WP Manifestindependent plugin directory
manifest / email / quick-smtp

Quick SMTP

Lightweight SMTP mailer for WordPress — configure outgoing email reliably and securely with AES-256 password encryption.

by Suchandan Haldar · github.com/suchandandev09/quick-smtp · website

★ 0stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/suchandandev09/quick-smtp/archive/refs/heads/main.zip

Lightweight SMTP mailer for WordPress — configure outgoing email reliably and securely with AES-256 password encryption.

Description

Quick SMTP replaces WordPress's default PHP mail() function with a proper SMTP connection, so your emails actually get delivered and don't land in spam.

Key Features

  • Simple settings page under Settings → Quick SMTP
  • Supports SSL and TLS encryption
  • SMTP password stored encrypted at rest using AES-256-CBC (requires PHP OpenSSL extension)
  • From Email and From Name pre-filled from your site settings
  • Built-in Send Test Email tool with full SMTP debug log
  • Email logging — keeps the last 20 outgoing emails for debugging
  • Inline troubleshooting guide for Gmail, Outlook, and other providers
  • Clean uninstall — removes all stored data when deleted
  • Multisite compatible (per-site settings)
  • Translation-ready (.pot file included)

Compatible Providers

Provider Host Port Encryption
Gmail smtp.gmail.com 587 TLS
Outlook / Microsoft 365 smtp.office365.com 587 TLS
Yahoo Mail smtp.mail.yahoo.com 587 TLS
Amazon SES Your SES endpoint 587 TLS
Mailgun smtp.mailgun.org 587 TLS
SendGrid smtp.sendgrid.net 587 TLS
Any standard SMTP server — — —

Requirements

  • WordPress 5.9 or higher
  • PHP 7.4 or higher
  • PHP OpenSSL extension (for AES-256 password encryption; falls back to plaintext storage if unavailable)

Installation

  1. Upload the quick-smtp folder to /wp-content/plugins/, or install directly via Plugins → Add New in the WordPress dashboard.
  2. Activate the plugin through the Plugins menu.
  3. Navigate to Settings → Quick SMTP.
  4. Enter your SMTP host, port, encryption type, username, and password.
  5. Click Save Settings.
  6. Click Send Test Email to verify the connection.

Configuration

Settings Fields

Field Description
Enable Quick SMTP Toggle the plugin on or off.
SMTP Host The hostname of your SMTP server (e.g., smtp.gmail.com).
SMTP Port The port your server listens on (commonly 587 for TLS, 465 for SSL).
Encryption None, SSL, or TLS (recommended).
Use Authentication Enable SMTP authentication with username and password.
Username Your SMTP account username (typically your email address).
Password Your SMTP account password or App Password. Encrypted at rest with AES-256-CBC.
From Email The email address outgoing mail is sent from. Defaults to the site admin email.
From Name The sender name for outgoing mail. Defaults to the site title.
Disable SSL Verification Skips certificate validation during TLS handshake. Only for local/dev environments.

Gmail Setup

Google no longer allows sign-in with a regular account password from third-party apps. You must:

  1. Enable 2-Step Verification on your Google account.
  2. Generate an App Password.
  3. Use the 16-character App Password in the Password field.

Recommended settings:

Host:       smtp.gmail.com
Port:       587
Encryption: TLS
Username:   your-email@gmail.com
Password:   <16-character App Password>

Outlook / Microsoft 365 Setup

Host:       smtp.office365.com
Port:       587
Encryption: TLS
Username:   your-email@outlook.com
Password:   your account password (or App Password if required)

Development

Project Structure

quick-smtp/
├── quick-smtp.php    # Main plugin file (singleton class, hooks, settings, SMTP config)
├── uninstall.php         # Clean removal of all plugin data (including multisite)
├── readme.txt            # WordPress.org plugin directory readme
├── languages/            # Translation files (.pot/.po/.mo)
│   └── index.php
└── README.md             # This file

Architecture

The plugin is built as a single-file singleton class (Quick_SMTP_Plugin) that:

  1. Registers hooks in the constructor — admin menu, settings API, phpmailer_init, mail filters, email logging, and the test-email handler.
  2. Stores settings using the WordPress Options API under the key quick_smtp_settings.
  3. Encrypts the SMTP password at rest using AES-256-CBC via PHP's OpenSSL extension, with the encryption key derived from the site's AUTH_SALT.
  4. Configures PHPMailer on phpmailer_init to use the saved SMTP settings instead of PHP's mail().
  5. Logs outgoing emails via the wp_mail filter, keeping the most recent 20 entries for debugging.
  6. Captures errors via wp_mail_failed and stores them in a short-lived transient for display on the settings page.

Key Constants

Constant / Class Constant Value Purpose
QUICK_SMTP_VERSION 1.1.0 Plugin version
QUICK_SMTP_FILE __FILE__ Plugin entry file path
QUICK_SMTP_DIR plugin_dir_path(__FILE__) Plugin directory path
OPTION_KEY quick_smtp_settings Settings option key
LOG_OPTION_KEY quick_smtp_email_log Email log option key
LOG_MAX_ENTRIES 20 Max email log entries retained
ENCRYPTION_PREFIX enc:v1: Prefix for encrypted password values

Hooks Used

Hook Type Purpose
init Action Load text domain for translations
admin_menu Action Register settings page under Settings menu
admin_init Action Register settings, sections, and fields
phpmailer_init Action Configure PHPMailer with SMTP settings
wp_mail Filter Log outgoing email details before sending
wp_mail_from Filter Override the From email address
wp_mail_from_name Filter Override the From name
wp_mail_failed Action Capture and store mail errors
admin_post_quick_smtp_test_email Action Handle test email form submission
plugin_action_links_* Filter Add "Settings" link in Plugins list

Security

  • Password encryption: SMTP passwords are encrypted using AES-256-CBC before being saved to the database. The key is derived from wp_salt('auth') via SHA-256, and a random 16-byte IV is generated for each encryption. Encrypted values are prefixed with enc:v1: for identification.
  • Nonce verification: The test email form is protected with wp_nonce_field / check_admin_referer.
  • Capability checks: All admin operations require the manage_options capability.
  • Input sanitization: All settings are sanitized on save using WordPress sanitization functions (sanitize_text_field, sanitize_email, absint, etc.).

Uninstall Behavior

When deleted via the WordPress dashboard, the plugin removes:

  • quick_smtp_settings option
  • quick_smtp_last_error transient
  • quick_smtp_test_result transient

On multisite networks, cleanup runs for every sub-site.

FAQ

Q: Does this work with Gmail? Yes. Use an App Password — your regular Google password will not work.

Q: Is the SMTP password stored securely? Yes. When PHP OpenSSL is available, the password is encrypted with AES-256-CBC using a key derived from your site's authentication salt.

Q: What is "Disable SSL Verification"? It skips certificate validation during the SMTP TLS handshake. Only enable this on local development environments (e.g., XAMPP, Local by Flywheel). Never use on production.

Q: Will my data be removed if I delete the plugin? Yes. All settings and transients are cleaned up on uninstall.

Q: Is it multisite compatible? Yes. Settings are stored per-site using get_option / update_option.

Changelog

1.1.0

  • Added email logging (last 20 outgoing emails)
  • Added wp_mail filter hook for pre-send logging

1.0.0

  • Initial release
  • SMTP configuration via Settings page
  • AES-256-CBC password encryption
  • Send Test Email with live SMTP debug capture
  • From Email and From Name pre-seeded from site settings
  • Disable SSL Verification option for local environments
  • Translation-ready

License

GPL-2.0-or-later — see LICENSE.

Author

Suchandan Haldar