Synthetic Industry

Job wordpress-form-notifications-smtp-authentication · revised 11 October 2026

Make your WordPress form notification emails arrive, through authenticated sending

Set up authenticated sending for up to three forms on one WordPress site, so notification emails come from your domain, and prove each one reaches the agreed mailbox.

You might be seeing

  • The form shows a success message but no email arrives
  • Notifications land in the spam folder or arrive hours late
  • Only some forms or some recipients receive anything
  • A test email from an SMTP plugin works, but the form notifications do not

No passwords, keys, card details or admin invites needed to start.

What usually happened

WordPress sends form notifications through a wrapper that hands the message to the server's mail function unless something else is configured. Hosts limit or block that route, the default sender address often does not belong to your domain, and receiving systems check whether your domain authorises the sender. A form can accept an enquiry while the notification fails, goes to junk or never leaves the server.

Who it’s for: Owner of a WordPress site whose contact, quote or booking form says "sent" but whose notifications do not reliably reach anyone.

Usually starts when: Customers say they filled in the form and heard nothing, enquiries are only some of what is expected, or the host has limited outgoing mail from websites.

The result: Each agreed form sends through an authenticated mail service with a sender on your own domain and the visitor as reply-to. After your site holder applies the change, a marked test from each form reaches the agreed mailbox, and we record the sender checks and whether it landed in Inbox or Junk.

Check whether this job fits

A few short questions. Your answers stay on this page unless you choose to email them.

Is the site built on WordPress, with the form made by a WordPress form plugin?
After a test submission, can you see the entry saved inside the form plugin or in a log?
Have you checked the spam folder and any quarantine page of the receiving mailbox?
Is the form's From address on your own domain?
Can someone add DNS records for your domain?

Answer the questions to see whether this job fits.

Nothing is sent anywhere until you choose to email us.

Send an enquiry about this outcome

Checks you can run yourself

  1. Send a marked test and read its headers

    Submit the form with a recognisable test message, then open the received message's original source or headers view in your mail program.

    Look for: Lines starting "Authentication-Results" or "Received-SPF" and "DKIM-Signature" showing pass or fail for your domain. Share only those lines, not the whole message.

  2. Read the form's notification settings

    Open the form in the WordPress admin, find its notification or email settings and note the To, From and Reply-To fields.

    Look for: A From address on a different domain from your website, the same address in To and From, or a notification switched off by a condition.

What you get

  • The configuration as settings steps for your site holder, with the exact fields to fill
  • Header results for one test message per form, with the SPF and DKIM outcomes recorded
  • A short note of where sending failures are logged and how to read them
  • The list of DNS records the mail service asks your domain holder to add, written out ready to enter
  • Steps to undo the change

Included

  • Up to three forms built with one form plugin on one single WordPress site
  • Configuring authenticated sending with a mail service you choose and hold: your mailbox provider's SMTP or a transactional email service in your name
  • Setting the sender address and name, and the visitor's address as reply-to, in each form's notification
  • Checking each form's notification settings: recipient, conditions and anything that blocks sending
  • Capturing the message headers of one test per form and reading the sender checks

Not included

  • Custom PHP or non-WordPress sites: the custom-PHP form job covers those
  • Editing your DNS records: your domain holder enters them, we supply the values
  • Fixing spam filtering for staff mailboxes or other tools
  • Newsletters, bulk email or marketing automation
  • Spam submissions to the form: that is a separate job
  • Building or redesigning forms
  • Multisite networks, which are quoted separately

How we know it’s done

Agreed with you before work starts. Each check produces evidence you keep.

  1. On staging, one test submission of each agreed form produces exactly one captured message with the agreed sender, the visitor's address as reply-to and the right recipient

    Evidence: Captured messages with headers, one per form

  2. After your site holder applies the settings, a marked test from each form reaches the agreed mailbox without a sending error

    Evidence: Your mailbox screenshot and the received message headers, with SPF and DKIM results recorded and Inbox or Junk noted

  3. With the sending password deliberately wrong on staging, the failure is written to a log we can read and, where the plugin keeps entries, the entry is still saved

    Evidence: The log line and the saved entry from the test

  4. Each form's notification has a single recipient field value and no condition that blocks it, as listed in the settings record

    Evidence: A list of each form's To, From and Reply-To values with secrets removed

Sign-off. You sign off after the staging checks pass and your site holder confirms a marked test from every agreed form reaches the mailbox.

If it fails. If the checks do not pass, you do not pay, and you keep our findings about how the forms send today.

When it fits, and when we stop

It fits when

  • A WordPress site where the form plugin sends through WordPress's normal mail function
  • You hold, or will open in your own name, a mailbox or a transactional email account that supports authenticated SMTP or an API
  • Your domain holder can add DNS records, or you tell us who can
  • Someone can apply settings in the live admin, or your host will, and a staging copy exists for the test

We stop and tell you if

  • The form does not accept or save submissions at all: that is a form fault, not a sending fault
  • The mail provider has suspended or blocked your account
  • The form sends to hundreds of recipients or works as a newsletter
  • Nobody can change the domain's DNS records
  • The notifications are sent by an external service the form plugin calls, not by WordPress

What could go wrong

The change is a set of plugin settings and one SMTP configuration, listed in the handover. Your site holder can switch back to the previous sending method and restore the old notification fields at once.

Scroll the table sideways to read it all.

RiskHow we handle it
Testing sends emails to real customersOn staging all outgoing mail is captured. Live tests use a marked message to your own agreed mailbox only.
The sending password or API key ends up in our notes or in emailYour site holder enters it directly in the plugin or a protected configuration file; we never receive it.
Wrong DNS records make things worse for other mail from your domainWe write each record out for your domain holder to review, and say which existing records must be kept or merged rather than replaced.
Delivery to Inbox cannot be guaranteedWe record actual results and say plainly if a receiver still junks the message for reasons outside the form.

A second reviewer checks that no sending secret appears in notes, that the sender fields are on your domain, and that the header results match what the steps claim.

How we deliver

We arrange the work and independent review, then show you the result against the agreed checks. You keep authority over your systems.

  • Read the form notification settings and the site's current mail path from a captured test on staging
  • Choose the sending route with you and list the DNS records the service needs
  • Configure authenticated sending and the sender and reply-to fields for each form on staging, with outgoing mail captured
  • Test each form with made-up data, including a deliberately wrong password to see how failure is logged
  • Independent review of the settings, where secrets are stored and the header results
  • Hand over the steps; your site holder applies the settings live and each form is tested to your mailbox

This is a one-off job, not emergency cover or a subscription. We confirm eligibility, the total price, a start window and a delivery date before you accept. Work starts only after agreed inputs, secure access, any licences and necessary permissions are in place. Hosting, plugin licence and supplier charges are excluded unless the written quote includes them. No charge or booking is created by an enquiry.

Need to keep it working?

Discuss a monthly test of every form so a silent failure is found early.

Ongoing work is separately scoped and quoted: no monitoring, response-time guarantee or automatic subscription is included in this job.

Explore an ongoing engineering lane, or mention the responsibility you need in your enquiry.

What you can check

This is a new service. We have not delivered this job for a client yet.

Other ways to get this done

  • If you only need messages to reach you, a hosted form service that emails each submission can replace the form without touching WordPress's mail setup.
  • Your mail provider or transactional email service usually publishes its own WordPress setup guide; if you are comfortable with DNS and plugin settings, the steps are often short.

Questions

Do you need my email password?

No. Your site holder enters the sending details in the plugin settings. A transactional email account in your own name works if you prefer not to use your mailbox.

Will I get back the enquiries that went missing?

Only if the form plugin saved them. If it did, we show you where; if it did not, they are gone and we say how to avoid that next time.

Does this cost anything every month?

Your mailbox plan may already include SMTP sending. A transactional email service may charge for usage; check its current price before you choose it.

Our staff email also goes to spam. Is that included?

No. This job fixes the form notifications only. Staff mail and domain-wide records are the separate email authentication job.

Send an enquiry

Send us

  • The address of the page with each form (up to three) and the form plugin's name
  • Who provides your email and your domain's DNS: Google Workspace, Microsoft 365, your host or another provider
  • The address that should receive the notifications and whether it is on your own domain
  • When notifications last arrived and what changed around then
  • Whether the form plugin saves entries you can see in the admin

Later, once you agree

  • A staging copy shared the way you choose, or a time with your site holder to apply settings
  • The sending details of your mail service, entered by your site holder into the plugin's settings and never emailed to us
  • A named person who can add DNS records
  • A company-controlled secure handoff agreed before access: no live passwords, keys, private code or customer records by ordinary email.

You keep the hosting, mailbox, DNS and mail-service accounts in your name. We prepare and test the configuration; your site holder enters sending passwords and API keys, and your domain holder adds DNS records.

A public HTTPS link only, without login details, query strings or fragments. No code or logs.

Sending emails your enquiry and contact address to our team through our mail provider (Resend). It is not kept in a website database. Do not send passwords, keys, recovery links, confidential code or customer records. Your contact email is unverified; nothing is ordered, charged or reserved. Privacy notice.

Email fallback: open your mail app

If website submission is unavailable, review and send the fallback email yourself. An email fallback is not a website receipt. Or write to hello@syntheticindustry.ai with “wordpress-form-notifications-smtp-authentication” as the subject.