[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQd90YXwrP21EQa2UcALHjA6nsLr-4PI5np3eJO_-lAg":3},{"slug":4,"display_name":5,"profile_url":6,"plugin_count":7,"total_installs":8,"avg_security_score":9,"avg_patch_time_days":10,"trust_score":11,"computed_at":12,"plugins":13},"dixonem","Dixon Cherian","https:\u002F\u002Fprofiles.wordpress.org\u002Fdixonem\u002F",1,0,100,30,94,"2026-08-28T22:41:38.739Z",[14],{"slug":15,"name":16,"version":17,"author":5,"author_profile":6,"description":18,"short_description":19,"active_installs":8,"downloaded":20,"rating":8,"num_ratings":8,"last_updated":21,"tested_up_to":22,"requires_at_least":23,"requires_php":24,"tags":25,"homepage":31,"download_link":32,"security_score":9,"vuln_count":8,"unpatched_count":8,"last_vuln_date":33,"fetched_at":34},"dixonsmtp-for-outlook-microsoft-365","DixonSMTP for Outlook & Microsoft 365","1.0.0","\u003Cp>WordPress’ default PHP mail() delivery is frequently blocked or spam-foldered. \u003Cstrong>DixonSMTP for Outlook & Microsoft 365\u003C\u002Fstrong> routes every email your site sends (core, WooCommerce, WPForms, Contact Form 7, Gravity Forms, and anything else using \u003Ccode>wp_mail()\u003C\u002Fcode>) through Microsoft’s SMTP servers — authenticated, encrypted, and deliverable.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>100% free.\u003C\u002Fstrong> No premium upsell, no paid tiers, no feature gating.\u003C\u002Fp>\n\u003Ch4>Why OAuth 2.0?\u003C\u002Fh4>\n\u003Cp>Microsoft has \u003Cstrong>deprecated Basic Authentication\u003C\u002Fstrong> for Exchange Online and is progressively disabling password-based SMTP AUTH (new Microsoft 365 tenants have it off by default). OAuth 2.0 (“Modern Authentication”) is the supported, secure path forward — which is why this plugin is \u003Cstrong>OAuth-only\u003C\u002Fstrong> by design. It implements the full Microsoft identity platform authorization code flow with automatic token refresh, so you sign in once and it keeps working.\u003C\u002Fp>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>OAuth 2.0 (Modern Auth)\u003C\u002Fstrong> for Microsoft 365 \u002F Entra ID — authorization code flow, automatic access-token refresh, encrypted token storage\u003C\u002Fli>\n\u003Cli>From Email \u002F From Name with optional force-override (recommended — Microsoft rejects mismatched senders)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Test email tool\u003C\u002Fstrong> with a full SMTP debug transcript\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email log\u003C\u002Fstrong> (last 10–500 emails, configurable) with status and error details in a custom table\u003C\u002Fli>\n\u003Cli>Optional \u003Cstrong>fallback to the default PHP mailer\u003C\u002Fstrong> when SMTP fails\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Failure notifications\u003C\u002Fstrong> to the site admin after repeated errors (rate-limited)\u003C\u002Fli>\n\u003Cli>Debug mode compatible with \u003Ccode>WP_DEBUG_LOG\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>Multisite compatible (network activation supported; settings are per-site)\u003C\u002Fli>\n\u003Cli>Secrets (client secret, OAuth tokens) stored \u003Cstrong>encrypted\u003C\u002Fstrong> (AES-256 keyed from your WordPress salts)\u003C\u002Fli>\n\u003Cli>Translation-ready, fully sanitized\u002Fescaped, capability + nonce protected\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Compatibility\u003C\u002Fh4>\n\u003Cp>Works with any plugin that sends mail through \u003Ccode>wp_mail()\u003C\u002Fcode>: WPForms, Contact Form 7, Gravity Forms, Ninja Forms, WooCommerce, Easy Digital Downloads, membership and newsletter plugins, etc.\u003C\u002Fp>\n\u003Ch3>Microsoft 365 \u002F Azure OAuth Setup\u003C\u002Fh3>\n\u003Cp>You need a (free) app registration in Microsoft Entra ID. One-time setup, about 5 minutes:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>1. Register the application\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Sign in to \u003Ca href=\"https:\u002F\u002Fentra.microsoft.com\" rel=\"nofollow ugc\">https:\u002F\u002Fentra.microsoft.com\u003C\u002Fa> (or the Azure Portal \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Microsoft Entra ID).\u003C\u002Fli>\n\u003Cli>Go to \u003Cstrong>Identity \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Applications \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> App registrations \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> New registration\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Name: e.g. \u003Ccode>WordPress SMTP\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>Supported account types:\n\u003Cul>\n\u003Cli>\u003Cem>Accounts in this organizational directory only\u003C\u002Fem> — single company tenant (most common; use your Tenant ID in the plugin).\u003C\u002Fli>\n\u003Cli>\u003Cem>Accounts in any organizational directory and personal Microsoft accounts\u003C\u002Fem> — needed for personal Outlook.com mailboxes (use \u003Ccode>common\u003C\u002Fcode> in the plugin).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Redirect URI: choose platform \u003Cstrong>Web\u003C\u002Fstrong> and paste the exact Redirect URI shown on the plugin’s \u003Cstrong>OAuth 2.0\u003C\u002Fstrong> tab\u003Cbr \u002F>\n(it looks like \u003Ccode>https:\u002F\u002Fyour-site.com\u002Fwp-json\u002Fdxn-outlook\u002Fv1\u002Fcallback\u003C\u002Fcode>).\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Register\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>2. Collect the IDs\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>On the app’s \u003Cstrong>Overview\u003C\u002Fstrong> page copy the \u003Cstrong>Application (client) ID\u003C\u002Fstrong> and \u003Cstrong>Directory (tenant) ID\u003C\u002Fstrong> into the plugin’s OAuth tab.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>3. Create a client secret\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>Certificates & secrets \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> New client secret\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Choose an expiry (set a calendar reminder — you must rotate it before expiry!).\u003C\u002Fli>\n\u003Cli>Copy the secret \u003Cstrong>Value\u003C\u002Fstrong> (not the Secret ID) immediately — it is shown only once — and paste it into the plugin.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>4. Add API permissions\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>API permissions \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Add a permission\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Choose \u003Cstrong>APIs my organization uses\u003C\u002Fstrong> and search for \u003Cstrong>Office 365 Exchange Online\u003C\u002Fstrong>\u003Cbr \u002F>\n(or use \u003Cem>Microsoft Graph \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Delegated\u003C\u002Fem> if \u003Ccode>SMTP.Send\u003C\u002Fcode> appears there in your tenant).\u003C\u002Fli>\n\u003Cli>Select \u003Cstrong>Delegated permissions \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> SMTP.Send\u003C\u002Fstrong>, then Add.\u003C\u002Fli>\n\u003Cli>\u003Ccode>offline_access\u003C\u002Fcode>, \u003Ccode>openid\u003C\u002Fcode>, \u003Ccode>profile\u003C\u002Fcode>, \u003Ccode>email\u003C\u002Fcode> are requested automatically at sign-in; no admin action usually needed. If your tenant requires it, click \u003Cstrong>Grant admin consent\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>5. Enable SMTP AUTH for the mailbox\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Even with OAuth, Exchange Online requires SMTP AUTH to be allowed for the sending mailbox:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Microsoft 365 admin center \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Cstrong>Users \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Active users \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan>\u003C\u002Fstrong> \u003Cem>select user\u003C\u002Fem> \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> \u003Cstrong>Mail \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Manage email apps\u003C\u002Fstrong> \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> check \u003Cstrong>Authenticated SMTP\u003C\u002Fstrong>, or\u003C\u002Fli>\n\u003Cli>PowerShell: \u003Ccode>Set-CASMailbox -Identity user@domain.com -SmtpClientAuthenticationDisabled $false\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>6. Authorize the plugin\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Save the Client ID, Client Secret and Tenant ID on the plugin’s \u003Cstrong>OAuth 2.0\u003C\u002Fstrong> tab.\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Sign in with Microsoft & Authorize\u003C\u002Fstrong> and sign in with the mailbox that should send email.\u003C\u002Fli>\n\u003Cli>When you return, the status shows \u003Cem>Connected\u003C\u002Fem>. Send a test email.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to Microsoft services in order to authenticate and deliver email. No data is sent to the plugin author or any other third party.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Microsoft identity platform\u003C\u002Fstrong> (\u003Ccode>login.microsoftonline.com\u003C\u002Fcode>) — used for OAuth 2.0 sign-in and token refresh. Sends your Azure app Client ID, Client Secret, authorization codes and refresh tokens. Contacted when you click “Sign in with Microsoft” and automatically before sending when the access token needs refreshing.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Microsoft SMTP servers\u003C\u002Fstrong> (\u003Ccode>smtp.office365.com\u003C\u002Fcode> or the host you configure) — used to deliver email. Sends the email content, sender and recipient addresses, and an OAuth access token for authentication. Contacted on every outgoing email.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>These services are provided by Microsoft: \u003Ca href=\"https:\u002F\u002Fwww.microsoft.com\u002Flegal\u002Fterms-of-use\" rel=\"nofollow ugc\">Terms of Use\u003C\u002Fa>, \u003Ca href=\"https:\u002F\u002Fprivacy.microsoft.com\u002Fprivacystatement\" rel=\"nofollow ugc\">Privacy Statement\u003C\u002Fa>.\u003C\u002Fp>\n","Send WordPress emails reliably through Outlook.com \u002F Microsoft 365 SMTP with OAuth 2.0, email logging, and a built-in test tool.",36,"2026-07-21T16:06:00.000Z","7.0.2","6.2","7.4",[26,27,28,29,30],"email","microsoft-365","oauth","outlook","smtp","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdixonsmtp-for-outlook-microsoft-365.1.0.0.zip",null,"2026-07-22T17:31:50.256Z"]