Skip to main content

Deliverability · Beginner · 20 minutes

How to send email from WordPress reliably — The From Address Is a Claim About a Name You Own

A form notification that never arrives is not a broken form. It is a message claiming your domain that nothing in your zone authorised anybody to send.

The short answer

WordPress sends through PHP's mail function by default, which means unauthenticated mail leaving a web server while claiming an address at your domain — exactly the pattern receiving servers trust least. The fix is to route everything through a real mailbox on the name you hold, so that the From address matches something your SPF record and DKIM signature actually cover. Allow 20 minutes; the work is beginner level.

The detail that decides it is alignment. The address WordPress puts in From: has to be at the same domain as the mailbox doing the authenticated sending, or the mail authenticates for somebody else's name and fails yours.

By the Hosting & Domains team · Reviewed 24 August 2026

Beginner

Level assumed

20 minutes

Time to allow

5

Stages to work through

24/7

Desk hours

What you need: control of the name, access to whichever panel holds its zone, and 20 minutes. Every instruction is written against cPanel as we run it, and carries over to any standard cPanel account unchanged.

Nothing on this page is a one-way door. Where a change carries a clock with it — a cache timer, a registry lock, a renewal date — the page says so before you act rather than afterwards.

What the default actually does

PHP's mail function hands the message to the web server's local mail transport and it goes out with nothing signed and nobody authenticated. The From: header still says you@yourdomain, which is a claim about a name, made by a process that never proved it had any right to make it.

Filters treat that pattern as what it usually is. Nothing bounces, nothing errors, and the enquiry simply never appears — which is why silent mail failure is measured in enquiries you never heard about rather than in error messages you can go and read.

Send as the site's own name

Create a mailbox — wordpress@yourdomain is the conventional choice — in cPanel, and feed its SMTP settings to an SMTP plugin such as WP Mail SMTP or FluentSMTP. Outbound mail then travels authenticated, aligned with the SPF record you published for the domain, and signed by the DKIM selector at that name.

The repair reaches every plugin on the site without any of them being aware of it. Contact forms, WooCommerce order emails, password resets and admin notices all go through the same route once it is configured.

From is the name, Reply-To is the human

Put the authenticated mailbox in From: and the enquirer's own address in Reply-To:. Deliverability needs the From address to align with the domain doing the authenticating; conversations need replies to reach the right person. That pattern satisfies both without compromise.

Form plugins configured to send as the visitor are the classic version of this mistake. The message claims a domain nobody in your zone can authorise, from a server the visitor's own provider has never heard of, and it goes precisely where you would expect.

When the site's name and the sending name differ

Staging subdomains, sites mid-rebrand and multisite installs all end up sending from one name while claiming another. The authentication then belongs to a domain the From: header is not using, and DMARC alignment fails even though every individual check looks correct.

Decide which name the mail belongs to and make everything match it. A staging copy should send as the staging hostname or not at all; a rebranding site should move its sending mailbox to the new name at the same moment the site does.

Mail landing at an address that carries the domain rather than a free provider

Where the account does this part for you

Guides written against a hypothetical registrar age badly. These were written at the same zone editor, client area and deliverability screen your own account opens on.

Support is a person at any hour, and the remit runs to the awkward practical questions: a stuck transfer, a record that will not resolve, a bounce nobody can account for.

  • Written against the account you will actually open
  • Organised by the name, not by the server
  • Anything with a clock on it called out up front
  • Help at any hour, mid-walkthrough included

Why Hosting & Domains

Standard on every plan

The silent failure, named first

The mistake this task actually produces is described before step one, which is how 20 minutes stays 20 minutes.

The parts the account already handles

Certificates, daily copies and application installs look after themselves, so the page only covers what is genuinely yours to decide.

The way back, printed beside the way in

Anything carrying a clock or a lock is marked, together with exactly how to reverse it.

Written out of the ticket queue

These pages exist because the same questions kept arriving. Every warning on them is one somebody has genuinely needed.

Checked at the panel, not imagined

Every instruction was carried out on the platform we run, against a name delegated to our own nameservers. No 'your provider may differ' hedging.

Stages, not padding

Each stage is a few minutes of careful clicking, and the parts that genuinely need care are marked as such.

Quick Start

Order placed to site online

  1. 1

    Create a mailbox at the name the site actually uses

    wordpress@yourdomain in cPanel, on the same domain the site is served from. Everything downstream depends on this address being at a name your zone already authenticates for.

  2. 2

    Install an SMTP plugin and point it at that mailbox

    WP Mail SMTP or FluentSMTP intercepts everything WordPress produces and sends it through authenticated SMTP instead of PHP's mail function. One configuration covers every plugin on the site.

  3. 3

    Set the From address to match the authenticated name

    The address in From: must be at the same domain as the mailbox doing the sending. This is the step that turns 'SPF passes' into 'DMARC aligns', and it is the one most often skipped.

  4. 4

    Put the enquirer in Reply-To, not in From

    Replies then reach the person who wrote in, while the message itself keeps claiming a name it can prove. Form plugins that send as the visitor are the standard cause of notifications that never arrive.

  5. 5

    Test to an outside mailbox and read the headers

    The plugin's test message should reach a real external inbox showing spf=pass and dkim=pass in Authentication-Results, with d= naming your own domain. Testing to an address on the same server proves nothing at all.

Built In

Fitted to every plan

  • Staging copies, for trying a change before the live name sees it
  • A daily copy of the account, restored from the panel by you
  • 99.9% uptime as the target, watched around the clock
  • Mailboxes that answer at the name you hold
  • WordPress Toolkit, with the updates seen to for you
  • Your existing site brought across by our engineers at no charge
  • Free SSL on every plan, reissued before the old certificate lapses
  • Softaculous bundled, for one-click application installs
  • No set-up charge at any point, and no joining fee
  • LiteSpeed caching built into the server rather than bolted on by plugin

Frequently Asked

Questions we field again and again

The site runs on a staging subdomain. Will its mail authenticate?

Only for the name it is actually sending as. A staging copy at staging.yourdomain sending with a From: address at yourdomain will fail alignment, because the authenticated mailbox and the claimed name do not match. Either give staging its own sending identity, or switch its mail off entirely until it goes live under the real name — which is usually the better answer.

Contact form notifications arrive but order confirmations do not. Why?

Almost always because the two are sending as different addresses. The form plugin has been configured with the mailbox you set up, and WooCommerce is still using its own From address from before the change — often admin@ something, or the site's default. Check the From address on every sending component rather than assuming the SMTP plugin covered them all.

Can I set the PHP release separately for each of my sites?

Yes — PHP is set per name from the control panel, so a legacy application and a current one can run side by side inside one account. Extensions and per-site tuning sit on the same screen, and none of it needs a support ticket.

If I cancel, do I keep the names and the files?

You do. Download a full copy from the panel whenever you like, before or during cancellation. Names stay registered in your name for the term you paid for, and can move to any other registrar once the standard 60-day window has passed.

Keep reading

  • WHMCS License

    Automate billing, provisioning and support for hosting clients of your own.

  • Agency Hosting

    Client accounts, staging and care-plan infrastructure arranged for agencies.

Changing provider? Work through this checklist beforehand.

A straightforward running order for a migration your visitors never spot: which files travel first, how to bring the mail across without dropping a single message, the right moment to repoint DNS, and the two errors that sit behind almost every outage we get called in to fix.

You get the checklist, followed now and then by a note on keeping a site responsive. Unsubscribe whenever you want; the privacy policy covers the rest.

Get the name under proper control.

NVMe hosting with the certificate and the migration included, people answering at any hour, and a renewal figure that does not move.

View WHMCS License plans