Security and privacy, specifically
An email plugin holds the keys to your domain’s reputation. Here is exactly what BooleanSMTP stores, where, and what it sends to whom.
Credentials are encrypted at rest
Passwords, API keys and OAuth tokens are encrypted with AES-256-CBC and authenticated with HMAC-SHA-256 before they are stored, and never shown in full in the admin screens.
The key is your site’s own authentication key, or one generated for the site when none is defined. Define BOOLEAN_SMTP_ENCRYPTION_KEY in wp-config.php to use your own; you can also keep credentials out of the database entirely by defining them in wp-config.php.
Nothing leaves your site unless you configure it
The free plugin contacts a service only when you set up a connection or an alert for it, and only to do what it is for. Nothing is sent anywhere by default, it collects no usage data, and it never contacts a licensing server.
What the OAuth relay sees
When you connect Google or Microsoft with OAuth, the provider sends its one-time sign-in code to oauth.booleansmtp.com, which immediately redirects your browser back to BooleanSMTP in your site’s admin with it. The relay receives only that single-use code and the signed state value that names your site, and stores neither. It never receives your client secret or any token: your site exchanges the code with the provider directly.
Prefer no relay at all? Define BOOLEANSMTP_USE_LOCAL_OAUTH_REDIRECTS as true in wp-config.php and register your site’s own callback URL with the provider.
Your logs stay in your database
Email logs, including message bodies, are stored in your own database only and pruned by the retention setting you choose. Debug log files are off by default; when a developer turns one on, secret-shaped values are masked.
Admin-only access
The REST API BooleanSMTP’s admin screens use is protected by the manage_options capability: only administrators can reach it.
Deleting the plugin deletes its data
Its tables, options, transients, scheduled events and log files are removed. Define BOOLEAN_SMTP_PRESERVE_DATA as true in wp-config.php before deleting it to keep everything for a later reinstall.
Reporting a vulnerability
Email contact@booleansmtp.comwith the details and steps to reproduce. Please give us a chance to fix it before telling anyone else.
Every wp-config.php constant is documented on developers.booleansmtp.com.