Skip to main content
HostingSeller
Shop plans

Reseller playbook · Beginner · 20 minutes

How to send email from WordPress reliably — The Care-Plan Failure Nobody Reports Until It Has Cost Them

A client whose enquiry notifications quietly stopped arriving does not raise a ticket — they conclude the site does not work and start looking elsewhere.

Straight answer first

Route every client site's mail through authenticated SMTP on a mailbox at their own domain, because the default PHP mail path sends unauthenticated from the web server and that is precisely the pattern inbox providers trust least.

Twenty minutes fixes one site. The thing that protects your care plan is doing it identically on all of them and putting a monthly delivery check into the routine, so a silent failure is found by you rather than by the client's missing enquiries.

Written by the Hosting Seller staff · Checked 24 August 2026

Beginner

Skill assumed

20 minutes

Per client site

5

Stages to a pattern

24/7

Cover for you and them

Written for whoever maintains a shelf of client WordPress sites. It assumes you did not build all of them, that some carry forms you have never tested, and that you will be blamed for anything that stops arriving.

This is the cheapest reliability work available on a managed fleet. It is also the most commonly skipped, because a site that fails this way looks perfectly healthy from the outside.

The complaint that arrives as churn, not as a ticket

When a contact form notification dies on the way out, nothing appears broken. The form submits, the visitor sees a thank-you, and the enquiry evaporates. Weeks later the client mentions that the website 'never really brought anything in' and declines to renew — and there is no ticket in your helpdesk to point at.

That makes this a commercial problem wearing a technical hat. The measurable cost is not support time; it is the retainer that quietly ends, and the reference you do not get.

One pattern, applied to every site you manage

Pick a single SMTP plugin and use it on every site rather than inheriting whatever each build happened to include. Consistency is worth more than the marginal differences between the popular options, because the value here is that you can check thirty sites the same way and train somebody else to do it.

Document the pattern once: which plugin, which mailbox naming convention, which from-address, which reply-to behaviour. Then it becomes something a junior can implement on a new site correctly, and something you can audit without opening each dashboard and thinking from first principles.

Whose mailbox does it authenticate as?

Create a mailbox on the client's own domain — wordpress@clientdomain is the obvious convention — and authenticate as that. Sending as a mailbox on your agency domain works technically and looks wrong in a header, and it means every client site on your shelf shares one reputation and one password.

Set the from-address to that authenticated mailbox and put the enquirer's real address in reply-to. Deliverability wants alignment with the sending domain; the client wants to hit reply and reach the customer. That pattern gives both, and it is the single most common thing done backwards.

The monthly check that belongs in the care plan

Once a month, submit the live contact form on each site you manage and confirm the notification arrives at an outside mailbox. It is tedious and it is the whole point: this failure is silent, so the only defence is a scheduled test rather than an alert that will never fire.

The platform helps with the parts around it. Mailboxes on the client's own domain come with the hosting, spam and virus filtering is fitted as standard, and daily backups run across every client account, so what remains is the ten minutes a month that proves the plumbing still works.

A business mail inbox open on a laptop

Why this is standard work on a reseller account

Mailboxes on the client's own domain are part of every hosting account, so the authenticated sender this job needs already exists rather than being an extra you have to buy.

One-click installs cover WordPress and 400+ other applications, and WordPress Toolkit keeps updates applied, which leaves your attention on the parts that fail quietly.

  • One SMTP pattern across the whole fleet
  • Sending as the client's domain, not yours
  • From and reply-to set the right way round
  • A monthly test, because nothing will alert you

Why Hosting Seller

On every plan, as standard

Framed as retention

Treats a silent form failure as churn rather than a support ticket, because that is where it actually costs.

One pattern, thirty sites

Standardises the plugin, the mailbox convention and the addresses so the fleet can be audited quickly.

Delegable to a junior

Documented enough that somebody else can implement it correctly on a new client build.

The header, done right

Sends as the client's own domain with reply-to pointing at the enquirer, which is the usual mistake.

A scheduled test

Puts a monthly live-form check into the care plan, since this failure never raises an alarm.

The mailbox is already included

Mailboxes on the client's own domain ship with the hosting, so the authenticated sender costs nothing extra.

First Steps

From choosing to live

  1. 1

    Understand why the default route fails

    WordPress uses PHP's mail function, which sends unauthenticated straight from the web server. That is the pattern filters trust least, and no amount of plugin configuration fixes it while the mail still leaves that way.

  2. 2

    Create the sending mailbox on the client's domain

    A mailbox in the client's own cPanel, named to a convention you use everywhere. Sending as your agency domain from their site works but reads wrong to a filter and pools every client's reputation into one.

  3. 3

    Install the same SMTP plugin you use everywhere

    One choice, applied across the fleet, with the settings recorded. Every other plugin on the site inherits the fix without knowing about it, which is why this single change covers forms, orders and password resets at once.

  4. 4

    Set from-address and reply-to deliberately

    From: the authenticated mailbox, so SPF and DKIM align. Reply-to: the enquirer, so the client can answer without copying an address out of the message body.

  5. 5

    Prove it against an outside mailbox, then diary the recheck

    Submit the real form and read the headers on delivery: spf=pass and dkim=pass. Then put the same test in the monthly care-plan routine, because the failure gives no warning of its own.

In the Box

Packed with every plan

  • Mailboxes on the client's own domain, included
  • One-click installs for WordPress and 400+ other applications
  • WordPress Toolkit, with updates applied for you
  • Staging copies so client changes are tested before going live
  • Daily backups across every client account
  • Spam and virus filtering fitted to every mailbox
  • LiteSpeed caching at the server, not bolted on by plugin
  • Free SSL on every client site, reissued before it lapses
  • WHM for you, a cPanel of their own for every client
  • Real people answer, for you and for them

Across the Counter

Things people ask us all the time

Should the SMTP mailbox belong to me or to the client?

The client. Create it in their own cPanel on their own domain, so the message aligns with the domain it claims to be from and one compromised credential cannot touch anybody else's site. A shared agency mailbox across a fleet pools reputation and risk in the same place.

How do I check thirty client sites are still sending?

Submit the live form on each one and confirm arrival at an outside mailbox, monthly, as a scheduled task. There is no alert for this failure — the form succeeds and the mail evaporates — so a boring recurring test is the only real defence.

Does the same setup cover WooCommerce order emails?

Yes. The SMTP plugin captures everything WordPress sends, orders included. When a client's volume grows, point the same plugin at a dedicated transactional service: the configuration pattern does not change, the sending infrastructure simply gets stronger.

Who am I actually buying from?

Hosting Seller is a trading name of IGI Security Services Ltd, a company registered in England and Wales, with terms published under English law. Checking that is worth doing about any supplier before you build a client list on top of them.

Read next

  • WHMCS License

    Bill, provision and support your own hosting customers automatically.

  • Agency Hosting

    Client accounts, staging and care-plan plumbing built for agencies.

Moving your site to another host? Start with this checklist.

A step-by-step order of work for a move your visitors never spot: which files to copy first, how to carry email across without losing one message, the right moment to repoint DNS, and the two mistakes behind nearly every hour of downtime people ring us about.

One email brings the checklist, then now and again a note about running a site properly. Leave the list whenever you feel like it. Our privacy policy spells out the rest.

Run a care plan you can defend.

Mailboxes on the client's domain, staging copies, daily backups per account and support that answers them too.

See WHMCS License plans