Website email — contact forms, password resets, order confirmations — is the mail most likely to vanish, because it’s often sent in the way filters trust least.
The two ways a website sends mail
PHP mail() | Authenticated SMTP | |
|---|---|---|
| How | Hands mail to the server’s local mail system | Logs in to a mailbox like an email app |
| From address | Whatever the code sets, often unrelated | A real mailbox on your domain |
| Authentication | Often weak or misaligned | SPF and DKIM align with your domain |
| Deliverability | Unpredictable | Reliable |
Set up a sending mailbox
- Create an address such as
website@yourdomain.co.uk. How to create an email account in DirectAdmin - Use it as the From address for all website mail.
- Configure your site to send through SMTP with these settings:
| Setting | Value |
|---|---|
| Host | mail.yourdomain.co.uk |
| Port | 465 (SSL) or 587 (TLS) |
| Username | website@yourdomain.co.uk |
| Password | That mailbox’s password |
For WordPress, use an SMTP plugin. How to send WordPress email through SMTP
The contact form trap
A form that sets the From address to the visitor’s email (say, a Gmail address) makes your server send mail claiming to be from Gmail. DMARC at Gmail rejects it. Instead:
- From: your sending mailbox
- Reply-To: the visitor’s address
Replies still go to the visitor.
PHP example with PHPMailer
$mail = new PHPMailer\PHPMailer\PHPMailer(true);
$mail->isSMTP();
$mail->Host = 'mail.yourdomain.co.uk';
$mail->SMTPAuth = true;
$mail->Username = 'website@yourdomain.co.uk';
$mail->Password = getenv('SMTP_PASSWORD');
$mail->SMTPSecure = 'ssl';
$mail->Port = 465;
$mail->setFrom('website@yourdomain.co.uk', 'Your Site');
$mail->addReplyTo($visitorEmail);
Keep the password out of files in public_html. Storing configuration and secrets outside public_html