Here’s the direct answer to how to fix WordPress not sending emails: WordPress sends mail through wp_mail(), which relies on PHP’s mail() function — unauthenticated, untrusted by Gmail and Outlook, and quietly blocked by many hosts. The fix is to route outgoing mail through an authenticated SMTP service instead. Install WP Mail SMTP, connect it to a real mailer (Brevo’s free tier handles 300 emails a day), enable Force From Email, add your SPF, DKIM, and DMARC records, and verify with a test send.
That sounds like a lot, but it takes about 20 minutes and permanently solves one of the most common WordPress problems. Let’s go step by step.
Why WordPress emails fail in the first place
WordPress needs to send email constantly: contact form notifications, password resets, WooCommerce order confirmations, comment notifications, update alerts. Out of the box, it does this with the PHP mail() function, which was designed in a gentler era of the internet. It sends messages with no authentication attached — no proof the email actually came from your domain.
Modern mail providers treat unauthenticated mail as guilty until proven innocent. Gmail and Outlook either dump it in spam or reject it silently. Meanwhile, many hosting providers block or throttle outbound mail() entirely because compromised WordPress sites historically used it to blast spam. The result: your site thinks it sent the email (no error anywhere), your visitor never receives it, and nobody tells you.
This got worse over time. Google removed less-secure-app access, tightening what counts as a legitimate sender, and mailbox providers have been steadily raising their authentication expectations through 2026. If your emails worked five years ago and stopped, authentication tightening is the most likely reason.
Pre-flight checks: do these first
Before you touch any settings, rule out the easy stuff — these resolve a surprising number of cases:
- Check the spam folder. Send a test (use the password reset on your own account) and check spam on the receiving end. If it’s there, the problem is authentication, not delivery — and the SMTP fix below still applies.
- Verify the admin email. Go to Settings → General in your WordPress dashboard and confirm the Administration Email Address is correct and actually monitored.
- Check the form’s “To” address. If only contact form emails fail, open the form plugin’s notification settings and confirm the recipient address. A single typo here mimics a site-wide mail failure.
- Test the password reset. If your site’s own password-reset email fails too, the problem is server-wide (your host’s mail path), not the form plugin. That confirms you need SMTP.
- Disable other mail plugins temporarily. Only run one SMTP/mail plugin at a time — two plugins fighting over
wp_mail()will break each other. If you have any old mail-related plugins, deactivate them before continuing.
Step 1: Install and configure WP Mail SMTP
WP Mail SMTP is the standard fix here, with over 4 million active installations — you can find it on the official WordPress plugin directory. (FluentSMTP, with 700,000+ installs, is a solid free alternative — the concepts are identical either way.)
- Go to Plugins → Add New, search “WP Mail SMTP”, install and activate it.
- The setup wizard launches automatically. Choose your mailer (step 2 below covers the options).
- In WP Mail SMTP → Settings, set the From Email to a real address on your domain — something like
info@yourdomain.comorhello@yourdomain.com. Do not use a Gmail address here; the From domain should match your website. - Set the From Name to your site or brand name.
- Turn on Force From Email and Force From Name. This is the setting most people skip, and it’s the one that stops themes and plugins from quietly overriding your address with an unauthenticated one. WordPress’s own documentation recommends the From domain match your website to avoid spam filtering.
In your contact form plugin, map the visitor’s submitted email address to the Reply-To field rather than the From field. Hitting “reply” will still reach the visitor — but the message itself goes out from your authenticated domain address.
Step 2: Connect a mailer
This is where you choose the actual email service. For most sites, one of these three is the right answer:
Brevo (free tier: ~300 emails/day). The best free option for small sites and blogs. Sign up at Brevo, verify your domain in their dashboard (they give you the DNS records — covered in step 3), then grab your SMTP credentials or API key and paste them into WP Mail SMTP’s Brevo mailer settings. Three hundred sends a day covers contact forms, comment notifications, and password resets comfortably.
SendLayer or similar transactional services. If you’re running a store or membership site sending dozens of transactional emails daily, a dedicated transactional provider with delivery logs is worth the small monthly cost. You get per-message tracking, which makes debugging painless.
Gmail via app password. If you want mail to come from your actual Gmail account, WP Mail SMTP supports Google’s OAuth connection. Important: Google retired less-secure-app access, so your normal Google password will not work for SMTP. Enable 2-Step Verification first, then generate an app password (Google Account → Security → App passwords) and use that as the SMTP password — otherwise authentication fails with a 535 error.
Which to pick? Brevo for most blogs and brochure sites. A transactional service like SendLayer for stores. Gmail only if your volume is tiny and you specifically want sends to come from your personal Gmail.
Step 3: Publish SPF, DKIM, and DMARC records
Connecting the mailer isn’t enough — receiving servers also check whether your domain authorized the mail. That’s what these three DNS records do. Your mail provider gives you the exact values; you add them wherever your domain’s DNS is managed (your host, Cloudflare, or your registrar).
- SPF (Sender Policy Framework): a single TXT record listing which servers are allowed to send mail for your domain. Rule: a domain must have exactly one SPF record. If you already send through other services, merge them into the one record — two SPF records cause failures.
- DKIM (DomainKeys Identified Mail): a public key published as a DNS record. Your provider signs every outgoing message with the matching private key, and receivers verify the signature. In Brevo’s dashboard this is under domain authentication; copy the records they give you.
- DMARC: a TXT record at
_dmarc.yourdomain.comthat tells receivers what to do when SPF/DKIM checks fail. Start withp=none(monitor mode) — this is explicitly allowed under Google’s sender rules and lets you collect failure reports before you enforce anything stricter.
After adding records, allow time for DNS propagation (usually minutes to a few hours), then test. Missing or wrong DNS records are the #1 cause of the “SMTP connects fine but mail lands in spam” complaint — the connection fix and the authentication fix are two separate problems.
Step 4: Test and verify delivery
Don’t trust the settings screen — verify actual delivery:
- In WP Mail SMTP → Tools → Email Test, send a test to an address you control. Confirm it arrives in the inbox, not spam.
- Run a score check at mail-tester.com — send to the address it gives you and review the report. It flags SPF, DKIM, and spam-content issues in plain language.
- Submit your own contact form and reply to the notification, confirming the Reply-To works end to end.
- If your site uses WooCommerce, place a real test order (you can refund it immediately) — order confirmations are the email type stores lose the most money on.
If the test fails, the error message tells you where to look:
- 535 authentication errors: wrong password (check for pasted whitespace or line breaks), stale credentials cached in
wp-config.phpconstants overriding the UI, or a Gmail login without an app password. - Connection timeouts: your host is blocking the outbound SMTP port. Try port 587 with TLS first, then 465 with SSL. If both fail, ask your host to unblock outbound SMTP — or switch to an API-based mailer (Brevo’s API option) that doesn’t need the SMTP port.
- Accepted but never arrives: check spam first, then verify DNS records are actually published (use a DNS lookup tool), confirm Force From Email is on, and check the provider’s suppression list — a previous bounce on that address can suppress future sends.
During debugging, enable WP Mail SMTP’s email logging so you can see exactly what was sent and what the server said back. Turn verbose logging off once you’re done — you don’t want message bodies piling up in your database forever.
Keeping it healthy: the monthly 5-minute check
Email delivery isn’t a set-and-forget forever. Once a month, submit your contact form and confirm the notification arrives — a silent form costs you leads without any warning. Glance at WP Mail SMTP’s email log for failed sends. And if you change hosts or add another email service, re-check your SPF record: one change there can silently break everything else.
Frequently Asked Questions
Why did WordPress stop sending emails when it used to work?
Most commonly because authentication requirements tightened. WordPress’s default PHP mail() sends unauthenticated messages; as Gmail, Outlook, and hosts have cracked down on unauthenticated mail through 2025–2026, messages that used to slip through now get filtered or blocked. Routing through an authenticated SMTP mailer fixes it permanently.
Which SMTP plugin should I use for WordPress in 2026?
WP Mail SMTP (4M+ active installs) is the most widely used and documented. FluentSMTP (700,000+) is a capable free alternative. Either works — just use one, never two simultaneously.
What are SPF, DKIM, and DMARC in simple terms?
SPF is a DNS list of servers allowed to send mail for your domain. DKIM is a cryptographic signature proving the message wasn’t tampered with and came from your provider. DMARC tells receiving servers what to do when those checks fail. All three live in your DNS settings, and your mail provider gives you the exact records to add.
Can I use Gmail to send WordPress emails?
Yes, via WP Mail SMTP’s Gmail mailer — but you cannot use your normal Google password. Google retired less-secure-app access, so enable 2-Step Verification and generate an app password (Google Account → Security → App passwords), then use that as the SMTP credential.
Why do my WordPress emails go to spam instead of the inbox?
Usually one of three things: no SPF/DKIM/DMARC records published, the From address is on a free provider (Gmail/Yahoo) instead of your own domain, or Force From Email is off and a plugin is sending from an unauthenticated address. Fix all three and re-test with mail-tester.com.
Sources: WordPress not sending emails? How to fix it (2026), How to fix WordPress not sending emails (October 2026)
