Email deliverability is one of the most persistent challenges for businesses that send transactional messages — order confirmations, OTPs, password resets, invoices, or newsletters. The root cause is almost always the same: email sent directly from an unfamiliar server IP gets flagged by spam filters before it ever reaches an inbox. SMTP Relay is the professional solution. This guide explains how it works, how to configure it across common platforms, and the best practices that keep your sender reputation healthy over the long term.

What Is SMTP Relay and How Does It Work?

An SMTP Relay — also called a Smart Host — sits between your application or server and the recipient's mail provider. Instead of your server trying to deliver email directly to Gmail or Outlook servers (Direct Send), it hands the message off to the relay, which then delivers it on your behalf using a pool of pre-warmed IP addresses with established reputation.

The flow is straightforward: Your Application → SMTP Relay (Port 587) → Recipient's Mail Server

Why relay instead of sending directly? Several reasons make a significant practical difference:

Choosing the Right SMTP Relay Provider

The market offers several relay providers, each optimized for a different use case. The three factors that should guide your choice are monthly sending volume, email type (transactional versus marketing), and budget.

Provider Free Tier Best For Strength
SendGrid 100 emails/day Transactional, SaaS Full-featured API, detailed analytics
Mailgun 100 emails/day (trial) Developers, API-first apps Webhooks, granular logging
Amazon SES 62,000/month (from EC2) High volume, cost-sensitive Extremely low cost, scalable
Brevo (Sendinblue) 300 emails/day SMEs, newsletter + transactional Easy UI, combined marketing and relay
Business Email Hosting SMTP Included in plan @yourdomain business email SPF/DKIM/DMARC pre-configured

For SMEs sending business email — invoices, order confirmations, customer follow-ups — through their own @domain address, a dedicated Email Hosting plan with SMTP, SPF, DKIM, and DMARC already configured is the most cost-effective and lowest-friction option.

Setting Up SPF, DKIM, and DMARC First

No relay provider can compensate for missing email authentication records. Before you configure any relay, make sure your DNS is correct. Receiving servers check these records before accepting your message.

SPF Record

SPF (Sender Policy Framework) tells receiving servers which IP addresses are permitted to send email on behalf of your domain. Add a TXT record in DNS:

yourdomain.com  IN  TXT  "v=spf1 include:sendgrid.net include:mail.yourdomain.com ~all"

Important: a domain must have exactly one SPF record. Multiple SPF TXT records cause a permanent failure (PermError). Combine all include: mechanisms into a single record. Each relay provider publishes its own include string in their documentation.

DKIM Record

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each outgoing message. Receiving servers verify the signature against a public key published in your DNS:

selector._domainkey.yourdomain.com  IN  TXT  "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBA..."

The selector value (e.g., s1, mail, default) is defined by your relay provider. Copy the public key from your provider's dashboard and paste it as the p= value.

DMARC Record

DMARC ties SPF and DKIM together and tells receiving servers what to do with messages that fail authentication. Start with a monitoring-only policy to observe without blocking:

_dmarc.yourdomain.com  IN  TXT  "v=DMARC1; p=none; rua=mailto:[email protected]"

After two to four weeks of clean reports, escalate to p=quarantine (spam folder), then p=reject (block entirely) to fully protect your domain against spoofing.

Configuring Postfix to Send Through an SMTP Relay

Postfix is the default Mail Transfer Agent on Ubuntu, Debian, and CentOS. Edit /etc/postfix/main.cf to define a relay host:

# Define Smart Host
relayhost = [smtp.sendgrid.net]:587

# Enable SASL authentication
smtp_sasl_auth_enable = yes
smtp_sasl_password_maps = hash:/etc/postfix/sasl_passwd
smtp_sasl_security_options = noanonymous

# Enforce TLS encryption
smtp_use_tls = yes
smtp_tls_security_level = encrypt
smtp_tls_CAfile = /etc/ssl/certs/ca-certificates.crt

Create /etc/postfix/sasl_passwd to store relay credentials:

[smtp.sendgrid.net]:587  apikey:SG.xxxxxxxxxxxxxxxxxxxx

Generate the hash database, secure permissions, and reload Postfix:

sudo postmap /etc/postfix/sasl_passwd
sudo chmod 600 /etc/postfix/sasl_passwd /etc/postfix/sasl_passwd.db
sudo systemctl reload postfix

Send a test message and check the mail log:

echo "Test body" | mail -s "Test Subject" [email protected]
tail -f /var/log/mail.log | grep "status=sent"

Configuring PHPMailer to Use SMTP Relay

PHPMailer is the most widely used PHP email library. Configure it for relay as follows:

<?php
use PHPMailer\PHPMailer\PHPMailer;
use PHPMailer\PHPMailer\SMTP;
use PHPMailer\PHPMailer\Exception;

require 'vendor/autoload.php';

$mail = new PHPMailer(true);

try {
    $mail->isSMTP();
    $mail->Host       = 'smtp.sendgrid.net';
    $mail->SMTPAuth   = true;
    $mail->Username   = 'apikey';
    $mail->Password   = 'SG.xxxxxxxxxxxxxxxxxxxx';
    $mail->SMTPSecure = PHPMailer::ENCRYPTION_STARTTLS;
    $mail->Port       = 587;

    $mail->setFrom('[email protected]', 'Your Company');
    $mail->addAddress('[email protected]', 'Customer Name');
    $mail->addReplyTo('[email protected]', 'Support');

    $mail->isHTML(true);
    $mail->Subject = 'Order Confirmation';
    $mail->Body    = '<h1>Thank you for your order</h1><p>Order details...</p>';
    $mail->AltBody = 'Thank you for your order. Order details follow.';

    $mail->send();
    echo 'Email sent successfully';
} catch (Exception $e) {
    echo "Error: {$mail->ErrorInfo}";
}
?>

Always set SMTPSecure and Port consistently — STARTTLS with port 587, or SMTPS (PHPMailer::ENCRYPTION_SMTPS) with port 465. Always include an AltBody plain-text fallback; email clients and spam filters prefer messages that include both HTML and plain-text parts.

Pro tip: If your application sends email from multiple domains, create a separate API key and DKIM selector for each domain rather than sharing credentials. Shared credentials mean shared reputation — a spike in bounces or spam complaints on one domain can hurt deliverability for all others using the same key. Keep sending streams isolated.

Connecting WordPress to SMTP Relay

WordPress routes outgoing mail through wp_mail(), which by default calls PHP's native mail() function. This sends directly from the server's IP with no DKIM signing, which is why WordPress notification emails so often end up in spam. The fix is the WP Mail SMTP plugin:

  1. Install the WP Mail SMTP plugin from the WordPress repository.
  2. Navigate to Settings → WP Mail SMTP → Settings.
  3. Set From Email to an address on a domain that already has SPF and DKIM configured.
  4. Select Mailer: Other SMTP.
  5. Enter SMTP Host (e.g., smtp.sendgrid.net), Encryption: TLS, Port: 587.
  6. Enable Authentication and enter your relay Username and Password.
  7. Save settings, then open the Email Test tab and send a test to confirm inbox delivery.
# Alternative: define constants in wp-config.php
define('WPMS_ON', true);
define('WPMS_SMTP_HOST', 'smtp.sendgrid.net');
define('WPMS_SMTP_PORT', 587);
define('WPMS_SSL', 'tls');
define('WPMS_SMTP_AUTH', true);
define('WPMS_SMTP_USER', 'apikey');
define('WPMS_SMTP_PASS', 'SG.xxxxxxxxxxxxxxxxxxxx');

Monitoring and Maintaining Sender Reputation

Configuring a relay correctly is the beginning, not the end. Sender reputation requires ongoing maintenance. Three tools are essential:

Google Postmaster Tools

Register your domain at postmaster.google.com and verify ownership via a DNS TXT record. Postmaster Tools shows your domain reputation, IP reputation, spam rate, and DMARC compliance for all messages delivered to Gmail addresses. Watch for any uptick in the spam rate metric — anything above 0.1% consistently requires immediate investigation.

Mail-Tester.com

Send a test email to the address provided by Mail-Tester and receive a 1–10 score with a detailed breakdown. It checks SPF, DKIM, DMARC, blacklist status, content scoring, and HTML quality in one report. Run this test whenever you change your relay configuration or email template.

Bounce Management

Hard bounces (non-existent addresses or invalid domains) must be removed from your list immediately. Repeatedly sending to addresses that bounce is a direct path to getting your sending domain or IP blocked. Most relay providers auto-suppress bouncing addresses, but sync that data back to your application's database to prevent re-adding them. Keep your overall bounce rate below 2%.

Email Content Best Practices

Authentication gets your message past the server-level checks, but content filters still evaluate every email for spam signals. Even perfectly authenticated messages can land in spam if the content looks suspicious:

Frequently Asked Questions

What is the difference between SMTP Relay and direct email sending?

Direct sending means your server delivers email straight to the recipient's mail server, exposing your own IP address to reputation checks. If your IP is new or has poor reputation, emails frequently end up in spam. SMTP Relay routes your messages through a Smart Host with pre-warmed IP pools and established sender reputation. The relay handles authentication, queuing, and bounce management, resulting in significantly higher deliverability for transactional and bulk business email.

Do I need to set up SPF and DKIM before using an SMTP Relay?

Yes, absolutely. SPF must include the IP ranges or include mechanism of your SMTP relay provider so they are authorized to send on behalf of your domain. DKIM requires you to publish a TXT record containing the public key provided by your relay service. Both records are checked by receiving servers like Gmail and Outlook when deciding whether to accept or reject your message. Without them, email will almost certainly be filtered to spam or rejected outright, regardless of which relay you use.

How do I connect WordPress to an SMTP Relay?

WordPress sends email through wp_mail(), which by default calls PHP's native mail() function — this typically results in poor deliverability since the server IP has no established reputation. Install the WP Mail SMTP plugin, then enter your relay provider's SMTP host, port 587 for STARTTLS (or 465 for SSL), username and password. The plugin hooks into wp_mail() and reroutes all outgoing email through your relay. Always use the built-in Email Test tab to confirm messages are landing in the inbox, not the spam folder.

When should I use SMTP port 25, 465, or 587?

Port 25 is the original MTA-to-MTA relay port, but most ISPs and cloud providers block outbound port 25 to prevent spam, making it unsuitable for application-level sending. Port 465 (SMTPS) uses Implicit TLS from the start of the connection; it was historically deprecated but RFC 8314 re-recommends it as the preferred option over STARTTLS. Port 587 is the modern Submission port using STARTTLS (Explicit TLS) and is the recommended standard for all SMTP relay connections from applications to a Smart Host. Always prefer port 587 unless your provider specifies otherwise.

Business Email Hosting on Your Own Domain

AsiaGB Email includes SPF, DKIM, and DMARC pre-configured for maximum deliverability. Starting from 200 THB/year.

View Email Plans