=== Postkeep – One Click SMTP Setup and Email Log ===
Contributors: kenanafsarcom
Tags: smtp, gmail, email, wp mail, email log
Requires at least: 6.3
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.2
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Gmail without an app password, or any SMTP server: reliable WordPress mail with an email log, a retry queue and a test tool.

== Description ==

Postkeep sends your WordPress mail through Gmail without an app password: click Connect with Google, sign in, and your mail starts going out through that account. If the site is already sending through an SMTP server of its own, Postkeep leaves it alone and the connected card offers a "Use this account for sending" button instead — switching over is your decision, not ours. The Gmail connection is a free service of allinonewpsettings.com (the makers of All-in-One WP Settings): the plugin links your site to a free account there, and that account holds the Google connection on your behalf and hands the plugin a short-lived sending token for each message. Your mail goes from your site to Google; the service never sees a message. One site per free account. The details of what is sent to the service are under "External services" below.

You do not need the service to use the plugin. Every other provider works with a plain SMTP login: Outlook.com and Microsoft 365 (with your own Azure app), Yahoo, Zoho, Yandex, SendGrid, Mailgun, Amazon SES, Brevo, SparkPost, Postmark, your host's own mail server, or any host and port you type in. Gmail also works with an app password if you prefer not to link the site.

**What you get**

* Gmail through the Gmail API, signed in once with no app password, with the narrow send-only permission (`gmail.send`), never the full mailbox.
* Any SMTP server: presets for the common providers, or your own host, port and encryption.
* An email log: every message with its status, and the reason when one failed — which stage broke (name lookup, connection, encryption, sign-in, recipient, transfer) and what the server said, with credentials redacted.
* A retry queue: a message the server refused is queued and tried again hourly.
* A test tool that tells you where a failure happened instead of "could not send".
* Passwords and tokens encrypted at rest with your site's security keys.
* A copy-for-support summary on the Help tab: versions, the sending setup and the last failures, with no secret in it, ready to paste into a forum post.
* Every string ready for translation, and German and Turkish already written: they are being imported to translate.wordpress.org, which is where WordPress.org builds and delivers language packs from. Until that import is through, the plugin reads in English.

**Postkeep and All-in-One WP Settings**

This plugin is the SMTP module of All-in-One WP Settings, offered on its own for free. If you later install the suite, it reads the same settings, log and queue, and this plugin steps aside on its own; you can then deactivate it. Nothing is lost either way.

== External services ==

The free Gmail connection uses a service at https://allinonewpsettings.com, operated by the makers of All-in-One WP Settings. It is used only when you click "Connect with Google"; if you never click it, the plugin contacts no external service.

**What is sent, and when**

* When you click "Connect with Google" on a site that is not yet linked: the site's URL, a random install identifier, the plugin, WordPress and PHP versions and the site's language, to obtain a sign-in link. Your browser then opens that link and you sign in to, or register with, allinonewpsettings.com. The plugin then exchanges a one-time code for a licence key and an activation token, which it stores encrypted.
* When the Google sign-in starts: the licence key, activation id and site URL, and the plugin's capabilities, to obtain the Google consent page. Google's own consent screen then asks you for permission to send mail as you.
* Every time a message is sent through the connection: the licence key, activation id and site URL, to obtain a short-lived Google access token. The message itself is sent from your site directly to Google's Gmail API and never passes through the service.
* Once a day: the licence key, activation id and site URL, to confirm the licence is still valid.
* When you click Disconnect: the same identifiers, so the service revokes the Google connection. When you delete the plugin: the same, so your site leaves the free licence.

The service stores your account e-mail address, the site URL, the install identifier and the Google connection (a refresh token and the connected Gmail address). It never receives a message, a recipient or your Gmail password.

Terms of service: https://allinonewpsettings.com/terms-of-service
Privacy policy: https://allinonewpsettings.com/privacy-policy

**The mail providers themselves**

Sending mail means talking to the provider you chose, with your own account. Those requests go from your site straight to the provider; nothing here passes through allinonewpsettings.com. They happen only for the provider you have configured, and only when your site sends mail or when you connect an account.

* **Google — sending.** When Gmail is your provider and the account is connected (through the free Gmail connection above, or through your own Google app), each message is posted to the Gmail API at https://gmail.googleapis.com — `/gmail/v1/users/me/messages/send`, or `/upload/gmail/v1/users/me/messages/send` when the message with its attachments is larger than 4 MB. What is sent is the message itself: your sender name and address, the recipients, the subject, the body and any attachments, with the access token for your account. Google's terms: https://policies.google.com/terms — Google's privacy policy: https://policies.google.com/privacy
* **Google — signing in with your own app.** If you enter your own Google Client ID and Secret instead of using the free Gmail connection, your browser is sent to https://accounts.google.com to approve it, and the plugin then exchanges the result for tokens at https://oauth2.googleapis.com/token, and refreshes them there. What is sent: your Client ID, your Client Secret and the code or refresh token. Same terms and privacy policy as above.
* **Microsoft — sending and signing in.** With Outlook.com or Microsoft 365 and your own Azure app, your browser is sent to https://login.microsoftonline.com to approve it; the plugin exchanges and refreshes tokens at the same host, reads the mailbox address once from https://graph.microsoft.com/v1.0/me, and posts each message to https://graph.microsoft.com/v1.0/me/sendMail — what is sent: your Client ID and Secret at sign-in, and afterwards the message — sender, recipients, subject, body and attachments. Microsoft Services Agreement: https://www.microsoft.com/en-us/servicesagreement — Microsoft privacy statement: https://www.microsoft.com/en-us/privacy/privacystatement
* **Yahoo — signing in.** With Yahoo Mail and OAuth2, your browser is sent to https://api.login.yahoo.com to approve your own app, and tokens are exchanged and refreshed at the same host; the mail itself then goes over SMTP to Yahoo's mail server. What is sent: your Client ID, your Client Secret and the code or refresh token. Yahoo's terms: https://legal.yahoo.com/us/en/yahoo/terms/otos/index.html — Yahoo's privacy policy: https://legal.yahoo.com/us/en/yahoo/privacy/index.html

Every other provider — SendGrid, Mailgun, Amazon SES, Brevo, SparkPost, Postmark, Zoho, Yandex, your host's own mail server, or any host you type in — is reached over plain SMTP at the address you enter, with the credentials you enter, and nowhere else.

**The provider list on the settings screen**

The settings screen offers thirteen providers to pick from, and each one is a saved set of starting values for the form: a port, an encryption setting, a link to that provider's own setup documentation — for example https://developers.sparkpost.com/api/smtp/ for SparkPost — and, for the named services, their mail server, such as `email-smtp.us-east-1.amazonaws.com` for Amazon SES or `smtp.sendgrid.net` for SendGrid. ("Shared Hosting" fills in `mail.` and your own domain; "Custom SMTP Server" fills in nothing and waits for you.) Picking a provider fills the form in for you; nothing is contacted when you pick one, and the documentation link only opens in your browser if you click it. The plugin sends mail to the server in the form after you have saved it, with the credentials you entered, and it contacts no other address. So the provider names and hostnames in the plugin's code are a list of choices available to you, not services this plugin talks to: a site that never picks Amazon SES never reaches Amazon, and the same for every other name on the list.

One more address appears in the plugin's code and is not a service it contacts: https://api.wordpress.org/secret-key/1.1/salt/ is named in an admin message that tells you where to generate WordPress's security keys when your `wp-config.php` has none. It is text in a warning on your own screen; the plugin makes no request to it.

== Installation ==

1. Upload the plugin to `/wp-content/plugins/postkeep/`, or install it from the Plugins screen.
2. Activate it. A new menu entry, Postkeep, appears.
3. On the Configuration tab, choose a provider. For Gmail, click "Connect with Google" and follow the sign-in; for any other provider, enter the host and login details.
4. For Gmail, that is all: the account starts sending as soon as Google sends you back. If the site was already sending through its own SMTP server, nothing is changed for you — press "Use this account for sending" on the card when you want to switch over. For any other provider, turn the SMTP switch on and save.
5. Send yourself a message from the Test Email tab.

== Frequently Asked Questions ==

= Do I need an account for Postkeep to work? =

Only for the free Gmail connection. Every other provider, and Gmail with an app password, works with no account and contacts no service.

= What does the free account allow? =

One site connected to Gmail through the service. Connecting a second site from the same account moves the connection to it; the service's page says so before it does.

= Which Google permission does the plugin ask for? =

Send-only (`https://www.googleapis.com/auth/gmail.send`). The plugin cannot read, search or delete your mail.

= Why does Outlook / Microsoft 365 not have a Connect button? =

Microsoft requires OAuth2 and does not allow a shared application for it on the free plan. Choose OAuth2 on the Outlook card and enter the Client ID and Client Secret of an app registered in your own Azure portal; the plugin walks you through it. Microsoft sign-in without an Azure app is part of All-in-One WP Settings.

= The connection says it is paused. What now? =

Then the free Gmail connection is closed for the moment. It is a service, and it can be paused for a while — when it is, the plugin says so instead of failing quietly, and an account you have already connected is kept: sending through it resumes when the connection reopens. Meanwhile Gmail works with an app password: choose Gmail, enter the address and the app password, and save.

= Where are my passwords stored? =

In your site's database, encrypted with your site's security keys (AES-256-GCM). A backup or export of the database does not contain them in the clear. If the security keys are ever changed, the plugin tells you which credential to enter again.

One exception, and the plugin says so on its own page when it applies: the encryption needs PHP's openssl extension, which nearly every host has. Without it a password is only encoded, not encrypted, and the Configuration tab shows a warning asking you to have openssl enabled.

= Can I set the SMTP password in wp-config.php instead? =

Yes: `define( 'POSTKEEP_SMTP_PASSWORD', 'your password' );` takes precedence over the saved one, and the settings page says so.

= Where do I get help? =

In the plugin's support forum on WordPress.org. The Help tab has a summary of your setup to paste into your post, with every secret left out.

== Screenshots ==

1. The Configuration tab with Gmail connected through Easy Connect: the provider cards, the connected account, and the line that says mail from this site goes out through it.
2. The Email Log with a failed message opened: which stage broke, what the server said, word for word, and what to do about it.
3. The retry queue: messages the provider refused, each with its retry count, its next try and the reason.
4. The Test Email tab after a successful send: the recipient, the method it went out through, the time, and a link to that message in the Email Log.
5. The Help tab with the copy-for-support summary: versions, the sending setup, the Google connection and the last failures, addresses masked and no secret in it.

== Changelog ==

= 1.0.2 =
* Connecting Gmail now finishes the job. Sign in once and the account starts sending; before this, signing in left it connected but not sending, and you had to pick Gmail in the provider list and save — which the plugin's own description did not say. A site that is already sending through its own SMTP server is never switched over silently: the connected card offers a "Use this account for sending" button, and the choice stays yours.
* Saving the Configuration form no longer asks for an SMTP host when there is none to give — a Gmail connection has no SMTP server — and turning SMTP Status off no longer asks for the settings of the thing being turned off.
* Debug output in the admin JavaScript could print a submitted SMTP password — and a bring-your-own OAuth client secret — in cleartext to the browser console when saving the Configuration tab failed. It is removed. The output was never transmitted anywhere: it went to your own browser's console and no further, only the signed-in administrator who pressed Save saw it, it needed a failed save (a successful one printed nothing), and nothing was written to a file, a database row or a log. If you believe a failed save was captured on a screen share or a recording, rotate the app password, and the client secret too if you use your own OAuth client.
* The Test Email tab's status panel said "From Email Set: Not set" when Gmail was connected. It now names the address mail actually goes out from — the connected account's own. Only the panel was wrong: mail sent through a connected account has always gone out from that account.
* Signing in to Gmail no longer asks you to press Connect twice. After the e-mail confirmation the plugin now goes on to Google by itself; before, it came back to the settings page and the sign-in had to be started again. If it still cannot start, you stay on the page with a sentence that says why and the button is there.
* The connected card no longer says "This account is connected but is not sending" for a moment on the way back from Google and then take it back. While it reads the connection's real state it says "Finishing the sign-in…" and nothing else.
* When the Gmail sign-in cannot start, the plugin says so instead of saying the connection service could not be reached. It told you to check a connection that was working.
* The description and the installation steps now say what the plugin actually does, step by step.

= 1.0.1 =
* Fixed a fatal error on activation on WordPress 6.8 and older. Those versions ship PHPMailer without its OAuthTokenProvider interface, and the plugin required that file outright. It is now loaded only when WordPress has it, and declared by the plugin when WordPress does not. Nothing else changed.

= 1.0.0 =
* First release: the SMTP module of All-in-One WP Settings on its own, with the free Gmail connection.

== Upgrade Notice ==

= 1.0.2 =
Sign in to Gmail once and the account starts sending. Also removes debug output that could print a submitted SMTP password to your own browser console when a save failed; nothing was transmitted or stored, but rotate the app password if a failed save may have been recorded.

= 1.0.1 =
Fixes a fatal error on activation on WordPress 6.8 and older. Update before activating.

= 1.0.0 =
First release.
