Postkeep sends your WordPress mail through Gmail without an app password: click Connect with Google, sign in, done. The one-click connection is a free service of allinonewpsettings.com (the makers of All-in-One WP Settings): the plugin links your site to a free account there, and that account holds the Google connection on your behalf and hands the plugin a short-lived sending token for each message. Your mail goes from your site to Google; the service never sees a message. One site per free account. The details of what is sent to the service are under “External services” below.
You do not need the service to use the plugin. Every other provider works with a plain SMTP login: Outlook.com and Microsoft 365 (with your own Azure app), Yahoo, Zoho, Yandex, SendGrid, Mailgun, Amazon SES, Brevo, SparkPost, Postmark, your host’s own mail server, or any host and port you type in. Gmail also works with an app password if you prefer not to link the site.
What you get
gmail.send), never the full mailbox.Postkeep and All-in-One WP Settings
This plugin is the SMTP module of All-in-One WP Settings, offered on its own for free. If you later install the suite, it reads the same settings, log and queue, and this plugin steps aside on its own; you can then deactivate it. Nothing is lost either way.
The one-click Gmail connection uses a service at https://allinonewpsettings.com, operated by the makers of All-in-One WP Settings. It is used only when you click “Connect with Google”; if you never click it, the plugin contacts no external service.
What is sent, and when
The service stores your account e-mail address, the site URL, the install identifier and the Google connection (a refresh token and the connected Gmail address). It never receives a message, a recipient or your Gmail password.
Terms of service: https://allinonewpsettings.com/terms-of-service
Privacy policy: https://allinonewpsettings.com/privacy-policy
The mail providers themselves
Sending mail means talking to the provider you chose, with your own account. Those requests go from your site straight to the provider; nothing here passes through allinonewpsettings.com. They happen only for the provider you have configured, and only when your site sends mail or when you connect an account.
/gmail/v1/users/me/messages/send, or /upload/gmail/v1/users/me/messages/send when the message with its attachments is larger than 4 MB. What is sent is the message itself: your sender name and address, the recipients, the subject, the body and any attachments, with the access token for your account. Google’s terms: https://policies.google.com/terms — Google’s privacy policy: https://policies.google.com/privacyEvery other provider — SendGrid, Mailgun, Amazon SES, Brevo, SparkPost, Postmark, Zoho, Yandex, your host’s own mail server, or any host you type in — is reached over plain SMTP at the address you enter, with the credentials you enter, and nowhere else.
The provider list on the settings screen
The settings screen offers thirteen providers to pick from, and each one is a saved set of starting values for the form: a port, an encryption setting, a link to that provider’s own setup documentation — for example https://developers.sparkpost.com/api/smtp/ for SparkPost — and, for the named services, their mail server, such as email-smtp.us-east-1.amazonaws.com for Amazon SES or smtp.sendgrid.net for SendGrid. (“Shared Hosting” fills in mail. and your own domain; “Custom SMTP Server” fills in nothing and waits for you.) Picking a provider fills the form in for you; nothing is contacted when you pick one, and the documentation link only opens in your browser if you click it. The plugin sends mail to the server in the form after you have saved it, with the credentials you entered, and it contacts no other address. So the provider names and hostnames in the plugin’s code are a list of choices available to you, not services this plugin talks to: a site that never picks Amazon SES never reaches Amazon, and the same for every other name on the list.
One more address appears in the plugin’s code and is not a service it contacts: https://api.wordpress.org/secret-key/1.1/salt/ is named in an admin message that tells you where to generate WordPress’s security keys when your wp-config.php has none. It is text in a warning on your own screen; the plugin makes no request to it.