Sending email from your website reliably

Why contact forms and website notifications go missing, the difference between PHP mail() and authenticated SMTP, and how to set up a sending address.

How-to guideIntermediate2 min readUpdated

Website email — contact forms, password resets, order confirmations — is the mail most likely to vanish, because it’s often sent in the way filters trust least.

The two ways a website sends mail

PHP mail()Authenticated SMTP
HowHands mail to the server’s local mail systemLogs in to a mailbox like an email app
From addressWhatever the code sets, often unrelatedA real mailbox on your domain
AuthenticationOften weak or misalignedSPF and DKIM align with your domain
DeliverabilityUnpredictableReliable

Set up a sending mailbox

  1. Create an address such as website@yourdomain.co.uk. How to create an email account in DirectAdmin
  2. Use it as the From address for all website mail.
  3. Configure your site to send through SMTP with these settings:
SettingValue
Hostmail.yourdomain.co.uk
Port465 (SSL) or 587 (TLS)
Usernamewebsite@yourdomain.co.uk
PasswordThat mailbox’s password

For WordPress, use an SMTP plugin. How to send WordPress email through SMTP

The contact form trap

A form that sets the From address to the visitor’s email (say, a Gmail address) makes your server send mail claiming to be from Gmail. DMARC at Gmail rejects it. Instead:

  • From: your sending mailbox
  • Reply-To: the visitor’s address

Replies still go to the visitor.

PHP example with PHPMailer

$mail = new PHPMailer\PHPMailer\PHPMailer(true);
$mail->isSMTP();
$mail->Host = 'mail.yourdomain.co.uk';
$mail->SMTPAuth = true;
$mail->Username = 'website@yourdomain.co.uk';
$mail->Password = getenv('SMTP_PASSWORD');
$mail->SMTPSecure = 'ssl';
$mail->Port = 465;
$mail->setFrom('website@yourdomain.co.uk', 'Your Site');
$mail->addReplyTo($visitorEmail);

Keep the password out of files in public_html. Storing configuration and secrets outside public_html

Popular

Tip: press / to search from any pageSee all results