Sound familiar?
- The form says "Thank you" but no email ever arrives
- Enquiries land in junk or spam
- "There was an error trying to send your message" (Contact Form 7)
- Form emails stopped after a hosting move or a change to Microsoft 365
- reCAPTCHA errors or the submit button does nothing
- The form is flooded with spam submissions
Key facts
- WordPress sends form emails with PHP mail() by default, which many hosts restrict and inboxes distrust
- Fix: send through authenticated SMTP or a mail API using a plugin such as WP Mail SMTP or FluentSMTP
- The From address must be on your own domain; the visitor's address goes in Reply-To
- SPF, DKIM and DMARC records must authorise whatever service sends the form email
- Caching can break form security tokens, causing "failed to send" errors
- We log every submission in the database too, so no enquiry is lost if email fails
- Most form fixes £45 an hour + VAT
Why website forms stop sending
A contact form has two jobs: accept the visitor's message, and email it to you. The first part almost always works. It is the email that fails, silently, which means a business can go weeks without realising enquiries are vanishing.
By default, WordPress sends email using PHP's built-in mail() function from the web server. That email has no proper authentication, often comes from an address like wordpress@yourdomain that does not exist, and is sent from a server your domain's SPF record does not mention. Gmail, Outlook and Microsoft 365 increasingly treat that as suspicious. Some hosts block mail() entirely. Since Google and Yahoo tightened their sender requirements in 2024, unauthenticated mail is rejected or junked more often than ever.
How we fix form email properly
- Authenticated sending. We install and configure WP Mail SMTP, FluentSMTP or similar so form email goes through a real mail service: your Microsoft 365 or Google Workspace mailbox using OAuth, or a transactional service such as Brevo, Postmark or Mailgun.
- DNS authentication. We add or correct the domain's SPF record to include that service, publish DKIM keys, and set a DMARC policy so receiving servers trust the mail. Watch out for SPF's ten DNS lookup limit; too many includes and SPF fails anyway.
- Correct headers. The From address is a real address on your domain, such as website@yourdomain. The visitor's address goes in Reply-To. Using the visitor's email as From is a classic cause of DMARC failures.
- Test end to end. We send test enquiries to every recipient and check headers for SPF, DKIM and DMARC passes.
Microsoft 365 and Google Workspace gotchas
Many small businesses use Microsoft 365, and it causes specific form problems. SMTP AUTH is disabled by default on newer tenants, and Microsoft is retiring basic (username and password) authentication for SMTP, so old setups that used a mailbox password stop working. We use an OAuth connection or Microsoft Graph API instead. Microsoft 365 can also quarantine or junk mail that claims to come from your own domain but fails authentication. On Google Workspace, app passwords and the SMTP relay service each have their own rules. For mail problems beyond the website, see email deliverability.
When the form itself is broken
Sometimes the problem is on the page, not in the mail. Things we fix:
- Caching and security tokens. Page caches can serve an expired nonce, so submissions are rejected. We exclude form pages or use plugins that refresh tokens.
- JavaScript conflicts. Another plugin or a script optimiser breaks the form's AJAX submit, so the button spins forever.
- reCAPTCHA or Turnstile keys that belong to an old domain, or v2 and v3 keys mixed up.
- Spam floods. We add honeypot fields, Cloudflare Turnstile or reCAPTCHA, and Akismet where suitable, without making the form harder for real people.
- File uploads failing because of PHP upload_max_filesize limits.
- Wrong recipient. The notification still goes to a former employee or an old address nobody checks.
Never lose an enquiry again
Email will occasionally fail, however well it is set up, so we make sure every submission is also saved in the website database (WPForms, Gravity Forms and Fluent Forms do this natively; for Contact Form 7 we add Flamingo). We can also turn on email logging in your SMTP plugin, so if a message bounces you can see why. Forms that collect personal data should also be covered in your privacy notice, see GDPR IT compliance.
Cost
Most form fixes, including SMTP setup and SPF, DKIM and DMARC records, take under two hours at £45 an hour + VAT, 30-minute minimum then 15-minute blocks. On a Business support plan at £50 a month + VAT, this sort of fix comes out of your included hour and we check forms after every update. Tell us what is happening.
What it costs
Support plans from £25 a month + VAT, or £45 an hour + VAT for one-off fixes. Pick a plan if you want it looked after every month, or pay by the hour for a one-off job.
Essential
Keep it updated, backed up and watched.
- Website software updates (core, plugins, themes) applied and checked
- Daily backups
- Uptime monitoring
- Security monitoring
Business
Updates plus an hour of fixes every month.
- Everything in Essential
- 1 hour of fixes or changes every month
- Priority support
Complete
Website and your team's IT, covered.
- Everything in Business
- 3 hours of fixes or changes every month
- IT and Microsoft 365 helpdesk for your team
No plan? The first 30 minutes are the minimum charge, then we bill in 15-minute blocks.
Frequently asked questions
Why does my contact form say sent but I get no email?
The form has worked, but the email failed. Most often WordPress is sending through the server's unauthenticated PHP mail() function and the email is blocked or junked. dijitul support connects the form to authenticated SMTP and sets SPF, DKIM and DMARC so messages are delivered.
Why are my website enquiries going to spam?
Usually because the email is not properly authenticated: it is sent from a server not listed in your SPF record, has no DKIM signature, or uses the visitor's email as the From address and fails DMARC. Fixing the sending method and DNS records solves it.
What is WP Mail SMTP?
WP Mail SMTP is a WordPress plugin that replaces the default PHP mail() function with an authenticated connection to a real mail service, such as Microsoft 365, Google Workspace, Brevo or Postmark. It is one of the tools dijitul support uses to make form email reliable.
My form broke after moving email to Microsoft 365. Why?
Your domain's SPF and DKIM now need to match Microsoft 365, and Microsoft restricts SMTP with plain passwords. The website may still be sending the old way. We reconfigure the form to use OAuth or the Graph API and update your DNS records.
How much does it cost to fix a website form?
dijitul support charges £45 an hour + VAT. Most form problems, including SMTP setup and DNS authentication records, are fixed within one to two hours. On the Business plan at £50 a month + VAT, the fix can come out of your included monthly hour.
How do I stop spam through my contact form?
Use layered protection: a hidden honeypot field, Cloudflare Turnstile or Google reCAPTCHA, and a spam filter such as Akismet. dijitul support sets these up so real visitors are not blocked, and checks the form still sends afterwards.
Related
Get it fixed
One-off fixes are £45 an hour + VAT. You'll know the likely cost before we start.