Vora SMTP Pro

Vora SMTP Pro documentation

Nine more sending methods for Vora SMTP, and one-click Gmail and Microsoft 365 setup that needs no Google Cloud or Azure app.

Version1.7.0RequiresVora SMTPWordPress6.0+PHP7.4+LicenceGPLv2 or later
Get Vora SMTP Pro

Install

Vora SMTP Pro is an add-on for the free plugin. It does not replace it and cannot run without it — the Requires Plugins header means WordPress itself enforces the dependency.

  1. 1Install and activate the free Vora SMTP plugin first — the add-on declares it as a dependency and WordPress enforces it.
  2. 2Upload the vora-smtp-pro folder to /wp-content/plugins/, or upload the zip through Plugins → Add New → Upload Plugin.
  3. 3Activate Vora SMTP Pro.
  4. 4Go to Vora SMTP → Providers and choose one of the added sending methods.
  5. 5Enter that provider's credentials and use Send Test Email to confirm the connection.
  6. 6Enter your licence key under Vora SMTP → License to receive updates.

How it fits together

The add-on supplies sending drivers and nothing else. It hooks the free plugin’s provider registry at vora_smtp_register_providers, and the free plugin does the sending, logging and retrying. Three consequences worth knowing:

Any of them can be primary, fallback, or both

They appear alongside the free methods on the Providers screen and behave identically in the fallback chain.

They share the email log

Messages sent through them appear in the log with the same preview and resend controls, and a message rescued by the fallback is credited to the method that actually delivered it.

Nothing is configured twice

The log, automatic fallback, failure alerts, the retry queue and the connection test all belong to the free plugin and already cover these providers.

Where the credentials live

In the free plugin’s settings, not the add-on’s. That is why they survive deactivating, updating or deleting this add-on.

The nine providers

Each appears on the Providers screen with its own fields. The keys beside each name are the settings keys they are stored under.

SendGridsendgrid_api_key

Web API v3, using an API key. Open tracking and click tracking are separate switches.

Mailgunmailgun_api_key · mailgun_domain · mailgun_region

The Messages API. The sending domain must be one verified in your Mailgun account, and the region has to match where that domain was created — an EU domain queried against the US endpoint returns a not-found error that reads like a bad key.

Amazon SESses_access_key · ses_secret_key · ses_region

The SES API with an access key pair and a region. Remember that a new SES account is sandboxed: it can only send to verified addresses until you request production access.

Postmarkpostmark_api_token · postmark_stream

The Email API with a server token. The message stream separates transactional from broadcast traffic; the default transactional stream is right for WordPress mail.

Brevobrevo_api_key

The transactional email API, formerly Sendinblue.

SparkPostsparkpost_api_key · sparkpost_region

The transmissions API, with a region selector for the EU and US endpoints.

Mandrillmandrill_api_key · mandrill_subaccount

Mailchimp's transactional service. The subaccount field is optional and only meaningful if you use them.

Zoho Mailzoho_host · zoho_port · zoho_username · zoho_password

Authenticated SMTP against Zoho's servers, with host and port configurable so you can point at the correct regional endpoint.

Microsoft 365 and OutlookOAuth

Send through a Microsoft account. Connect it with your own Azure app, or in one click through the relay.

One-click Gmail and Microsoft 365

Connecting a Gmail, Google Workspace or Microsoft 365 account normally means registering your own application — enabling an API, configuring a consent screen, creating credentials and pasting a redirect URI. This add-on removes that: press Connect, approve the account, done.

How it works

The OAuth handshake is routed through a relay that holds one shared application per provider, so the client secret never sits in your site's database and you never create an app.

What crosses the browser

Tokens are never placed in a browser URL. The browser carries only a one-time code, which your site exchanges server-to-server.

The manual flow still exists

The free plugin's bring-your-own-app flow is untouched and remains available — use it if you would rather hold your own credentials.

Disconnecting

For Google this revokes the authorisation and deletes the stored tokens. Microsoft publishes no revocation endpoint, so the tokens are deleted and you are pointed at your Microsoft account to withdraw consent there — the add-on says so rather than implying the grant is gone.

Licence and updates

What a licence controls

Access to new versions, and nothing else. Every sending method keeps working with no key, an expired key, or an unreachable licence server — a problem at wpvora.com can never stop your site sending email.

The License screenVora SMTP → License

Takes your key and binds it to this site. It shows how many of your site activations are in use, when updates and support run to, the version you have installed and the version published on wpvora.com, and says plainly whether a newer one exists.

Check for updates now

Forces a fresh check. WordPress's own “Check again” link cannot do this — it clears WordPress's update cache but not the add-on's, so the six-hour cached answer is handed straight back and a freshly published version stays invisible until it expires.

When a licence lapses

The new version is still announced on the Plugins screen, so an unlicensed site does not look identical to an up-to-date one. It cannot be installed without a key — WordPress shows “Automatic update is unavailable for this plugin” — and the message distinguishes a site that never had a licence from one whose licence ran out.

Sending is never gated

This is worth repeating because most licensed plugins do the opposite: an expired licence here withholds new versions, never delivery. Your site keeps sending.

Deactivating and deleting

If the site is sending through one of these providers when the add-on is deactivated, the sending method is switched back to PHP Mail rather than left pointing at a driver that is no longer loaded — mail keeps going out instead of failing every send with “Unknown provider”. The same applies to a fallback set to one of these methods, and your original choice is restored the next time the add-on is activated.

Deleting removes only the add-on’s own bookkeeping. Provider credentials stay where they are, in the free plugin’s settings.

External services

The OAuth relayone-click setup only

Contacted only if you use the one-click buttons. The manual bring-your-own-app flow and every other sending method contact nothing.

Sent: the provider name, your site's callback URL, a one-time state token, the authorisation code returned by the consent screen, and your refresh token when an access token needs renewing. It is contacted during a connection you start, and on later token refreshes for that connection.

Licence and updatesapi.wpvora.com

The add-on checks its licence and asks for new versions, sending the licence key, your site URL and the installed version.

Both are operated by WPVora — see the terms and privacy policy.

Running your own relay

Site owners who would rather not route a handshake through ours can point the add-on elsewhere with the VORA_SMTP_OAUTH_RELAY_URL constant or the vora_smtp_oauth_relay_url filter, in which case the applicable terms are that relay’s rather than ours.

Troubleshooting

Does this replace the free plugin?+

No. It is an add-on and requires the free Vora SMTP plugin to be installed and active. On its own it registers nothing and shows a notice telling you what is missing.

Do I need to configure the log, fallback or alerts separately?+

No. Those are features of the free plugin and apply to every sending method, including the nine added here.

What happens to my settings if I deactivate the add-on?+

Nothing is deleted. Credentials for these providers live in the free plugin's settings and stay there. If one of these providers was the active sending method, the site falls back to PHP Mail so email keeps working, and your original choice is restored when you activate the add-on again.

What happens if I delete the add-on?+

Deleting it removes only the add-on's own bookkeeping. Your provider credentials are left in place, because they belong to the free plugin's settings and because an API key is usually shown only once at the moment it is issued — a plugin that discards one on the way out has destroyed something you cannot get back.

Test Connection fails but sending works+

This was a bug in versions before 1.7.0 for accounts connected through the one-click relay: the test asked for a local app registration, which a relay connection has none of by design. Update to 1.7.0, where the check no longer asks for one.

Can I use one of these as the fallback rather than the primary?+

Yes. Any provider here can be the primary sending method, the fallback, or both — the free plugin's fallback routing treats them exactly like the built-in methods.