Craft sends account activations, password resets and anything your templates or plugins mail out through one mailer, which by default uses the server's sendmail. SMTP is built in — no plugin needed — and switching it to Postwing takes one settings screen.
| Setting | Value |
|---|---|
| SMTP host | smtp.postwing.app |
| Port | 587 |
| Encryption | STARTTLS (the connection is upgraded to TLS before login) |
| Username | The login of an SMTP token for your domain |
| Password | The password of that token — shown once, when the token is created |
Email settings are stored in project config, which is usually committed. Keep the values in .env and reference them from the control panel:
SYSTEM_EMAIL=noreply@your-domain.com
SMTP_HOST=smtp.postwing.app
SMTP_PORT=587
SMTP_USERNAME=token-login@your-domain.com
SMTP_PASSWORD=your-token-passwordIn the control panel go to Settings → Email and fill in:
| Field | Value |
|---|---|
| System Email Address | $SYSTEM_EMAIL — an address on your verified domain |
| Sender Name | Your site name |
| Transport Type | SMTP |
| Hostname | $SMTP_HOST |
| Port | $SMTP_PORT (587) |
| Use authentication | On |
| Username | $SMTP_USERNAME |
| Password | $SMTP_PASSWORD |
465 is TLS from the first byte, any other port is upgraded with STARTTLS. With 587 the password is never sent in plaintext. To keep mail out of the control panel entirely — or to use a different transport per environment — override the mailer component:
<?php
// config/app.php — overrides the SMTP settings from the control panel
use craft\helpers\App;
use craft\helpers\MailerHelper;
use craft\mail\transportadapters\Smtp;
return [
'components' => [
'mailer' => function() {
$config = App::mailerConfig();
$adapter = MailerHelper::createTransportAdapter(Smtp::class, [
'host' => App::env('SMTP_HOST'),
'port' => App::env('SMTP_PORT'),
'useAuthentication' => true,
'username' => App::env('SMTP_USERNAME'),
'password' => App::env('SMTP_PASSWORD'),
]);
$config['transport'] = $adapter->defineTransport();
return Craft::createObject($config);
},
],
];Press Test at the bottom of Settings → Email, or run the same check from the command line, which prints the full SMTP error:
php craft mailer/test --to=you@example.com On staging, the testToEmailAddress general setting routes every outgoing email to one address so real users are never mailed.
| Error | Cause and fix |
|---|---|
Connection could not be established with host | Outbound port blocked or wrong hostname. Try port 8587. |
Timeout on port 8465 | Craft only uses implicit TLS on 465 exactly. Use 8587. |
Failed to authenticate on SMTP server | Wrong token login or password. |
| Rejected as "authentication required" | Use authentication is off. |
| Works locally, fails after deploy | The $SMTP_* variables are missing from the server's .env. |
| Mail goes to spam | System Email Address is not on your verified domain. |
Settings → Email in the control panel (/admin/settings/email). Choose SMTP as the Transport Type and the Hostname, Port, Use authentication, Username and Password fields appear. The values are saved to project config, so they travel with your deployments.
You don't — Craft 5 has no encryption setting, and Craft 4 dropped it in 4.3.7. Port 465 gets TLS from the first byte; any other port is upgraded with STARTTLS when the server offers it. Use 587, and don't look for a missing field.
Type an environment variable reference such as $SMTP_PASSWORD into the Password field instead of the password itself, and define the variable in .env. Project config then stores only the reference, which is safe to commit.
Press Test at the bottom of Settings → Email, or run php craft mailer/test --to=you@example.com. The CLI command uses the saved settings and prints the full error, which helps when the control panel only shows a short message.
Craft's SMTP transport uses TLS from the first byte only when the port is exactly 465; on any other port it expects to start in plaintext and upgrade. If your host blocks 587, use 8587, which works the same way as 587.
Check the System Email Address in Settings → Email. It is the From address for everything Craft sends, including account activation and password resets, and it must be on the domain you verified so DKIM, SPF and DMARC align.