Missivus for WordPress
Everything WordPress sends — password resets, order confirmations, form notifications — delivered through Microsoft Graph as one free shared mailbox. No SMTP, no user login, no paid add-on.
SMTP AUTH basic authentication is disabled by default for Microsoft 365 tenants from the end of December 2026, and unavailable by default for new tenants after that; final removal will be announced for late 2027. Updated timeline (January 2026)
What it does
Every email WordPress produces
Missivus short-circuits wp_mail() itself, through WordPress's own pre_wp_mail seam, into the Graph API. HTML and plaintext, multiple recipients, Cc, Bcc, Reply-To, attachments — there is nothing to switch over form by form.
One mailbox, enforced by Exchange
Designed around an application access policy scoped to a single free shared mailbox. Even a fully leaked credential can send as exactly one no-reply address — and the install guide treats that step as first-class, with a command to verify it took effect.
Large attachments handled
Files under 3 MB go inline; anything larger is uploaded through a Graph upload session automatically. There is no setting that can get this wrong.
Secret or certificate
A client secret is the quickest way in and is the default; certificate authentication is supported as optional hardening. Nothing gets reinstalled when you switch.
Secrets can stay out of the database
Every value can come from a MISSIVUS_* constant in wp-config.php, which then wins over the settings UI and is never written to the options table.
Fails loudly, never silently
A Graph failure is logged at error level and announced on wp_mail_failed with the exact Microsoft error attached. A test-email button shows you precisely what Microsoft returned. The fallback to WordPress's own transport is off by default.
Why another Office 365 mail plugin?
The usual WordPress mailers for Microsoft 365 use delegated authentication — a human clicks "Connect" and mail goes out as that person's account. That is the wrong shape for a server.
| Missivus — application permission | Delegated mailers | |
|---|---|---|
| Who sends | A shared mailbox — free, no licence | A named person's account |
| Setup | Nothing to click — client credentials | A human clicks "Connect" |
| Survives an employee leaving | Yes — no user involved | No — breaks with their account |
| Reach if the credential leaks | One mailbox, enforced by Exchange | Whatever that person can reach |
| Cost | Free — GPLv3 | Often a paid extension |
Requirements
- WordPress 5.7 or later, PHP 7.2 or later with the openssl and json extensions — no Composer, no SDK, no third-party runtime dependencies
- A Microsoft 365 tenant and an administrator who can create an app registration, grant admin consent and run one Exchange Online PowerShell command
- A shared mailbox to send from — it needs no licence
- About thirty minutes for the one-time Microsoft setup
Get the plugin
Download from GitHub
Release zip, source, changelog and issue tracker.
WordPress.org directory
The listing in the WordPress plugin directory is in review — until it is live, install from the GitHub release zip.
Two ways to get it running
Install it yourself
The installation guide is written for someone who has never opened Microsoft Entra — every click spelled out. Budget half an hour for the Microsoft side.
Have Solvetus install it
One appointment — Entra app, access policy, mailbox, plugin, test email, handover document. The software stays free; you pay for the hour, not the tool.