Email Spam Tester

Email Spam Tester › Email Spam Tester for WordPress

Email Spam Tester for WordPress

A plugin for site owners and the people who run their sites. It tests the emails WordPress actually sends, through wp_mail and whatever SMTP plugin is behind it, and tells you what to change in DNS and in WordPress.

Version 0.1.0, 1 October 2026. Download (58 KB), SHA-256 b55d590195e181a5e9248620778f7a51f96bd366e43eded8752fb2f009f98fa2. Installation is the last section of this page.

Why a plugin, when the site can just send to a test address

You can, and it is easy to send one email from your own mailbox, get a good score and stop there, while the order confirmations go out a different way. A shop's mail leaves through wp_mail(): PHP's mail() on the web server if nobody changed it, or an SMTP plugin such as WP Mail SMTP or FluentSMTP. Each of those has its own From address, its own envelope sender and its own server, and a WooCommerce email has a From address of its own on top. The plugin sends the test along that exact path.

What a test is

Pick one of the site's emails and press Send the test:

Each of these is filled with Jane Sample, a reset link that resets nothing and an order that is never saved, because anyone with a test report's link can open it.

The test also tells the service whether WordPress sends through mail() or SMTP, and through which host and SMTP plugin, and the AI plan takes it into account. On my test site, which sends through PHP's mail(), the plan's first steps were "Stop sending directly through the web server" and "Authorize the SMTP provider with SPF".

"Also check the folder at email providers" is on by default and costs about 30 more emails from your SMTP quota. The copies go out a few at a time while the page is open, or on WordPress's scheduled runs when it is not. The table fills in over half an hour: Inbox, Spam or Promotions at Gmail, Outlook, Yahoo, Proton, AOL and the rest, or the answer a provider gave when it refused the email. The Gmail mailboxes are public test mailboxes, so the subject and the sender name can be seen there.

Records to add

Before anything is sent, the Test page checks the From domain's SPF, DKIM, DMARC and MX and lists the records to add, each with a Copy button. When the site sends through a known provider (Mailgun, SendGrid, Google, Microsoft 365, Amazon SES, Brevo, Postmark and a few more) the SPF line gets that provider's include instead of one IP from its pool. After a test, the check also knows which IP the email came from. The plugin never touches DNS; it cannot, since the zone is at the registrar or Cloudflare.

History

The History tab lists the site's tests newest first. A chart above it follows the score, and each row says which checks went from fail to pass, or back, since the test before.

Monitoring

This part is off until you switch it on. Then, once a minute, the plugin asks Email Spam Tester which of the emails the site sent are of a new kind, and sends a copy of only those to a private address, through the same wp_mail(). The original is not touched, and the copy keeps its From and headers but drops Cc, Bcc, attachments and every link's query string, which also takes out password reset keys. Its report says which plugin sent the email, found from the code that called wp_mail(): WooCommerce, Contact Form 7, WPForms, WordPress itself.

The Monitoring tab then shows the last 24 hours by plugin, alerts such as "WooCommerce: DMARC fails in 12 of 12 emails", and emails WordPress failed to hand over at all, with the server's answer. Those failures are also a Site Health test.

The rest

What leaves your site

Nothing goes out before you press Connect this site. After that the service gets the WordPress and plugin versions, the test emails, the From domain and how WordPress sends (never an SMTP password), and the server's answer when it refused an email, with addresses removed. With monitoring on, it also gets the sender and subject of every email the site sends and a copy of each new kind; only the site can see those reports. How long each thing is kept is in the plugin's section of the privacy page.

Price

The plugin is free to use right now, with 30 tests and 3 folder checks a day per site and up to 3 monitored domains.

Install

  1. Download the zip above and check it: sha256sum -c email-spam-tester-0.1.0.zip.sha256 should print OK.
  2. In WordPress, go to Plugins › Add New Plugin › Upload Plugin, choose the zip, install and activate.
  3. Open Email Spam Tester in the admin menu, read what connecting sends, and press Connect this site.
  4. Choose an email and press Send the test. The report shows up on the same page within a minute or two.

The plugin will be submitted to the WordPress.org directory. Once it is listed there, updates come through the dashboard like any other plugin.

Tested on WordPress 7.1.2 with PHP 8.3, WooCommerce and PHP's mail() through Postfix. Not yet tested on a live host with an SMTP plugin sending through a provider, or on multisite.