Lean SMTP Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Lean SMTP makes WordPress send its mail through a real mail service instead of the host’s default PHP mail, which improves deliverability. It is deliberately small: a handful of transports, a handful of settings, no upsells.
Website: https://leansmtp.com
Every provider below also offers plain SMTP, so the SMTP transport alone covers all of them. The API transports exist for hosts that block outbound mail ports (25/465/587), which is common on shared hosting and some managed platforms.
- SMTP — any host/port with TLS, SSL, or no encryption, optional username/password.
- Amazon SES (API) — the SES v2 API, signed with a hand-rolled AWS Signature V4 signer, so no AWS SDK is bundled.
- Mailgun (API) — US or EU region, sending the message as MIME so attachments and formatting survive untouched.
- Resend (API) — a single API key, nothing else to configure.
- Offline — record every message and send nothing, for staging sites that must never mail real customers. wp_mail() still reports success, so plugins behave exactly as they would in production.
- From identity — set the From name and address, and optionally force them over anything another plugin sets.
- Reply-To — a site-wide default for replies, useful when the From address is a no-reply. A Reply-To the message set itself is always kept.
- wp-config.php overrides — pin any setting in code instead of the database, so credentials can live in environment variables and never diverge between environments.
- Failure alerts — an admin notice when mail stops going out, so a broken mailer isn’t discovered via missed password resets. It clears itself once mail works again.
- WP-CLI —
wp lean-smtp testandwp lean-smtp status. - Test email — a button on the settings page to confirm your configuration works.
- Send log — optional; records the most recent sends (recipient, subject, result) with a viewer and a clear button. The message headers, attachment filenames and body can each be recorded too, behind their own settings and off by default.
- Encrypted secrets — stored passwords and API keys are AES-256 encrypted, keyed to your site salts.
Deliberately not included: Gmail and Microsoft 365 OAuth. Both need an OAuth consent flow, refresh-token storage, and (for Google) app verification — more machinery than the rest of this plugin combined. Use an app password or a provider above.
Configuring in wp-config.php
Any setting can be defined as a constant instead of saved in the database. The constant name is the option name in upper case, and it always wins — the settings page shows the field as read-only and names the constant, so what you see is always what is in force. Removing the constant restores whatever was saved before.
define( 'LEAN_SMTP_MAILER', 'ses' );
define( 'LEAN_SMTP_FROM_EMAIL', 'noreply@example.com' );
define( 'LEAN_SMTP_SES_REGION', 'us-east-1' );
define( 'LEAN_SMTP_SES_ACCESS_KEY', 'AKIA…' );
define( 'LEAN_SMTP_SES_SECRET_KEY', getenv( 'SES_SECRET_KEY' ) );
Secrets defined this way are used as-is and are never written to the database. Run wp lean-smtp status to see every setting and where it came from.
External services
Lean SMTP sends email through whichever mail service you configure. When — and only when — you select an API transport and your site sends mail, the plugin connects to that provider’s HTTPS API and transmits the message being sent (recipients, subject, body, headers, and any attachments) along with the credentials you entered, so the provider can authenticate the request and deliver the message. Nothing is sent until you configure and select a transport, and the plugin contacts no other services: there is no telemetry, tracking, or analytics.
The provider you choose is the data controller for the mail you route through it. Review its terms and privacy policy:
- Amazon SES — sends to
email.{region}.amazonaws.com. Terms: https://aws.amazon.com/service-terms/ · Privacy: https://aws.amazon.com/privacy/ - Mailgun — sends to
api.mailgun.netorapi.eu.mailgun.net. Terms: https://www.mailgun.com/legal/terms/ · Privacy: https://www.mailgun.com/legal/privacy-policy/ - Resend — sends to
api.resend.com. Terms: https://resend.com/legal/terms-of-service · Privacy: https://resend.com/legal/privacy-policy
The SMTP transport connects only to the host you configure and bundles no third-party service. The Offline mailer connects to nothing at all: messages are written to the local send log and never leave your server.
Screenshots
Settings page: pick a mailer — including Offline, which records mail without sending it — set the From identity and Reply-To, configure the transport, and choose how much of each message the log keeps.
Amazon SES — region and IAM access key; the secret key is stored encrypted and never shown.
Mailgun — sending domain, US/EU region, and API key.
Resend — a single API key.
Send a test email, and review the optional send log. When message content is recorded, each row expands to show the headers, attachment names and body that were sent.

