A contact form, an order receipt, a password reset: sooner or later your code has to send an e-mail. The simple function PHP ships with does send, but it sends badly, and the message ends up in the bin of the person who should have read it.
PHPMailer fixes that: instead of leaving the message at the door, it logs into the mail server with a username and a password, exactly as your phone does. The message now has an owner, and an identified owner is half the battle against the spam folder.
Why it is worth the swap
| With the simple PHP function |
With authenticated PHPMailer |
| The message leaves without identifying itself. |
The message leaves in the name of a mailbox that really exists. |
| Errors vanish silently: the code says it sent and nobody receives. |
There is an answer from the server, and you can read it and show it. |
| Attachments and accents have to be hand built, and usually come out wrong. |
Attachments, HTML and accents are handled by the library. |
| The sender can be anything, which is exactly what filters look for. |
The sender matches the domain, which is what SPF and DKIM want to see. |
The settings on this server
Do not copy ports from a random tutorial: they differ from host to host. These are the ones here.
| Field |
Value |
| Outgoing server |
mail. followed by your domain |
| Port |
465 |
| Encryption |
SSL, that is, encrypted from the first moment. In PHPMailer that is the value smtps. |
| Authentication |
On. |
| Username |
The full e-mail address of the mailbox you created in cPanel. Not just the part before the at sign, and not your cPanel user. |
| Password |
The mailbox password. |
| From address |
That same mailbox. Do not put the visitor’s address as the sender: put it in reply to. |
To read mailboxes from code, IMAP is on port 993, also SSL, on the same mail. name of your domain.
|
Create a mailbox just for this, with a name that explains itself, instead of using your personal one. If the password ever has to change, it changes in one place and you do not lose your mail. And if somebody abuses the form, you switch off that mailbox and not yours.
|
How to install it
| 1 |
With Composer, if the project already uses it: one line, and it stays updatable. This is the recommended route.
|
|
| 2 |
Or by hand, downloading the library from the official PHPMailer repository and including the files. It works, but keeping up with new versions becomes your job.
|
|
| 3 |
Where you put it matters. If you get to choose, put it outside the public folder and include it from there. Anything inside the public folder can be requested from the internet.
|
|
| 4 |
Do not write the password into the code. Put it in a separate configuration file outside the public folder and read it from there. See where credentials belong.
|
|
The errors you are going to see
| Message |
What it is |
| SMTP connect() failed |
It never reached the mail server. If the code runs on our server, this is nearly always a mistyped host name or the wrong encryption setting. If it runs on your own machine or at another provider, their network may be blocking outbound mail. |
| SMTP Error: Could not authenticate |
The username is not the full address, or the password is wrong. Test the same mailbox in webmail: if it lets you in, the credentials are fine and the problem is in the options. |
| Certificate not trusted |
You are connecting by IP address, or by a name that is not on the certificate. Use mail. with your domain. Do not switch off certificate verification to silence the error: that throws away the whole protection. |
| It sends, but lands in the recipient’s spam |
The connection is fine and the domain identity is missing. That is SPF, DKIM and DMARC. |
| It reaches some people and not others |
Usually filtering on the receiving side, or reputation. See why your e-mail is not sending or receiving. |
|
Turn debug output on while you are testing. PHPMailer has an option that prints the entire conversation with the server, line by line. The answer is in there, usually with a number attached. Turn it off before the site goes live, or you are showing your passwords to whoever opens the page.
|
|
A form with no brakes is a spam machine waiting to be found. Add a check against robots, never let the visitor choose the recipient, and never copy what they typed into the message headers. An open form ends up sending thousands of messages in your domain’s name, and the price of that is a burnt domain for weeks.
|
On volumes, pacing and lists, the good practice is in how to write an e-mail that does not land in spam.
|
Sending fails and the message means nothing to you? Send us the debug text, without the password.
Open a support ticket
|
RECOMMENDED PRODUCT Professional e-mail on your domain Mailboxes in your company name, no adverts, with spam filtering. See plans |