A success message may prove only the first boundary
A browser can report submission success before a background job or mail server completes delivery. PHP explicitly says mail() returning true means accepted for delivery, not that it reached the recipient. Separate the form request, application processing, provider acceptance and destination result.
- Use one agreed synthetic submission with a traceable identifier.
- Check existing application and provider errors with the account holder.
- Inspect the controlled recipient's spam folder and redacted headers without exporting customer messages.
Check identity and transport independently
Confirm the configured sender and recipient without sharing secrets. A website, mailbox host and transactional provider may differ. Authentication records should match the actual authorised sender; adding arbitrary SPF or DKIM values is not a general mail repair. A queue failure needs worker evidence, while a provider rejection needs its redacted response.
- Do not use the visitor's address as an untrusted From header.
- Review header input sanitisation; PHP warns about injected headers.
- Use a fixed permitted sender and an agreed reply path.
Testing can send real mail
Only use a recipient and test route approved by the account holder. Repeated form submissions can create bookings, CRM records or notifications even when no email appears. Isolate those effects and verify whether the earlier request already created a record before retrying it.
- No passwords, SMTP keys or message contents in a first enquiry.
- Do not add debug output to the public form.
- Check that invalid or incomplete inputs fail safely.
Acceptance result
One synthetic request should reach the agreed controlled destination with the expected fields, and the application should expose a controlled failure when transport is unavailable. Keep identifiers and redacted results at each boundary. This tests the named form flow, not guaranteed inbox placement for every future recipient.
Sources and limits
- PHP: mail function Checked 2026-10-10.
- A true mail() return means accepted for delivery, not guaranteed receipt.
- Outside data used in headers must be sanitised to avoid header injection.
- Microsoft: email authentication Checked 2026-10-10.
- Authentication does not guarantee destination delivery.