Available now · GPLv3

Missivus for WordPress

Everything WordPress sends — password resets, order confirmations, form notifications — delivered through Microsoft Graph as one free shared mailbox. No SMTP, no user login, no paid add-on.

SMTP AUTH basic authentication is disabled by default for Microsoft 365 tenants from the end of December 2026, and unavailable by default for new tenants after that; final removal will be announced for late 2027. Updated timeline (January 2026)

What it does

Every email WordPress produces

Missivus short-circuits wp_mail() itself, through WordPress's own pre_wp_mail seam, into the Graph API. HTML and plaintext, multiple recipients, Cc, Bcc, Reply-To, attachments — there is nothing to switch over form by form.

One mailbox, enforced by Exchange

Designed around an application access policy scoped to a single free shared mailbox. Even a fully leaked credential can send as exactly one no-reply address — and the install guide treats that step as first-class, with a command to verify it took effect.

Large attachments handled

Files under 3 MB go inline; anything larger is uploaded through a Graph upload session automatically. There is no setting that can get this wrong.

Secret or certificate

A client secret is the quickest way in and is the default; certificate authentication is supported as optional hardening. Nothing gets reinstalled when you switch.

Secrets can stay out of the database

Every value can come from a MISSIVUS_* constant in wp-config.php, which then wins over the settings UI and is never written to the options table.

Fails loudly, never silently

A Graph failure is logged at error level and announced on wp_mail_failed with the exact Microsoft error attached. A test-email button shows you precisely what Microsoft returned. The fallback to WordPress's own transport is off by default.

Delegated mailers vs Missivus

Why another Office 365 mail plugin?

The usual WordPress mailers for Microsoft 365 use delegated authentication — a human clicks "Connect" and mail goes out as that person's account. That is the wrong shape for a server.

Missivus — application permissionDelegated mailers
Who sendsA shared mailbox — free, no licenceA named person's account
SetupNothing to click — client credentialsA human clicks "Connect"
Survives an employee leavingYes — no user involvedNo — breaks with their account
Reach if the credential leaksOne mailbox, enforced by ExchangeWhatever that person can reach
CostFree — GPLv3Often a paid extension

Requirements

  • WordPress 5.7 or later, PHP 7.2 or later with the openssl and json extensions — no Composer, no SDK, no third-party runtime dependencies
  • A Microsoft 365 tenant and an administrator who can create an app registration, grant admin consent and run one Exchange Online PowerShell command
  • A shared mailbox to send from — it needs no licence
  • About thirty minutes for the one-time Microsoft setup

Get the plugin

Download from GitHub

Release zip, source, changelog and issue tracker.

WordPress.org directory

The listing in the WordPress plugin directory is in review — until it is live, install from the GitHub release zip.

Two ways to get it running

Install it yourself

The installation guide is written for someone who has never opened Microsoft Entra — every click spelled out. Budget half an hour for the Microsoft side.

Open the installation guide

Have Solvetus install it

One appointment — Entra app, access policy, mailbox, plugin, test email, handover document. The software stays free; you pay for the hour, not the tool.

Installation & support