For a few messages (a contact form, the confirmations of a small shop), SMTP with a mailbox on your domain is enough. For large volumes, newsletters, or when you need to know what happened to each message, use a sending service through its API. Many of those services offer both routes, so the choice is rarely “one or the other” for ever.
What each route is
SMTP is the protocol of e-mail itself: the application connects to a server with a user name and password and hands over the message. An API is an HTTPS request to a third-party sending service (one you contract separately): the application sends the message data and the service does the rest. Behind the scenes the service also sends by SMTP; what changes is how you hand it the message.
Side by side
| Criterion |
SMTP |
The service’s API |
| How it connects |
Server, port, user name and password. Almost all software knows how. |
An HTTPS request with a key. Needs code, or a plugin that talks to the service. |
| Effort to start |
Low: you fill in a form in the settings. |
Medium: you write code, or install a plugin. |
| What you get to know |
Only whether the server accepted the message. |
Usually also what happened afterwards (delivered, bounced, complaint), through notices the service sends. |
| Volume |
Limited by the mailbox and plan limits. |
Built for large volumes, under the service’s rules. |
| Reputation |
Shares that of your domain and the server. |
Depends on the service and on what you send through it. |
| Where it fits |
WordPress, forms, ready-made programs. See making WordPress send e-mail with SMTP. |
Applications of your own, with heavy sending, or where each message counts. |
How to decide
| 2 |
Do you need proof of delivery? Invoices and receipts by e-mail that the customer must receive justify a route that tells you what happened to each message.
|
|
What does not change on either route
The domain the message comes from must be authenticated. With a third-party service, it gives you SPF and DKIM records to put in DNS. A domain should have only one SPF record: merge the authorisations into the same record, do not create a second. See SPF, DKIM and DMARC.
|
An API key is a password. Whoever has it sends e-mail in your name. Keep it in an environment file, never in public code or in a repository, and replace it if you suspect it leaked. See keeping passwords out of your PHP code.
|
|
Third-party services are contracted separately. We do not sell them; the setup on your side (DNS, plugins, code) is yours, and support explains how far it goes in how far our support goes.
|
|
Not sure whether what you want to send fits in a mailbox? Tell us the kind of messages and the volume.
Open a support ticket
|
RECOMMENDED PRODUCT Professional e-mail on your domain Mailboxes in your company name, no adverts, with spam filtering. from 5.940,00 Kz/mo (3-year plan, with coupon) See plans |