Mesh SMTP – Easy WordPress SMTP &
Mesh SMTP is a lightweight WordPress SMTP plugin for website owners who want a clear way to configure outgoing email without a crowded dashboard. Connect WordPress to Gmail, Google Workspace, Microsoft 365, Zoho Mail, Hostinger Email, SendGrid, Mailgun, or any custom SMTP server. The guided setup explains each field in plain language and separates mailer acceptance from real inbox delivery. Mesh SMTP works with email sent through WordPress wp_mail(), which commonly includes: Contact form notifications Password reset emails New user and administrator notifications WooCommerce transactional emails WordPress update and security notifications Messages sent by compatible themes and plugins Easy 3-Step WordPress SMTP Setup Choose your email provider from simple provider cards. Enter the SMTP connection details with clear host, security, port, authentication, username, password, and sender guidance. Send and confirm a test email so the dashboard does not claim delivery before you verify the inbox. Main Features Simple three-step SMTP setup wizard Provider presets for Gmail, Microsoft 365, Zoho, Hostinger, SendGrid, and Mailgun Custom SMTP support with optional authentication for trusted relays Test email flow with honest Accepted, Received and Confirmed, Failed, and Retest Required states Automatic test invalidation when SMTP settings change Clear SMTP host, TLS/SSL, port, authentication, username, password, From Email, and From Name fields Recommended port guidance without overwriting a custom port Saved password indicator with a dedicated Remove Saved Password action Warning when another common SMTP plugin appears active Microsoft 365 warning when OAuth or tenant SMTP AUTH policy may be required Privacy-first email logging: Off, failures only, or all mailer results Optional masked, hidden, or full recipient storage Optional subject logging and 7, 14, or 30-day retention Clear Logs and Clear Last Failure actions Masked support summary by default, with an explicit option to include personal details Safe JSON settings export and import without exporting the SMTP password wp-config.php constants for deployment-managed SMTP credentials WordPress Site Health integration Accessible provider cards, wizard steps, live status messages, and password controls Admin assets load only on the Mesh SMTP screen Capability checks, nonces, sanitization, and escaped output Honest Test Email Results A successful wp_mail() response means WordPress and PHPMailer accepted the sending request without returning an error. It does not prove that the message reached the Inbox. Mesh SMTP therefore uses a two-part verification flow: Accepted by mailer — WordPress returned no sending error. Received and confirmed — an administrator checked the Inbox or Spam folder and confirmed receipt. This avoids a misleading “delivered” message when the receiving mail server may still delay, filter, or reject the email. Privacy-First Email Logs Email logging is configurable. The recommended default stores failed emails only, masks recipient addresses, hides subject lines, and removes old entries after 14 days. Mesh SMTP never stores email bodies or attachments in its activity log. Supported Provider Presets Gmail and Google Workspace Outlook and Microsoft 365 Zoho Mail Hostinger Email SendGrid Mailgun Custom SMTP Microsoft 365 Note Some Microsoft 365 tenants do not allow username/password SMTP. OAuth 2.0 or an administrator-enabled SMTP AUTH policy may be required. Mesh SMTP currently supports standard SMTP credentials and displays a warning when the Microsoft preset is detected. Secure wp-config.php Constants Developers can define these constants in wp-config.php to override values saved in WordPress: MESHSMTP_ENABLED MESHSMTP_HOST MESHSMTP_PORT MESHSMTP_SECURE MESHSMTP_AUTH MESHSMTP_USERNAME MESHSMTP_PASSWORD MESHSMTP_FROM_EMAIL MESHSMTP_FROM_NAME The SMTP password is never shown back in the admin interface.
Top keywords
- smtp23×4.02%
- email15×2.62%
- password10×1.75%
- meshsmtp9×1.57%
- wordpress9×1.57%
- microsoft7×1.22%
- 3656×1.05%
- mesh6×1.05%
- mesh smtp6×1.05%
- microsoft 3656×1.05%
- clear5×0.87%
- mail5×0.87%
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!