Quick SMTP
Lightweight SMTP mailer for WordPress — configure outgoing email reliably and securely with AES-256 password encryption.
by Suchandan Haldar · github.com/suchandandev09/quick-smtp · website
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/suchandandev09/quick-smtp/archive/refs/heads/main.zipLightweight SMTP mailer for WordPress — configure outgoing email reliably and securely with AES-256 password encryption.
Description
Quick SMTP replaces WordPress's default PHP mail() function with a proper SMTP connection, so your emails actually get delivered and don't land in spam.
Key Features
- Simple settings page under Settings → Quick SMTP
- Supports SSL and TLS encryption
- SMTP password stored encrypted at rest using AES-256-CBC (requires PHP OpenSSL extension)
- From Email and From Name pre-filled from your site settings
- Built-in Send Test Email tool with full SMTP debug log
- Email logging — keeps the last 20 outgoing emails for debugging
- Inline troubleshooting guide for Gmail, Outlook, and other providers
- Clean uninstall — removes all stored data when deleted
- Multisite compatible (per-site settings)
- Translation-ready (
.potfile included)
Compatible Providers
| Provider | Host | Port | Encryption |
|---|---|---|---|
| Gmail | smtp.gmail.com |
587 | TLS |
| Outlook / Microsoft 365 | smtp.office365.com |
587 | TLS |
| Yahoo Mail | smtp.mail.yahoo.com |
587 | TLS |
| Amazon SES | Your SES endpoint | 587 | TLS |
| Mailgun | smtp.mailgun.org |
587 | TLS |
| SendGrid | smtp.sendgrid.net |
587 | TLS |
| Any standard SMTP server | — | — | — |
Requirements
- WordPress 5.9 or higher
- PHP 7.4 or higher
- PHP OpenSSL extension (for AES-256 password encryption; falls back to plaintext storage if unavailable)
Installation
- Upload the
quick-smtpfolder to/wp-content/plugins/, or install directly via Plugins → Add New in the WordPress dashboard. - Activate the plugin through the Plugins menu.
- Navigate to Settings → Quick SMTP.
- Enter your SMTP host, port, encryption type, username, and password.
- Click Save Settings.
- Click Send Test Email to verify the connection.
Configuration
Settings Fields
| Field | Description |
|---|---|
| Enable Quick SMTP | Toggle the plugin on or off. |
| SMTP Host | The hostname of your SMTP server (e.g., smtp.gmail.com). |
| SMTP Port | The port your server listens on (commonly 587 for TLS, 465 for SSL). |
| Encryption | None, SSL, or TLS (recommended). |
| Use Authentication | Enable SMTP authentication with username and password. |
| Username | Your SMTP account username (typically your email address). |
| Password | Your SMTP account password or App Password. Encrypted at rest with AES-256-CBC. |
| From Email | The email address outgoing mail is sent from. Defaults to the site admin email. |
| From Name | The sender name for outgoing mail. Defaults to the site title. |
| Disable SSL Verification | Skips certificate validation during TLS handshake. Only for local/dev environments. |
Gmail Setup
Google no longer allows sign-in with a regular account password from third-party apps. You must:
- Enable 2-Step Verification on your Google account.
- Generate an App Password.
- Use the 16-character App Password in the Password field.
Recommended settings:
Host: smtp.gmail.com
Port: 587
Encryption: TLS
Username: your-email@gmail.com
Password: <16-character App Password>
Outlook / Microsoft 365 Setup
Host: smtp.office365.com
Port: 587
Encryption: TLS
Username: your-email@outlook.com
Password: your account password (or App Password if required)
Development
Project Structure
quick-smtp/
├── quick-smtp.php # Main plugin file (singleton class, hooks, settings, SMTP config)
├── uninstall.php # Clean removal of all plugin data (including multisite)
├── readme.txt # WordPress.org plugin directory readme
├── languages/ # Translation files (.pot/.po/.mo)
│ └── index.php
└── README.md # This file
Architecture
The plugin is built as a single-file singleton class (Quick_SMTP_Plugin) that:
- Registers hooks in the constructor — admin menu, settings API,
phpmailer_init, mail filters, email logging, and the test-email handler. - Stores settings using the WordPress Options API under the key
quick_smtp_settings. - Encrypts the SMTP password at rest using AES-256-CBC via PHP's OpenSSL extension, with the encryption key derived from the site's
AUTH_SALT. - Configures PHPMailer on
phpmailer_initto use the saved SMTP settings instead of PHP'smail(). - Logs outgoing emails via the
wp_mailfilter, keeping the most recent 20 entries for debugging. - Captures errors via
wp_mail_failedand stores them in a short-lived transient for display on the settings page.
Key Constants
| Constant / Class Constant | Value | Purpose |
|---|---|---|
QUICK_SMTP_VERSION |
1.1.0 |
Plugin version |
QUICK_SMTP_FILE |
__FILE__ |
Plugin entry file path |
QUICK_SMTP_DIR |
plugin_dir_path(__FILE__) |
Plugin directory path |
OPTION_KEY |
quick_smtp_settings |
Settings option key |
LOG_OPTION_KEY |
quick_smtp_email_log |
Email log option key |
LOG_MAX_ENTRIES |
20 |
Max email log entries retained |
ENCRYPTION_PREFIX |
enc:v1: |
Prefix for encrypted password values |
Hooks Used
| Hook | Type | Purpose |
|---|---|---|
init |
Action | Load text domain for translations |
admin_menu |
Action | Register settings page under Settings menu |
admin_init |
Action | Register settings, sections, and fields |
phpmailer_init |
Action | Configure PHPMailer with SMTP settings |
wp_mail |
Filter | Log outgoing email details before sending |
wp_mail_from |
Filter | Override the From email address |
wp_mail_from_name |
Filter | Override the From name |
wp_mail_failed |
Action | Capture and store mail errors |
admin_post_quick_smtp_test_email |
Action | Handle test email form submission |
plugin_action_links_* |
Filter | Add "Settings" link in Plugins list |
Security
- Password encryption: SMTP passwords are encrypted using AES-256-CBC before being saved to the database. The key is derived from
wp_salt('auth')via SHA-256, and a random 16-byte IV is generated for each encryption. Encrypted values are prefixed withenc:v1:for identification. - Nonce verification: The test email form is protected with
wp_nonce_field/check_admin_referer. - Capability checks: All admin operations require the
manage_optionscapability. - Input sanitization: All settings are sanitized on save using WordPress sanitization functions (
sanitize_text_field,sanitize_email,absint, etc.).
Uninstall Behavior
When deleted via the WordPress dashboard, the plugin removes:
quick_smtp_settingsoptionquick_smtp_last_errortransientquick_smtp_test_resulttransient
On multisite networks, cleanup runs for every sub-site.
FAQ
Q: Does this work with Gmail? Yes. Use an App Password — your regular Google password will not work.
Q: Is the SMTP password stored securely? Yes. When PHP OpenSSL is available, the password is encrypted with AES-256-CBC using a key derived from your site's authentication salt.
Q: What is "Disable SSL Verification"? It skips certificate validation during the SMTP TLS handshake. Only enable this on local development environments (e.g., XAMPP, Local by Flywheel). Never use on production.
Q: Will my data be removed if I delete the plugin? Yes. All settings and transients are cleaned up on uninstall.
Q: Is it multisite compatible?
Yes. Settings are stored per-site using get_option / update_option.
Changelog
1.1.0
- Added email logging (last 20 outgoing emails)
- Added
wp_mailfilter hook for pre-send logging
1.0.0
- Initial release
- SMTP configuration via Settings page
- AES-256-CBC password encryption
- Send Test Email with live SMTP debug capture
- From Email and From Name pre-seeded from site settings
- Disable SSL Verification option for local environments
- Translation-ready
License
GPL-2.0-or-later — see LICENSE.
Author
Suchandan Haldar