Tutorials

XenForo Email Setup: SMTP, SPF, DKIM and Bounces

A step-by-step XenForo email setup for 2.2 and 2.3: transport, SPF, DKIM and DMARC, the outbound test and bounce handling, so member emails reach inboxes.

D.C Style · 9 min read
Share on X
An envelope travels from a server past a shield and key into an inbox tray.
On this page

A reliable XenForo email setup needs four things: a sending method your host or mail provider allows, DNS records (SPF, DKIM and DMARC) that prove the mail comes from your domain, a test run, and bounce handling so dead addresses stop hurting your sender reputation. This guide covers each one in order for XenForo 2.2 and 2.3, using the setting names from the Admin CP.

The short answer: what a working XenForo email setup needs

If registration or password reset emails go missing, check these in order:

  1. Transport. Pick how XenForo hands off mail: PHP built-in mail, SMTP or, where available, Google OAuth.
  2. DNS records. Publish SPF, DKIM and DMARC for the domain in your sender address.
  3. Test. Send a test email from the Admin CP and see where it lands.
  4. Bounces. Let XenForo read a bounce mailbox, so it stops mailing addresses that no longer work.

Most problems come from the first two. Change one thing at a time and test after each change.

Step 1: choose a transport in Options > Email options

Open Admin CP > Options > Email options. The setting you want is called Email transport method. A transport is simply the way XenForo passes a finished email to the outside world. The XenForo manual on email lists three choices:

TransportHow it worksGood for
PHP built-in mailHands each email to a mail program on your server. The manual calls this the preferred option because it performs better.Servers with a working mail program and good DNS.
SMTPXenForo connects to an outside mail server and sends each email itself. Slower, but it can reduce the chance of mail being seen as spam.Shared hosting, or forums using a mail service.
Google OAuthSends through Google using OAuth 2.0 credentials instead of a plain password.Forums sending through a Google account.

The current manual lists Google OAuth but doesn't say which version added it. If you don't see it on your 2.2 forum, use SMTP instead. The manual lists Google as the only OAuth option.

Filling in xenforo smtp settings

If you choose SMTP, your mail provider gives you a host, port, encryption type, username and password. Copy them exactly. Port 587 usually pairs with STARTTLS and port 465 with SSL/TLS, but follow what your provider says.

For Google OAuth, you create a project in Google's Developer Console with OAuth 2.0 credentials for a web application. XenForo shows step-by-step instructions on screen during setup.

The other email options

  • Default email address: the sender address. It must be a valid address, ideally on your forum's own domain.
  • Bounced email address: where bounce messages go. If you leave it empty, bounces go to the default address.
  • Default email sender name: replaces the board title as the name members see.

Step 2: add SPF, DKIM and DMARC so mail lands in the inbox

Mail services like Gmail check whether your email is allowed to come from your domain. Three DNS records answer that:

  • SPF lists the servers allowed to send mail for your domain.
  • DKIM adds a signature to each email, which receivers check against a public key in your DNS.
  • DMARC tells receivers what to do when SPF or DKIM fails, and where to send reports.

The XenForo manual doesn't cover SPF or DMARC, so this part of your XenForo email setup draws on mail provider guidance and experienced XenForo admins.

If you send through an SMTP provider

Services like SES, SparkPost or SendGrid give you their own SPF and DKIM records to add in DNS, as members describe in this thread on xenforo dkim spf with SMTP services. Add those, then set up DMARC yourself. The provider signs the mail, so you don't need XenForo's own DKIM option.

If your server sends the mail itself

XenForo has built-in DKIM signing. A XenForo developer said it was implemented in 2.2.9. According to one moderator's post, the setting sits with the email options; look for Enable DKIM. He says XenForo shows the DNS records to add automatically. Copy them into your DNS exactly as shown.

Note:
XenForo's DKIM option applies only when the domain in your sender address matches the DKIM domain. Keep your default email address on the domain you sign for.

A basic SPF and DMARC pair looks like this. Replace the placeholders with your own values:

example.com.         TXT  "v=spf1 a mx include:your-provider ~all"
_dmarc.example.com.  TXT  "v=DMARC1; p=none; rua=mailto:dmarc@example.com"

Starting DMARC at p=none lets you read reports before you tighten it. Experienced admins also advise a matching reverse DNS (PTR) record for your server's IP, which your host sets. None of this guarantees inbox delivery, but missing records make the spam folder far more likely.

Step 3: send a test with the built-in outbound email test

Open Tools > Checks and tests > Test outbound email. The Checks and tests page explains that it checks your server can send email and helps diagnose problems.

  1. Send a test to an address at a big provider, such as Gmail or Outlook.
  2. If XenForo shows an error, fix the transport settings first. Read the message closely; it often points to the login, host or port.
  3. If it sends, check the inbox and the spam folder.
  4. Open the message's original source (most webmail has a "show original" option) and check that SPF, DKIM and DMARC pass.

Then do a real check: register a test account and request a password reset. These are the emails members depend on most.

Step 4: turn on bounce and unsubscribe handling

A bounce is the automatic reply you get when an email can't be delivered. Mailing dead addresses again and again hurts your sender reputation. XenForo can read a bounce mailbox over POP3 or IMAP and stop mailing those members.

  1. Create a mailbox for bounces and enter it as the Bounced email address.
  2. In Email options, enable the automated bounce handler and choose POP3 or IMAP.
  3. Enter that mailbox's host, port, encryption, username and password. It doesn't need to be on the same server or domain as your outgoing mail.
  4. Set up the unsubscribe handler the same way if you use it.
  5. Check that it connects. Users report running the bounce and unsubscribe crons manually to catch errors right away.

Admins report success with IMAP on port 993 with SSL, or POP3 on port 995 with SSL. A "connection error" often means the wrong port or encryption. On XF 2.2, the error "Bounce connection error: cannot login, user or password wrong" means the mailbox login details are wrong.

On 2.2, an address must bounce a set number of times (3 by default) or within a set number of days before it's marked as bounced, as a moderator explains in this thread on xenforo email bounce handling. The member's status then becomes "Email invalid (bounced)" and XenForo stops mailing them.

Common problems: emails not sending, landing in spam, or hitting provider limits

XenForo emails not sending at all

Run the outbound test. With PHP built-in mail, your host may not run a mail program or may block it, so switch to SMTP. With SMTP, check the host, port and encryption, and ask your host whether outgoing SMTP ports are blocked.

Emails land in spam

Check the message source from Step 3. A failed SPF or DKIM result points to a missing or wrong DNS record. Also make sure your sender address uses the domain you signed for.

Sending slows down after enabling DKIM

An early bug made DKIM signing slow. It's marked fixed, so update XenForo if you're on an older 2.2 release.

Mail stops partway through the day

Many SMTP providers cap how much you can send in a given period. A busy forum can hit that cap with notifications, and then password resets fail too.

When one SMTP provider is not enough: limits, failover and separate routes

XenForo's built-in settings take one transport. That's fine for many forums. It becomes a problem when one provider's limit or outage stops every email, including account and security mail. With only the built-in settings, your option is to notice the problem and switch providers by hand.

Smart Mail Router handles this for you. You add several SMTP providers, each with optional sending limits over rolling 60-minute and 24-hour windows. You can send account and security emails through one provider and notifications and digests through another. When a limit is reached, mail waits in a persistent queue, and temporary failures can move to a backup provider. It needs XenForo 2.2 or later and can import your existing password-based SMTP settings, so your current XenForo email setup is a starting point, not wasted work.

The steps are in the guides: install and set up Smart Mail Router, route emails by type or recipient domain and fix queued or failed email.

Checklist before you change mail settings on a live forum

  • Write down your current Email options so you can switch back.
  • Add the DNS records your new provider needs before you switch transports.
  • Change one setting at a time, then run the outbound test.
  • Test a registration and a password reset with a real account.
  • Check for errors after the bounce and unsubscribe crons run.
  • Keep sending limits below your provider's allowance if other apps share the account.

What to do next

Start with Step 3: run the outbound test now and look at the message source. If SPF and DKIM pass and the mail reaches the inbox, turn on bounce handling and your XenForo email setup is done. If one provider's limits keep causing trouble, plan a second route before your next busy week.

Sources