# Send WordPress email with Emailit

> Route WordPress, WooCommerce and contact form email through Emailit SMTP with WP Mail SMTP or a small plugin, using an API key as the password.

WordPress sends password resets, WooCommerce orders and contact form messages with `wp_mail()`, which uses the server's mail setup by default and often lands in spam. This guide routes that mail through the Emailit SMTP relay, either with the WP Mail SMTP plugin or with a few lines of code.

## Prerequisites

- Administrator access to your WordPress site.
- A [verified sending domain](/docs/domains/add-a-domain/), for example `acme.com`. Your site's From address must use it.
- An [API key](/docs/developers/api-keys/). Create a **Sending Only** key restricted to your domain, named something like `wordpress-acme`, so a leaked plugin setting can't be used for anything else.
- Until your workspace has [production access](/docs/workspaces/production-access/), you can only send to the account emails of workspace members. Test with your own address.

## SMTP settings

These are the values you'll enter in any SMTP plugin:

| Setting | Value |
| --- | --- |
| SMTP host | `smtp.emailit.com` |
| Encryption | TLS (STARTTLS) |
| SMTP port | `587` |
| Authentication | On |
| SMTP username | `emailit` |
| SMTP password | Your API key (`secret_…`) |
| From email | An address on your verified domain, for example `hello@acme.com` |

If your host blocks port 587, use `2525` or `2587` with TLS, or `465` with SSL. See [SMTP settings](/docs/smtp/settings/).

## Configure WP Mail SMTP

[WP Mail SMTP](https://wordpress.org/plugins/wp-mail-smtp/) is a free plugin that replaces WordPress's mail transport. Other SMTP plugins, such as FluentSMTP or Post SMTP, use the same settings with slightly different labels.

1. **Install the plugin.** In WordPress, go to **Plugins > Add New**, search for **WP Mail SMTP**, then install and activate it. Skip the setup wizard if it opens; you can configure everything on the settings page.

2. **Set the sender.** Open the plugin's settings. Set **From Email** to an address on your verified domain and turn on **Force From Email**, so every plugin sends from that address. Set **From Name** to your site or company name.

3. **Choose Other SMTP.** Under **Mailer**, choose **Other SMTP**.

4. **Enter the server.** Set **SMTP Host** to `smtp.emailit.com`, **Encryption** to **TLS**, and **SMTP Port** to `587`. Leave **Auto TLS** on.

5. **Enter the credentials.** Turn on **Authentication**. Set **SMTP Username** to `emailit` and **SMTP Password** to your API key. Save the settings.

6. **Send a test.** Use the plugin's **Email Test** tool to send a message to your own address. It appears in **Email API → Emails** within seconds.

### Keep the key out of the database

WP Mail SMTP can read its settings from constants, so the API key lives in `wp-config.php` instead of the database. Add these lines above `/* That's all, stop editing! */`:

```php title="wp-config.php"
define( 'WPMS_ON', true );
define( 'WPMS_MAILER', 'smtp' );
define( 'WPMS_SMTP_HOST', 'smtp.emailit.com' );
define( 'WPMS_SMTP_PORT', 587 );
define( 'WPMS_SSL', 'tls' );
define( 'WPMS_SMTP_AUTH', true );
define( 'WPMS_SMTP_AUTOTLS', true );
define( 'WPMS_SMTP_USER', 'emailit' );
define( 'WPMS_SMTP_PASS', 'secret_••••••••••••••••••••••••••••••••' );
define( 'WPMS_MAIL_FROM', 'hello@acme.com' );
define( 'WPMS_MAIL_FROM_FORCE', true );
define( 'WPMS_MAIL_FROM_NAME', 'Acme' );
```

The settings page then shows these values as locked. Check the plugin's documentation if a field doesn't pick up its constant.

## Configure without a plugin

If you'd rather not install a plugin, add a must-use plugin that configures WordPress's built-in PHPMailer. Define the key in `wp-config.php`:

```php title="wp-config.php"
define( 'EMAILIT_API_KEY', 'secret_••••••••••••••••••••••••••••••••' );
```

Then create this file:

```php title="wp-content/mu-plugins/emailit-smtp.php"
<?php
/**
 * Plugin Name: Emailit SMTP
 * Description: Sends all WordPress email through the Emailit SMTP relay.
 */

add_action( 'phpmailer_init', function ( $phpmailer ) {
    $phpmailer->isSMTP();
    $phpmailer->Host       = 'smtp.emailit.com';
    $phpmailer->Port       = 587;
    $phpmailer->SMTPSecure = 'tls';
    $phpmailer->SMTPAuth   = true;
    $phpmailer->Username   = 'emailit';
    $phpmailer->Password   = EMAILIT_API_KEY;
} );

add_filter( 'wp_mail_from', fn () => 'hello@acme.com' );
add_filter( 'wp_mail_from_name', fn () => 'Acme' );
```

Files in `mu-plugins` load automatically and can't be turned off from the admin screen.

## Receive webhooks

Most sites don't need webhooks. If you want to react to bounces or complaints, for example to flag a WooCommerce customer's address, register a REST route and verify the signature. Store the webhook's signing secret in `wp-config.php` as `EMAILIT_WEBHOOK_SECRET`:

```php title="wp-content/mu-plugins/emailit-webhooks.php"
<?php
add_action( 'rest_api_init', function () {
    register_rest_route( 'emailit/v1', '/webhook', [
        'methods'             => 'POST',
        'permission_callback' => '__return_true',
        'callback'            => function ( WP_REST_Request $request ) {
            $payload   = $request->get_body();
            $timestamp = (string) $request->get_header( 'x-emailit-timestamp' );
            $signature = (string) $request->get_header( 'x-emailit-signature' );
            $expected  = hash_hmac( 'sha256', $timestamp . '.' . $payload, EMAILIT_WEBHOOK_SECRET );

            if ( abs( time() - (int) $timestamp ) > 300 || ! hash_equals( $expected, $signature ) ) {
                return new WP_Error( 'invalid_signature', 'Invalid signature', [ 'status' => 401 ] );
            }

            foreach ( json_decode( $payload, true ) as $event ) {
                if ( 'email.bounced' === $event['type'] ) {
                    // Flag $event['data']['object']['to'].
                }
            }

            return new WP_REST_Response( null, 200 );
        },
    ] );
} );
```

Point the [webhook](/docs/webhooks/set-up/) at `https://acme.com/wp-json/emailit/v1/webhook`. The signature check is what protects the route, so don't remove it.

## Production tips

- **Force the From address.** WooCommerce, contact form and membership plugins often set their own sender. Forcing a From address on your verified domain stops `530 From/Sender domain is not verified` errors.
- **Check the logs when something fails.** **Email API → Logs** shows every SMTP login and message with its status code, filtered by API key.
- **Watch your limits.** New workspaces can send 2 emails per second and 5,000 per day by default. A large WooCommerce sale or a newsletter plugin can hit that; see [Limits](/docs/limits/) to request more.
- **Don't send newsletters through wp_mail.** For marketing email to a list, use [Campaigns](/docs/campaigns/), which handle unsubscribe links and audiences for you.

## Troubleshooting

| Symptom | Cause | Fix |
| --- | --- | --- |
| `535 Authentication failed` | The password isn't a valid API key. | Paste the full key, including `secret_`, and use `emailit` as the username. |
| `530 From/Sender domain is not verified for this workspace` | The From address isn't on a verified domain. | Set and force a From email on your verified domain. |
| `530 API key is restricted to sending domain` | The key is restricted to another domain. | Use a From address on the key's domain, or another key. |
| Connection timed out | Your host blocks the port. | Try port `2525` or `2587` with TLS, or ask your host to allow outbound SMTP. |
| `550 Unverified workspaces can only send to workspace members' account emails` | The workspace doesn't have production access yet. | [Request production access](/docs/workspaces/production-access/). |

For more, see [SMTP troubleshooting](/docs/smtp/troubleshooting/).

## Next steps

  - [SMTP settings](/docs/smtp/settings/): Ports, TLS and credentials.
  - [Deliverability best practices](/docs/deliverability/best-practices/): Keep your mail out of spam.
  - [Email statuses](/docs/logs/email-statuses/): What each status in the Emails list means.
  - [API keys](/docs/developers/api-keys/): Scopes, domain restrictions and rotation.

---
Source: https://emailit.com/docs/frameworks/wordpress/
