li>\n<li>Works with WooCommerce, contact form plugins and anything else that uses <code>wp_mail()<\/code>. Core hooks such as <code>wp_mail_from<\/code>, <code>wp_mail_content_type<\/code>, <code>wp_mail_succeeded<\/code> and <code>wp_mail_failed<\/code> keep working. <code>phpmailer_init<\/code> (used by DKIM-signing plugins) runs for SMTP, Amazon SES and Mailgun, which send full MIME; Postmark, Brevo and SendGrid build the message on their side.<\/li>\n<\/ul>\n\n<h4>Secure by default<\/h4>\n\n<p>Email logs hold password-reset links, so a leaky log is a site takeover waiting to happen. Codo Mailer is designed around that:<\/p>\n\n<ul>\n<li>Password-reset, set-password and email-confirmation links, one-time tokens and plaintext \"Password:\" lines are <strong>redacted<\/strong> before an email is logged, and those emails cannot be resent from the log. Redaction is best-effort, so as a fail-safe, if a secret still shows up once the body is decoded, the whole body is left out of the log.<\/li>\n<li>The log is only ever shown on the admin screen to administrators (<code>manage_options<\/code>; on multisite, super admins only, because whoever controls mail can read any user's reset email). There are <strong>no REST or AJAX endpoints<\/strong> for it.<\/li>\n<li>API keys and passwords are <strong>encrypted at rest<\/strong> (libsodium), so a database dump alone does not reveal them.<\/li>\n<li>Or keep credentials out of the database entirely with <strong><code>wp-config.php<\/code> constants<\/strong>.<\/li>\n<li>Logs are deleted after 30 days by default.<\/li>\n<\/ul>\n\n<h4>For hosts and agencies: configuration in wp-config.php<\/h4>\n\n<p>Every setting can be fixed with a constant. Constants override the database and show read-only in the admin screen.<\/p>\n\n<pre><code>define( 'CODO_MAILER_FROM_EMAIL', 'noreply@example.co.uk' );\ndefine( 'CODO_MAILER_FROM_NAME', 'Example Ltd' );\n\ndefine( 'CODO_MAILER_PRIMARY_TYPE', 'ses' );\ndefine( 'CODO_MAILER_PRIMARY_REGION', 'eu-west-2' );\ndefine( 'CODO_MAILER_PRIMARY_ACCESS_KEY', 'AKIA...' );\ndefine( 'CODO_MAILER_PRIMARY_SECRET_KEY', '...' );\n\ndefine( 'CODO_MAILER_BACKUP_TYPE', 'smtp' );\ndefine( 'CODO_MAILER_BACKUP_HOST', 'smtp.example.net' );\ndefine( 'CODO_MAILER_BACKUP_USERNAME', '...' );\ndefine( 'CODO_MAILER_BACKUP_PASSWORD', '...' );\n\ndefine( 'CODO_MAILER_ALERT_EMAIL', 'ops@example.co.uk' );\n<\/code><\/pre>\n\n<p>Connection field names: SMTP <code>host<\/code>, <code>port<\/code>, <code>encryption<\/code> (tls, ssl, none), <code>auth<\/code>, <code>username<\/code>, <code>password<\/code>; SES <code>region<\/code>, <code>access_key<\/code>, <code>secret_key<\/code>; Postmark <code>server_token<\/code>, <code>message_stream<\/code>; Mailgun <code>domain<\/code>, <code>api_key<\/code>, <code>region<\/code> (eu, us); Brevo and SendGrid <code>api_key<\/code>.<\/p>\n\n<p>To use your own encryption key instead of the site salts, define <code>CODO_MAILER_ENCRYPTION_KEY<\/code>. If you rotate your salts without one, re-enter saved API keys and passwords (secrets set as constants are unaffected).<\/p>\n\n<h4>For developers<\/h4>\n\n<ul>\n<li><code>codo_mailer_redaction_patterns<\/code> filter: add regular expressions for other secret links (e.g. magic-login tokens).<\/li>\n<li><code>codo_mailer_transport<\/code> filter: provide a transport for a custom connection type.<\/li>\n<li><code>codo_mailer_alert_interval<\/code> filter: change the alert throttle (seconds).<\/li>\n<li><code>codo_mailer_capability<\/code> filter: change who can manage the plugin.<\/li>\n<li><code>codo_mailer_sent<\/code> action: fires after delivery with the message, connection and provider result.<\/li>\n<\/ul>\n\n<p>Source, issues and tests: <a href=\"https:\/\/github.com\/Codo-Digital-Ltd\/codo-mailer\">github.com\/Codo-Digital-Ltd\/codo-mailer<\/a>.<\/p>\n\n<h3>External services<\/h3>\n\n<p>Codo Mailer delivers your site's email through an email provider that you choose and configure. It does not contact any service until you save a connection in Settings &gt; Codo Mailer (or define one in <code>wp-config.php<\/code>), and it only ever contacts the providers you have configured. It never sends data to Codo Digital.<\/p>\n\n<p><strong>When data is sent:<\/strong> every time WordPress sends an email through <code>wp_mail()<\/code> (for example password resets, new-user notifications, WooCommerce orders and form notifications), when you use \"Send a test\", and when you resend an email from the log. The primary connection is used first; the backup connection is contacted only if the primary fails.<\/p>\n\n<p><strong>What is sent:<\/strong> the email itself: sender, recipients (To, Cc, Bcc), Reply-To, subject, body, attachments and any custom headers, plus the credentials you entered for that provider so it can authenticate the request (for Amazon SES, your access key ID and a signature made with your secret key; the secret key itself is never sent).<\/p>\n\n<h4>Amazon SES (Amazon Web Services)<\/h4>\n\n<p>Amazon Simple Email Service is an email sending service. If you choose it, each email is sent to the SES API endpoint for the region you select (<code>email.&lt;region&gt;.amazonaws.com<\/code>), signed with your access keys.<\/p>\n\n<ul>\n<li>Terms: https:\/\/aws.amazon.com\/service-terms\/<\/li>\n<li>Privacy: https:\/\/aws.amazon.com\/privacy\/<\/li>\n<\/ul>\n\n<h4>Postmark (ActiveCampaign)<\/h4>\n\n<p>Postmark is a transactional email service. If you choose it, each email is sent to <code>api.postmarkapp.com<\/code> with your server token.<\/p>\n\n<ul>\n<li>Terms: https:\/\/postmarkapp.com\/terms-of-service<\/li>\n<li>Privacy: https:\/\/www.activecampaign.com\/legal\/privacy-policy<\/li>\n<\/ul>\n\n<h4>Mailgun (Sinch Email)<\/h4>\n\n<p>Mailgun is an email sending service. If you choose it, each email is sent to <code>api.eu.mailgun.net<\/code> (EU region) or <code>api.mailgun.net<\/code> (US region), depending on your setting, with your API key.<\/p>\n\n<ul>\n<li>Terms: https:\/\/www.mailgun.com\/legal\/terms\/<\/li>\n<li>Privacy: https:\/\/www.mailgun.com\/legal\/privacy-policy\/<\/li>\n<\/ul>\n\n<h4>Brevo<\/h4>\n\n<p>Brevo is an email and marketing platform with a transactional email API. If you choose it, each email is sent to <code>api.brevo.com<\/code> with your API key.<\/p>\n\n<ul>\n<li>Terms: https:\/\/www.brevo.com\/legal\/termsofuse\/<\/li>\n<li>Privacy: https:\/\/www.brevo.com\/legal\/privacypolicy\/<\/li>\n<\/ul>\n\n<h4>SendGrid (Twilio)<\/h4>\n\n<p>SendGrid is an email sending service. If you choose it, each email is sent to <code>api.sendgrid.com<\/code> with your API key.<\/p>\n\n<ul>\n<li>Terms: https:\/\/www.twilio.com\/en-us\/legal\/tos<\/li>\n<li>Privacy: https:\/\/www.twilio.com\/en-us\/legal\/privacy<\/li>\n<\/ul>\n\n<h4>SMTP server<\/h4>\n\n<p>If you choose SMTP, each email is sent to the SMTP server you enter (your mailbox provider, host or any other server), with the username and password you enter. Its terms and privacy policy are those of whoever runs that server.<\/p>\n\n<h4>Failure alert webhook (optional)<\/h4>\n\n<p>If you enter a webhook URL (for example a Slack incoming webhook), Codo Mailer posts a JSON alert to that URL when an email fails to send, at most once an hour by default. The alert contains the site name, site URL, the failed email's subject, the error message and the time. Nothing is posted if the field is left empty. The service's terms and privacy policy are those of whoever provides that URL; for Slack: https:\/\/slack.com\/main-services-agreement and https:\/\/slack.com\/trust\/privacy\/privacy-policy<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install from Plugins &gt; Add New, or upload the <code>codo-mailer<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate the plugin.<\/li>\n<li>Go to Settings &gt; Codo Mailer, choose a provider and enter its credentials.<\/li>\n<li>Use the \"Send a test\" tab to confirm delivery.<\/li>\n<\/ol>\n\n<p>Until a primary connection is saved, WordPress keeps sending email the way it did before.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20an%20account%20with%20an%20email%20provider%3F\"><h3>Do I need an account with an email provider?<\/h3><\/dt>\n<dd><p>Yes. Codo Mailer connects your site to a provider; it doesn't send email itself. Amazon SES, Postmark, Mailgun, Brevo and SendGrid all have free or low-cost tiers, or you can use your existing mailbox's SMTP server.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20woocommerce%20and%20form%20plugins%3F\"><h3>Does it work with WooCommerce and form plugins?<\/h3><\/dt>\n<dd><p>Yes. Anything that sends through <code>wp_mail()<\/code> goes through Codo Mailer.<\/p><\/dd>\n<dt id=\"why%20can%27t%20i%20resend%20a%20password-reset%20email%3F\"><h3>Why can't I resend a password-reset email?<\/h3><\/dt>\n<dd><p>The reset link was redacted before logging, so the logged copy no longer contains it. Ask the user to request a new reset, which is also safer.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20both%20connections%20fail%3F\"><h3>What happens if both connections fail?<\/h3><\/dt>\n<dd><p>The failure is logged with each provider's error, WordPress's <code>wp_mail_failed<\/code> action fires, and an alert goes to your alert email and\/or webhook.<\/p><\/dd>\n<dt id=\"does%20it%20send%20any%20data%20to%20codo%20digital%3F\"><h3>Does it send any data to Codo Digital?<\/h3><\/dt>\n<dd><p>No. It talks only to the email provider (and alert webhook) you configure.<\/p><\/dd>\n<dt id=\"is%20it%20multisite%20compatible%3F\"><h3>Is it multisite compatible?<\/h3><\/dt>\n<dd><p>Yes. Each site has its own settings and log, managed by super admins only. Constants in <code>wp-config.php<\/code> apply to every site in the network.<\/p><\/dd>\n<dt id=\"can%20i%20send%20an%20email%20with%20only%20bcc%20recipients%3F\"><h3>Can I send an email with only Bcc recipients?<\/h3><\/dt>\n<dd><p>Over SMTP, Amazon SES and Mailgun, yes. Postmark, Brevo and SendGrid require at least one To address and will report an error.<\/p><\/dd>\n<dt id=\"will%20a%20failure%20slow%20my%20site%20down%3F\"><h3>Will a failure slow my site down?<\/h3><\/dt>\n<dd><p>Each provider call times out after 15 seconds. Failure alerts are sent at the end of the request, after the page has been delivered where the server supports it, so visitors don't wait for them.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First release: SMTP, Amazon SES, Postmark, Mailgun, Brevo and SendGrid; backup connection; email log with redaction and resend; email and webhook alerts; wp-config.php constants; encrypted secrets.<\/li>\n<\/ul>","raw_excerpt":"Secure-by-default email delivery: SMTP, Amazon SES, Postmark, Mailgun, Brevo and SendGrid, with a log, resend, backup connection and alerts. Free.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/381359","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=381359"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/cododigital"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=381359"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=381359"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=381359"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=381359"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=381359"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=381359"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}