Vora SMTP Pro documentation
Nine more sending methods for Vora SMTP, and one-click Gmail and Microsoft 365 setup that needs no Google Cloud or Azure app.
Install
Vora SMTP Pro is an add-on for the free plugin. It does not replace it and cannot run without it — the Requires Plugins header means WordPress itself enforces the dependency.
- 1Install and activate the free Vora SMTP plugin first — the add-on declares it as a dependency and WordPress enforces it.
- 2Upload the vora-smtp-pro folder to /wp-content/plugins/, or upload the zip through Plugins → Add New → Upload Plugin.
- 3Activate Vora SMTP Pro.
- 4Go to Vora SMTP → Providers and choose one of the added sending methods.
- 5Enter that provider's credentials and use Send Test Email to confirm the connection.
- 6Enter your licence key under Vora SMTP → License to receive updates.
How it fits together
The add-on supplies sending drivers and nothing else. It hooks the free plugin’s provider registry at vora_smtp_register_providers, and the free plugin does the sending, logging and retrying. Three consequences worth knowing:
- Any of them can be primary, fallback, or both
They appear alongside the free methods on the Providers screen and behave identically in the fallback chain.
- They share the email log
Messages sent through them appear in the log with the same preview and resend controls, and a message rescued by the fallback is credited to the method that actually delivered it.
- Nothing is configured twice
The log, automatic fallback, failure alerts, the retry queue and the connection test all belong to the free plugin and already cover these providers.
Where the credentials live
The nine providers
Each appears on the Providers screen with its own fields. The keys beside each name are the settings keys they are stored under.
- SendGridsendgrid_api_key
Web API v3, using an API key. Open tracking and click tracking are separate switches.
- Mailgunmailgun_api_key · mailgun_domain · mailgun_region
The Messages API. The sending domain must be one verified in your Mailgun account, and the region has to match where that domain was created — an EU domain queried against the US endpoint returns a not-found error that reads like a bad key.
- Amazon SESses_access_key · ses_secret_key · ses_region
The SES API with an access key pair and a region. Remember that a new SES account is sandboxed: it can only send to verified addresses until you request production access.
- Postmarkpostmark_api_token · postmark_stream
The Email API with a server token. The message stream separates transactional from broadcast traffic; the default transactional stream is right for WordPress mail.
- Brevobrevo_api_key
The transactional email API, formerly Sendinblue.
- SparkPostsparkpost_api_key · sparkpost_region
The transmissions API, with a region selector for the EU and US endpoints.
- Mandrillmandrill_api_key · mandrill_subaccount
Mailchimp's transactional service. The subaccount field is optional and only meaningful if you use them.
- Zoho Mailzoho_host · zoho_port · zoho_username · zoho_password
Authenticated SMTP against Zoho's servers, with host and port configurable so you can point at the correct regional endpoint.
- Microsoft 365 and OutlookOAuth
Send through a Microsoft account. Connect it with your own Azure app, or in one click through the relay.
One-click Gmail and Microsoft 365
Connecting a Gmail, Google Workspace or Microsoft 365 account normally means registering your own application — enabling an API, configuring a consent screen, creating credentials and pasting a redirect URI. This add-on removes that: press Connect, approve the account, done.
- How it works
The OAuth handshake is routed through a relay that holds one shared application per provider, so the client secret never sits in your site's database and you never create an app.
- What crosses the browser
Tokens are never placed in a browser URL. The browser carries only a one-time code, which your site exchanges server-to-server.
- The manual flow still exists
The free plugin's bring-your-own-app flow is untouched and remains available — use it if you would rather hold your own credentials.
- Disconnecting
For Google this revokes the authorisation and deletes the stored tokens. Microsoft publishes no revocation endpoint, so the tokens are deleted and you are pointed at your Microsoft account to withdraw consent there — the add-on says so rather than implying the grant is gone.
Licence and updates
- What a licence controls
Access to new versions, and nothing else. Every sending method keeps working with no key, an expired key, or an unreachable licence server — a problem at wpvora.com can never stop your site sending email.
- The License screenVora SMTP → License
Takes your key and binds it to this site. It shows how many of your site activations are in use, when updates and support run to, the version you have installed and the version published on wpvora.com, and says plainly whether a newer one exists.
- Check for updates now
Forces a fresh check. WordPress's own “Check again” link cannot do this — it clears WordPress's update cache but not the add-on's, so the six-hour cached answer is handed straight back and a freshly published version stays invisible until it expires.
- When a licence lapses
The new version is still announced on the Plugins screen, so an unlicensed site does not look identical to an up-to-date one. It cannot be installed without a key — WordPress shows “Automatic update is unavailable for this plugin” — and the message distinguishes a site that never had a licence from one whose licence ran out.
Sending is never gated
Deactivating and deleting
If the site is sending through one of these providers when the add-on is deactivated, the sending method is switched back to PHP Mail rather than left pointing at a driver that is no longer loaded — mail keeps going out instead of failing every send with “Unknown provider”. The same applies to a fallback set to one of these methods, and your original choice is restored the next time the add-on is activated.
Deleting removes only the add-on’s own bookkeeping. Provider credentials stay where they are, in the free plugin’s settings.
External services
- The OAuth relayone-click setup only
Contacted only if you use the one-click buttons. The manual bring-your-own-app flow and every other sending method contact nothing.
Sent: the provider name, your site's callback URL, a one-time state token, the authorisation code returned by the consent screen, and your refresh token when an access token needs renewing. It is contacted during a connection you start, and on later token refreshes for that connection.
- Licence and updatesapi.wpvora.com
The add-on checks its licence and asks for new versions, sending the licence key, your site URL and the installed version.
Both are operated by WPVora — see the terms and privacy policy.
Running your own relay
Site owners who would rather not route a handshake through ours can point the add-on elsewhere with the VORA_SMTP_OAUTH_RELAY_URL constant or the vora_smtp_oauth_relay_url filter, in which case the applicable terms are that relay’s rather than ours.
Troubleshooting
Does this replace the free plugin?+–
No. It is an add-on and requires the free Vora SMTP plugin to be installed and active. On its own it registers nothing and shows a notice telling you what is missing.
Do I need to configure the log, fallback or alerts separately?+–
No. Those are features of the free plugin and apply to every sending method, including the nine added here.
What happens to my settings if I deactivate the add-on?+–
Nothing is deleted. Credentials for these providers live in the free plugin's settings and stay there. If one of these providers was the active sending method, the site falls back to PHP Mail so email keeps working, and your original choice is restored when you activate the add-on again.
What happens if I delete the add-on?+–
Deleting it removes only the add-on's own bookkeeping. Your provider credentials are left in place, because they belong to the free plugin's settings and because an API key is usually shown only once at the moment it is issued — a plugin that discards one on the way out has destroyed something you cannot get back.
Test Connection fails but sending works+–
This was a bug in versions before 1.7.0 for accounts connected through the one-click relay: the test asked for a local app registration, which a relay connection has none of by design. Update to 1.7.0, where the check no longer asks for one.
Can I use one of these as the fallback rather than the primary?+–
Yes. Any provider here can be the primary sending method, the fallback, or both — the free plugin's fallback routing treats them exactly like the built-in methods.