Skip to content
WP Cloud
WP Cloud
    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management
    • PanelAlpha Integration: White-Label WordPress Control Panel for Hosts
    • EasyEngine Panel Integration: Visual WordPress Management for WP Cloud
    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
    • Pressable
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Impressive Hosting
    • Blog
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗
  • Solutions

    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Featured Partners

    Features

    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management

    Integrations

    • PanelAlpha Integration
    • Easy Engine Panel Integration

    Resources

    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
  • Case Studies
    • PressableA case study about how WP Cloud supports Pressable to power millions of page views daily.
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Newspack
    • Inverse Paradox
  • Insights
    • Podcast
    • BlogWP Cloud blog page with latest news and updates about the platform.
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗

Browse

    • WP Cloud platform overview
    • Onboard and launch with WP Cloud
    • WP Cloud Partner Portal
    • Get support from WP Cloud
    • WP Cloud glossary
    • Manage and secure API keys
    • Client SSH
    • WP Cloud API quick start
    • Webhooks
    • Run bulk tasks across sites
      • Manage site domains and aliases
      • Domain verification records
      • TLS certificates
      • Manage custom TLS certificates
      • Cloudflare and WP Cloud
    • Clone a site
    • Configure resources, site type, and billing with site meta
    • Delete a site
    • Persistent data
    • Staging sites
    • Migrate a site to WP Cloud
      • SSH and SFTP access models
      • Client SSH
      • User SSH and SFTP access
      • Database credentials
      • phpMyAdmin
      • ABSPATH
      • Default wp-config.php
      • Site constants
      • Configure redirects and headers with custom-redirects.php
      • Akismet and Jetpack
      • Blocked and unsupported plugins
      • PHP lifecycle and supported versions
      • Symlinks and managed software
      • WordPress versions
      • Install Composer and WP-CLI packages
      • Manage platform software with WP-CLI
      • Useful WP-CLI commands
    • Transactional email
    • WordPress multisite
    • Cron scheduling
    • Decoupled and headless WordPress
    • Repair Yoast indexables
      • Page Cache
      • Edge Cache
      • Object Cache
      • Image transformation
      • Offload image sub-sizes
    • Configure lightweight 404s for static files
      • DDoS protection
      • Defensive Mode
      • Rate limiting
      • Network and web application firewalls
      • Bot protection
      • Password protection
      • HTTP and security headers
      • PHP filesystem access permissions
      • Scan a site for malware
    • Backups overview
    • Create an on-demand backup
    • Restore a backup
    • Jetpack backups
      • Error logs
      • Web server logs
    • Metrics
    • Application performance monitoring
    • Automated failover
    • IP ranges
    • Origin and edge servers
    • Server specifications and settings
    • EasyEngine integration
    • PanelAlpha integration
      • White labelling and co-marketing WP Cloud
      • WP Cloud logos
      • Terms of Service & Compliance
      • Prohibited content
      • Copyright infringement and takedown notifications
    • WP Cloud billing
    • WP Cloud for agencies and site networks
    • WP Cloud partner support options
    • Troubleshoot Page and Edge Cache
    • Troubleshoot HTTP 429 and 599 errors
    • WP Cloud HTTP status codes
    • Troubleshoot site performance
    • Cache slow database queries
    • Troubleshoot duplicate core files, wp-config.php, and wp-admin 403 errors
    • Troubleshoot email delivery
    • Troubleshoot PDF thumbnail generation
    • Troubleshoot TLS certificate provisioning
Documentation/WordPress on WP Cloud/Transactional email

Transactional email

LAST UPDATED

3 months ago

    WP Cloud provides a transactional email service for WordPress system messages, password resets, order notices, and contact-form messages. Mail sent with WordPress’s normal PHP mail path is relayed through WP Cloud mail servers and signed for the site’s primary domain.

    Host partners can use this service as the default for their customers or allow end users to connect an external SMTP provider. It is not intended for email marketing campaigns or other bulk mail.

    Default delivery and limits

    The platform-provided mailer accepts up to 200 messages per site per hour. Messages over the limit are rejected and must be sent again later. The limit does not apply when a site sends through its own SMTP provider.

    Some managed host clients use a custom relay configuration in which the local mail server sends to a third-party provider. That configuration requires coordination when the provider does not perform DKIM signing itself and should not be assumed for every WP Cloud client.

    Authenticate mail with DNS

    Host partners should provide these records to customers or add them when the partner manages DNS for the site’s primary domain.

    SPF

    When the domain has no SPF record, add:

    TypeHostValue
    TXT@v=spf1 include:_spf.wpcloud.com ~all

    For a site sending from a subdomain such as news.example.com, use news as the host rather than @.

    A domain must have only one SPF record. If an SPF record already exists, add include:_spf.wpcloud.com to that record before its final ~all, -all, or other all-mechanism instead of creating a second TXT record.

    DKIM

    Add both CNAME records:

    TypeHostValue
    CNAMEwpcloud1._domainkeywpcloud1._domainkey.wpcloud.com
    CNAMEwpcloud2._domainkeywpcloud2._domainkey.wpcloud.com

    WP Cloud signs mail for the site’s primary domain. A domain-based multisite that sends from an alias or subsite domain may need to force its From address to the primary domain or use another SMTP service.

    DMARC

    DMARC policy depends on the domain owner’s mail systems and enforcement plan. The following record begins with monitoring only:

    TypeHostValue
    TXT_dmarcv=DMARC1; p=none;

    Do not move directly to p=quarantine or p=reject without confirming every authorized sender and reviewing DMARC reports. Some mailbox providers require DMARC for high-volume senders. DMARC.org and Cloudflare’s SPF, DKIM, and DMARC overview provide background on the records.

    Abuse detection and email blocks

    WP Cloud can temporarily or permanently block a site that abuses the shared transactional email service. Host partners can query the Email Block endpoint for blocked domains.

    The sasl_block webhook is sent when a domain’s block record changes, including an unblock or an extension of an existing block. Review the expires value before notifying a customer because a later event can replace an earlier expiration.

    {
      "event": "sasl_block",
      "timestamp": 1721230550,
      "atomic_site_id": 123456789,
      "data": {
        "domain": "example.com",
        "reason": "Optional reason for block",
        "expires": "2026-02-04 15:42:14"
      }
    }Code language: JSON / JSON with Comments (json)

    An expires value in the future means the domain is currently blocked. Use the event to start the host partner’s spam and abuse workflow and to help the customer correct missing SPF, DKIM, or DMARC records. See Webhooks for signing and event handling.

    Before requesting review of a WP Cloud SASL block, collect the sender address and domain, the sending path, the abused form or compromised account, the spam that was produced, and the block reason and expiration. Record the plugin, theme, and WordPress updates applied; credential and two-factor authentication changes where applicable; malware or vulnerability findings; and evidence that the unwanted sending stopped.

    A WP Cloud SASL block is different from a rejection by a remote SMTP provider or mailbox service and from a sender-reputation problem. Check which service returned the error before changing the site’s WP Cloud mail configuration.

    Use an email service provider

    An end user can install an SMTP plugin and send through a provider of their choice. This bypasses WP Cloud’s mail servers and uses the provider’s limits, authentication, reporting, and delivery controls.

    An external provider is a better fit when a site:

    • needs more than four sender addresses;
    • needs more than 200 transactional messages per hour;
    • sends automated transactional sequences through tools such as AutomateWoo;
    • sends bulk or marketing email rather than standard transactional messages;
    • needs more than 500 messages per day, delivery monitoring, analytics, or detailed bounce handling;
    • has a custom configuration that does not work reliably with PHP mail(); or
    • continues to encounter failed or filtered messages.

    MailPoet is the first option to consider for WordPress newsletters and WooCommerce email. Other provider options include SMTP.com, Brevo, Mailgun, SendGrid, SendLayer, Google Workspace, and Zoho.

    Examples of WordPress SMTP plugins include Post SMTP, WP Mail SMTP, and Easy WP SMTP. The host partner and end user are responsible for selecting, configuring, securing, and supporting a third-party service.

    Previous Useful WP-CLI commands
    Next WordPress multisite

    Related Guides

    • ABSPATH

      Understand why ABSPATH points to managed WordPress core on WP Cloud and use WP_CONTENT_DIR for…

      1 Min.

      READ

    • Akismet and Jetpack

      Understand the platform-managed Akismet and Jetpack packages and how to unlock one before removal.

      1 Min.

      READ

    • Install Composer and WP-CLI packages

      Install Composer and site-scoped WP-CLI packages over Client SSH on WP Cloud.

      2 Min.

      READ

    On this page

      Contact support

      Contact us with Support issues and questions related to WP Cloud, the WP Cloud Atomic API, API-key IP allow list changes, Station, and more.

      Check the FAQs

      Have questions? Please visit our FAQ to learn more.

      An Automattic venture

      Work With Us

      Press

      Privacy Policy

      © 2021-2026 Automattic Inc.

      Notifications