=== AuthenticSender ===
Contributors: alexhedstrom
Tags: smtp, email, mail, phpmailer, usesend
Requires at least: 6.4
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Configure WordPress to send email via SMTP or the UseSend API instead of the built-in mail() function.

== Description ==

AuthenticSender replaces WordPress' default `mail()` function with a configurable SMTP connection or the UseSend HTTP API, giving you control over how your site delivers email.

= Delivery Method =

Choose **SMTP** (default) or **UseSend API**. Existing SMTP configurations keep working unchanged when SMTP is selected.

= SMTP Configuration =

Enable or disable SMTP routing with a single checkbox. When disabled (and not using UseSend API), WordPress falls back to its default `mail()` function. Configure your server connection with:

* **Host** - your SMTP server hostname or IP address
* **Port** - any valid port (1-65535), defaulting to 25
* **Encryption** - None, TLS, or SSL
* **Authentication** - optional username and password (stored encrypted with AES-256-GCM)

= Provider Presets =

Select a preset from the dropdown and the host, port, and encryption fields are filled in automatically. Supported providers:

* Gmail
* SendGrid
* Mailgun
* Postmark
* Hostinger
* UseSend (host `smtp.usesend.com`, username `usesend`, password = your API key)

For a self-hosted UseSend SMTP proxy, use Custom and enter your proxy host with the same username/API-key password pattern.

= UseSend API =

Send mail through the UseSend HTTP API instead of SMTP:

* Encrypted API key storage
* Cloud hosting (`app.usesend.com`) or self-hosted instance URL
* From, Reply-To, BCC, HTML/text, and attachments are mapped to the API

= Sender Identity =

Override the From name and From email address on outgoing emails when SMTP is enabled or UseSend API is selected. Enable **Force Identity** to apply From, Reply-To, and BCC even when using WordPress default mail.

= Additional Headers =

Set global Reply-To (email and name) and BCC addresses. These apply when SMTP is enabled, UseSend API is selected, or when Force Identity is on. The BCC field accepts multiple comma-separated addresses.

Password resets, email confirmations, and similar sensitive messages are never copied to BCC, so reset links and verification tokens are not shared with the BCC address.

= Test Email =

Send a test message directly from the settings page. AuthenticSender attempts delivery via `wp_mail()` and returns a clear success or error message, so a misconfiguration never leaves you guessing.

= Email Log =

Keep a database record of every email sent or failed. The log view includes:

* Timestamp, recipient, subject, status, and delivery method (SMTP, UseSend, or WP Default)
* Error message for failed deliveries
* Filter by All / Success / Failed
* Paginated table (20 entries per page)
* One-click Clear Log with confirmation prompt
* Configurable retention period (1-365 days); older entries are pruned automatically

Logging can be toggled on or off at any time from the Settings tab.

= Security =

* SMTP password and UseSend API key stored encrypted using AES-256-GCM with WordPress `AUTH_KEY` and `SECURE_AUTH_KEY`
* Unique (non-default, non-identical) authentication keys are required before new SMTP passwords or UseSend API keys can be saved; English and localized sample phrases are detected
* Self-hosted UseSend URLs must use HTTPS; localhost, private/reserved IPs, and unresolvable hosts are blocked by default; HTTP redirects are disabled
* Global BCC skips password resets, email confirmations, and similar sensitive mail by default
* Email log redacts subjects for the same sensitive-mail patterns
* Plugin settings (including credentials) are not autoloaded on front-end requests

== Installation ==

1. Upload the `authenticsender` folder to the `/wp-content/plugins/` directory.
2. Activate the plugin through the Plugins menu in WordPress.
3. Go to **Settings > AuthenticSender** and choose SMTP or UseSend API.
4. Open the **Test Email** tab and send a test message to verify everything is working.

== Frequently Asked Questions ==

= Do I need to disable WordPress' default mail() function? =

No. AuthenticSender hooks into PHPMailer (SMTP) or `pre_wp_mail` (UseSend API) automatically. When SMTP is enabled or UseSend API is selected, the default `mail()` function is bypassed; otherwise it is restored.

= Can I use this with Gmail? =

Yes. Select Gmail from the Provider Preset dropdown, then enter your Google account username and an App Password (not your regular Google password). App Passwords are generated at https://myaccount.google.com/apppasswords

= How do I use UseSend? =

Two options:

1. **SMTP** — Delivery Method = SMTP, Provider Preset = UseSend, username `usesend`, password = your API key.
2. **API** — Delivery Method = UseSend API, enter your API key, choose Cloud or Self-hosted (and your instance URL).

= Where are the email logs stored? =

Logs are stored in the WordPress database. No files are written to the filesystem. You can view, filter, and clear the log from the **Email Log** tab in the plugin settings.

= Does the plugin log all emails sent by WordPress? =

Yes, when logging is enabled. This includes password reset emails, WooCommerce order notifications, contact form submissions, and any other email routed through `wp_mail()`.

= What happens if I disable logging after entries already exist? =

Existing entries are preserved. No new entries are written while logging is off. You can re-enable logging at any time or clear the existing log manually.

= Is my SMTP password stored securely? =

Yes. Passwords and UseSend API keys are encrypted with AES-256-GCM using a key derived from your WordPress `AUTH_KEY` and `SECURE_AUTH_KEY` constants before being written to the database.

= When do From, Reply-To, and BCC apply? =

They apply when SMTP is enabled or UseSend API is selected. Turn on **Force Identity** in Sender Identity if you want those overrides while using WordPress default mail.

== Changelog ==

= 1.0.1 =
* Add UseSend SMTP provider preset.
* Add UseSend HTTP API delivery (cloud and self-hosted instance URL).
* Log delivery method as UseSend when the API path is active.
* Warn when WordPress AUTH_KEY / SECURE_AUTH_KEY still use sample defaults.
* Require unique AUTH_KEY / SECURE_AUTH_KEY (including localized samples) before saving new credentials.
* Require HTTPS for self-hosted UseSend; block localhost/private IPs and unresolvable hosts by default; disable HTTP redirects.
* Reject invalid UseSend Instance URLs on save (keep previous value).
* Apply test-email rate limit when sending throws an exception.
* Redact sensitive email subjects in the email log.

= 1.0.0 =
* Initial release.

== Upgrade Notice ==

= 1.0.1 =
Adds UseSend SMTP preset and UseSend HTTP API (cloud or self-hosted). Existing SMTP settings are unchanged.

= 1.0.0 =
Initial release.
