SparkPost plugin for WordPress

Install WP Mail SMTP and pick its built-in SparkPost mailer, or install any generic-SMTP mailer plugin and paste SMTP_Injection as the literal SMTP username. The official SparkPost WordPress plugin was closed on the wordpress.org repository in March 2025 for a security issue and has not been reinstated, so all current setups go through a general-purpose mailer plugin. The literal-string username is SparkPost’s signature setup trap: the username field is not the sender’s email, not the account name, and not anything readable; it is the exact seven-character string SMTP_Injection, and pasting anything else produces an authentication failure that reads as wrong password.

For the case for or against SparkPost as a sending service (its 1,000-a-month free tier, the Bird acquisition context, and the flat $20/$75 tier pricing without a published overage rate), start at the Bird / SparkPost review. This page is the setup walk-through. It assumes the decision to use SparkPost has already been made.

Which plugin to install

Three plugin paths reach SparkPost. None of them is a SparkPost-only plugin, because that option no longer exists.

WP Mail SMTP with its SparkPost mailer is the recommended path. WP Mail SMTP ships a dedicated SparkPost option in its mailer picker that calls the SparkPost Transmissions API directly rather than going over SMTP, so there is no literal SMTP_Injection string to remember. Setup is one API key with the Transmissions: Read/Write permission and a from-address. The plugin also adds email logging on its free tier, a setup wizard, and, on Pro, backup connections and smart routing. Pick it for most SparkPost setups from clean.

FluentSMTP or Post SMTP in generic-SMTP mode reaches SparkPost with smtp.sparkpostmail.com (or smtp.eu.sparkpostmail.com for accounts provisioned in the EU region), port 587, STARTTLS, SMTP_Injection as the username, and the API key with Send via SMTP permission as the password. FluentSMTP is the pick when per-address routing rules matter and the site does not want to pay for WP Mail SMTP Pro; Post SMTP is the pick when real-time failure notifications to Chrome, Slack, or Teams matter. Both work fine with SparkPost.

The closed vendor plugin is worth calling out because it still shows up in year-old WordPress search results. The SparkPost plugin by Message Systems was closed on 2025-03-13, was last tested against WordPress 6.3.8, and is no longer downloadable from wordpress.org. Any tutorial that points at it is out of date; do not install it if a copy is found in a plugin repository mirror.

For the plugin-by-plugin comparison in the general case (not SparkPost-specific), see best WordPress SMTP plugins.

Before touching WordPress

SparkPost accepts sends from unverified domains during the initial signup window, but production traffic requires a verified sending domain, and receivers require the DKIM signature that verification unlocks. Two things sit upstream of the WordPress install: an API key scoped correctly for the plugin path, and DNS records at the sending domain.

Generate the API key with the right permission

Log in to the SparkPost dashboard (accounts created after the 2024 Bird rebrand also reach this from bird.com under the SparkPost product tab). Navigate to Account > API Keys > New API Key. Give the key a description that identifies the WordPress site.

The permission selection matters and depends on the plugin path chosen above. For WP Mail SMTP’s native SparkPost mailer, which uses the Transmissions API, tick Transmissions: Read/Write. For generic-SMTP plugins that connect over port 587, tick Send via SMTP. A key without the right permission returns authentication failed on the first test send, which is the second common first-day misdiagnosis. If in doubt, tick both; the risk profile of a WordPress-scoped key with both permissions is not meaningfully different from either alone.

Copy the generated key. SparkPost shows the key value once, at creation; a lost key has to be regenerated.

Verify the sending domain and publish DKIM and SPF

In the SparkPost dashboard, Configuration > Sending Domains > Add a Sending Domain. Enter the domain the WordPress site sends From:, meaning example.com, not mail.example.com. SparkPost returns the DNS records to publish: a DKIM TXT record at scph<year><suffix>._domainkey.<your-domain> (SparkPost rotates the selector suffix per year, so the record name for a new domain today is not the same as for a domain added in 2023), and the SPF include to add to the domain’s existing SPF record.

The SPF record adds include:sparkpostmail.com to the domain’s existing SPF record at the apex. If the domain already has an SPF record covering Google Workspace or another sender, edit it to add the include; do not create a second SPF record at the apex, because a domain with two SPF records at the same name is a permanent SPF error under RFC 7208 regardless of what the records say. If the domain has no SPF record, publish v=spf1 include:sparkpostmail.com -all. The SPF merger folds include:sparkpostmail.com into an existing string and counts the DNS lookups against RFC 7208’s ten-lookup ceiling before you publish.

Return to the SparkPost dashboard and click Verify on the sending domain. Verification is typically minutes when propagation is fast and up to an hour on slow DNS hosts. Both DKIM and SPF must show verified before SparkPost signs sends from that domain with DKIM in production.

DMARC is not SparkPost-specific but is required for domains sending more than 5,000 messages per day to Gmail or Yahoo under their 2024 bulk-sender rules. Publish _dmarc.example.com as TXT v=DMARC1; p=none; rua=mailto:[email protected] as a safe starting point; tighten to p=quarantine or p=reject once reports show no legitimate mail failing alignment. The bulk sender authentication checklist has the full order of operations.

Once DKIM and SPF verify in the SparkPost dashboard, the DNS auth checker reads how the DKIM selector, the apex SPF, and _dmarc look from a receiver’s perspective, which catches nameserver caches and mistyped selectors before real traffic does.

Installing and configuring WP Mail SMTP with SparkPost

The plugin install is standard: Plugins > Add New > search WP Mail SMTP > Install > Activate. On first activation, WP Mail SMTP launches its setup wizard; skip it (click Go Back to the Dashboard) and configure manually so the values below are the ones you set rather than the ones the wizard picks.

In the WP Mail SMTP settings screen, the General tab holds the sender identity. Set From Email to an address at the domain verified with SparkPost and check Force From Email, which stops plugins that hardcode their own sender (WooCommerce order emails, some form plugins) from overriding it. A From: address at an unverified domain is SparkPost’s most common first-day rejection. Set From Name to the site or brand name and check Force From Name for the same reason. Leave Return Path on: Return-Path controls where bounce notifications land, and leaving it on lets SparkPost attribute bounces to the right send instead of dropping them into the WordPress admin inbox. Then set Mailer to SparkPost.

WP Mail SMTP reveals the SparkPost fields once the mailer is selected. Paste the API key (with Transmissions: Read/Write permission) into the API Key field, and pick the region matching the SparkPost account: US for accounts on smtp.sparkpostmail.com, EU for accounts on smtp.eu.sparkpostmail.com. The region selector controls which API endpoint WP Mail SMTP hits; the account is bound to one region at creation and cannot be moved between them, so getting this wrong produces authentication failed even with a correct key.

Save. WP Mail SMTP runs a validate-connection check against the SparkPost API and shows Valid or an error. A Valid result confirms the API key and region are correct and the account is active; it does not confirm that the DKIM and SPF are set up correctly for the from-address, because the validation call does not attempt an actual send.

Under Email Test in WP Mail SMTP, send a test message to an address you can read. Check the HTML toggle if the site’s real mail is HTML. A success message from the plugin means the API accepted the send; verify the message actually arrived at the destination before treating the setup as done, and open the message headers to confirm Authentication-Results shows dkim=pass for the SparkPost DKIM selector and spf=pass for the sending IP. If either fails, the DNS records did not propagate or were entered incorrectly at the DNS host; return to the SparkPost dashboard’s sending domain page and re-check.

For FluentSMTP or Post SMTP over generic SMTP, the settings are Connection Type SMTP, Host smtp.sparkpostmail.com (or smtp.eu.sparkpostmail.com for EU accounts), Port 587 (or 2525 if 587 is blocked upstream), Encryption STARTTLS, Auto TLS on, Authentication PLAIN or LOGIN, Username the literal string SMTP_Injection, Password the SparkPost API key with Send via SMTP permission. The literal username is the trap; do not substitute the account email or anything else that looks like a username.

Sending the first test and reading the failure

The three error patterns worth naming.

Authentication failed on port 587 with a fresh API key. Either the API key is missing the Send via SMTP permission, or the SMTP username is not the literal string SMTP_Injection. Both are equally common first-day misdiagnoses. Log in to SparkPost, edit the API key, tick Send via SMTP, and re-check that the mailer plugin’s SMTP username field is exactly SMTP_Injection with no leading or trailing whitespace and no substitution.

Authentication failed with WP Mail SMTP’s native SparkPost mailer. The API key is missing the Transmissions: Read/Write permission, or the region selector points at US when the account is EU (or vice versa). Regenerate the key with the correct permission and confirm the region matches the SparkPost dashboard URL prefix (app.sparkpost.com for US, app.eu.sparkpost.com for EU).

Domain not verified or unsigned in SparkPost’s message events. The from-address is at a domain SparkPost has not verified, or DKIM has not propagated. Check the SparkPost dashboard’s sending domain page shows both DKIM and SPF verified for the exact domain in the from-address. [email protected] is a different domain to [email protected] under DKIM alignment rules; verify the domain the site actually sends from, not the domain the site is hosted at.

The SparkPost Message Events page shows every send in near-real-time with its delivery status and any bounce reason. Point it at the last hour and the test sends appear near the top; a message that shows delivered in the events log but has not arrived at the destination is a receiver-side delivery decision, not a SparkPost problem, and the message headers (Authentication-Results, Received-SPF) are where the reason lives.

SparkPost-specific things to know

Inbound routing and dedicated IPs are Premier-tier and up. SparkPost’s Starter plan ($20/month) is send-only. WordPress use cases that depend on parsed inbound mail (help-desk plugins, reply-to-post workflows) need the Premier plan ($75/month) or a separate service. Dedicated IPs are also gated at Premier. Sites on Starter share IPs and share the reputation of everyone else on them.

The free tier has no published daily rate limit. SparkPost’s 1,000-a-month free tier does not enforce a daily cap the way Mailjet’s 6,000-a-month tier does with its 200-per-day rule. Bursts inside the monthly allowance are accepted without artificial throttling, which makes SparkPost’s free tier fit occasional-heavy-day sites better than fixed daily-cap tiers do for the same monthly total.

The pricing card does not publish included volume or overage rates. Bird’s Starter and Premier plans are flat monthly prices; the pricing page shows a volume selector from 50K to 5M+ but leaves the included allowance implicit. The effective per-email cost above the free tier’s 1,000-a-month allowance is opaque until sending starts. Sites planning around a specific monthly volume should confirm the allowance with Bird sales before committing.

Log retention is 10 days historically. SparkPost retained message-level events for 10 days on all plans historically; the retention has not been re-confirmed under Bird’s post-acquisition dashboard. Sites that need longer retention should mirror sends to a WordPress email log (Check & Log Email, Log Emails, or WP Mail SMTP’s own log tier) in parallel, because the WordPress log will still have the send after SparkPost’s window closes.

Region choice is baked into the account, not switchable. SparkPost accounts are provisioned in either US or EU at signup, and the region cannot be changed later. The EU endpoint is smtp.eu.sparkpostmail.com and the EU dashboard is app.eu.sparkpost.com; the US variants drop the eu. segment. Sites with a data-residency requirement pick the region at signup, not at the plugin layer.

When another provider fits better

If the WordPress site sends fewer than 3,000 messages per month and wants a no-branding free tier with published pricing that scales predictably, Resend covers the case at a similar volume without SparkPost’s opaque paid-tier allowance. Above the 1,000-a-month free tier, Postmark ($15 for 10,000 messages, no platform subscription, 45-day log retention on Basic) publishes both allowance and per-message cost, which is easier to size than SparkPost’s flat Starter tier. For higher volumes with a WordPress-first workflow, SMTP2GO and Mailgun both publish per-block or per-message pricing on their cards. The SMTP cost calculator runs the crossover math against a site’s actual monthly send volume.

Related

When you are ready to go further: