Send Landing Page Form Emails Using Google Workspace SMTP on Hostinger
Quick Answer If a plain HTML landing page hosted on Hostinger needs to send form submissions through a Google Workspace mailbox, the recommended implementati...
Quick Answer
If a plain HTML landing page hosted on Hostinger needs to send form submissions through a Google Workspace mailbox, the recommended implementation is to keep the HTML form on the landing page and submit it to a server-side PHP handler. The PHP handler can use PHPMailer to connect securely to Google Workspace SMTP.
For a direct Google Workspace SMTP connection, use smtp.gmail.com with port 587 and TLS/STARTTLS, or port 465 with SSL. Google also provides smtp-relay.gmail.com as a dedicated SMTP relay option for applications and devices; Google currently recommends SMTP relay for applications. :contentReference[oaicite:0]{index=0}
For the example below, suppose the business mailbox is abc@xyz.com. When a visitor submits the form, the PHP handler can send one notification to abc@xyz.com and a separate confirmation message to the customer's submitted email address.
Recommended Email Flow
The basic architecture should be:
Customer ↓ HTML Landing Page ↓ PHP Form Handler ↓ PHPMailer ↓ Google Workspace SMTP ↓ ┌──────────────────────────────┐ │ Business notification │ → abc@xyz.com │ Customer confirmation │ → customer's email └──────────────────────────────┘
The SMTP credentials must remain on the server. They should never be placed in HTML, JavaScript, or other browser-side code.
Google Workspace SMTP Settings
| Setting | Value |
|---|---|
| SMTP server | smtp.gmail.com |
| Port | 587 |
| Encryption | TLS / STARTTLS |
| SMTP authentication | Enabled |
| Username | Full Google Workspace email address, such as abc@xyz.com |
| Password | App Password where supported |
| From address | abc@xyz.com |
Google documents smtp.gmail.com with port 465 for SSL and port 587 for TLS. When using this option, authentication uses the complete Google Workspace email address and an app password. :contentReference[oaicite:1]{index=1}
SMTP Relay Alternative
Google Workspace also provides smtp-relay.gmail.com. Google describes SMTP relay as the recommended option for sending email from applications and devices. SMTP relay can use ports 25, 465, or 587 and can authenticate using configured IP addresses and/or other supported authentication methods. :contentReference[oaicite:2]{index=2}
For a typical shared-hosting landing page, the direct smtp.gmail.com approach can be simpler if the Workspace account is permitted to use an app password. If you want to use Google's SMTP relay instead, configure the relay service in the Google Workspace Admin console first rather than simply changing the hostname in PHP.
Important Change to Google Workspace Authentication
Do not use the normal Google Workspace account password as the SMTP password for a new website integration. Google has discontinued less-secure username/password access for third-party apps and devices. Google's current documentation specifies an app password for the Gmail SMTP-server option, while app passwords require 2-Step Verification. :contentReference[oaicite:3]{index=3}
App passwords may not be available for every Google Workspace account. Google lists organizational restrictions and Advanced Protection among reasons the App Password option may be unavailable. :contentReference[oaicite:4]{index=4}
HTML Landing Page Form
The landing page can remain a normal HTML page. Change the form so that it submits to a PHP endpoint on the same hosting account.
<form action="/send-mail.php" method="post"> <input type="text" name="name" placeholder="Your Name" maxlength="100" required> <input type="email" name="email" placeholder="Your Email" maxlength="254" required> <input type="tel" name="phone" placeholder="Phone Number" maxlength="30"> <textarea name="message" placeholder="Your Enquiry" maxlength="5000" required></textarea> <button type="submit">Submit</button> </form>
The exact fields should match the fields used on the advertising landing page.
Server-Side PHP Handler
The PHP handler receives the submitted information, validates it, and sends the messages through SMTP. PHPMailer is preferable to relying on basic PHP mail() for an authenticated SMTP integration. Hostinger also recommends SMTP-based sending for improved functionality and deliverability. :contentReference[oaicite:5]{index=5}
A PHPMailer SMTP configuration for Google Workspace can use:
$mail->isSMTP(); $mail->Host = 'smtp.gmail.com'; $mail->SMTPAuth = true; $mail->Username = 'abc@xyz.com'; $mail->Password = 'YOUR_GOOGLE_APP_PASSWORD'; $mail->SMTPSecure = PHPMailer\PHPMailer\PHPMailer::ENCRYPTION_STARTTLS; $mail->Port = 587;
The sender should normally be the authenticated mailbox:
$mail->setFrom('abc@xyz.com', 'Website Enquiries');
Do not use the customer's submitted email address as the From address. Instead, use it as the Reply-To address:
$mail->addReplyTo($customerEmail, $customerName);
This keeps the message authenticated as being sent by your domain while allowing you to click Reply and respond directly to the customer.
Sending the Business Notification
The first email should contain the customer's submitted information and be sent to the business mailbox.
$mail->setFrom('abc@xyz.com', 'Website Enquiries'); $mail->addAddress('abc@xyz.com', 'Website Enquiries'); $mail->addReplyTo($customerEmail, $customerName); $mail->Subject = 'New Landing Page Enquiry'; $mail->Body = ' <h2>New Website Enquiry</h2> <p><strong>Name:</strong> ' . htmlspecialchars($customerName) . '</p> <p><strong>Email:</strong> ' . htmlspecialchars($customerEmail) . '</p> <p><strong>Phone:</strong> ' . htmlspecialchars($customerPhone) . '</p> <p><strong>Message:</strong></p> <p>' . nl2br(htmlspecialchars($customerMessage)) . '</p> ';
Sending the Customer Confirmation
The second email should be a separate message addressed to the email address entered by the customer.
$confirmation = new PHPMailer(true); $confirmation->isSMTP(); $confirmation->Host = 'smtp.gmail.com'; $confirmation->SMTPAuth = true; $confirmation->Username = 'abc@xyz.com'; $confirmation->Password = 'YOUR_GOOGLE_APP_PASSWORD'; $confirmation->SMTPSecure = PHPMailer\PHPMailer\PHPMailer::ENCRYPTION_STARTTLS; $confirmation->Port = 587; $confirmation->setFrom('abc@xyz.com', 'Your Company'); $confirmation->addAddress($customerEmail, $customerName); $confirmation->addReplyTo('abc@xyz.com', 'Your Company'); $confirmation->Subject = 'We received your enquiry'; $confirmation->Body = ' <h2>Thank you for contacting us</h2> <p>Dear ' . htmlspecialchars($customerName) . ',</p> <p>We have received your enquiry and will contact you shortly.</p> <p>Regards,<br>Your Company</p> ';
In production code, validate all submitted values before using them and handle exceptions so that SMTP errors are logged server-side rather than exposing technical details to visitors.
Recommended Sender and Reply-To Configuration
| From | To | Reply-To | |
|---|---|---|---|
| Business notification | abc@xyz.com | abc@xyz.com | Customer's submitted email |
| Customer confirmation | abc@xyz.com | Customer's submitted email | abc@xyz.com |
This is preferable to dynamically changing the sender to the visitor's email address.
Installing PHPMailer on Hostinger
Hostinger documents PHPMailer as an option for PHP websites and explains installation through Composer or manual installation. On plans where Composer is available, Composer is generally the cleaner approach for maintaining the dependency. :contentReference[oaicite:6]{index=6}
A typical project structure can look like:
public_html/ ├── index.html ├── send-mail.php ├── config.php └── vendor/ └── autoload.php
If possible, keep the SMTP configuration in a server-side configuration file outside the publicly accessible web directory. If the hosting environment does not permit a location outside public_html, protect the configuration appropriately and ensure it cannot be downloaded or displayed as source code.
Do You Need to Open an SMTP Port on the Domain?
No. You normally do not add an SMTP port to DNS and you do not need to open an incoming SMTP port on the website.
Your PHP application makes an outbound connection from Hostinger to Google's SMTP service. The relevant setting is therefore in the PHP/PHPMailer configuration:
$mail->Host = 'smtp.gmail.com'; $mail->Port = 587; $mail->SMTPSecure = PHPMailer\PHPMailer\PHPMailer::ENCRYPTION_STARTTLS;
If the Hostinger server cannot establish the outbound connection, check with Hostinger whether outbound SMTP connections to the required Google service and port are permitted for the hosting account.
SPF, DKIM and DMARC
SMTP authentication and domain authentication are related but different. Your sending domain should also have appropriate email authentication configured.
SPF
SPF identifies authorized sending infrastructure for your domain. Google recommends setting up SPF or DKIM for senders, and all systems that send email for the domain should be considered when creating the SPF record. :contentReference[oaicite:7]{index=7}
If Google Workspace is the relevant sender for your domain, Google's SPF documentation provides the appropriate Google SPF configuration. Do not create a second SPF TXT record if your domain already has one; consolidate authorized senders into the existing SPF record. :contentReference[oaicite:8]{index=8}
DKIM
DKIM adds a cryptographic signature to outgoing messages. Google Workspace administrators can generate a DKIM record in the Google Admin console and publish the required public key in DNS. Google recommends a 2048-bit key when the DNS provider supports it. :contentReference[oaicite:9]{index=9}
DMARC
DMARC builds on SPF and DKIM and lets the domain owner specify how receiving systems should handle messages that fail authentication alignment. It is particularly important when a domain is used for business communication and advertising lead generation.
Configure DMARC carefully, especially if other systems besides Google Workspace send mail on behalf of the domain. A restrictive DMARC policy can affect legitimate third-party senders that have not been configured correctly.
Spam Protection for a Google Ads Landing Page
A public advertising landing page should not blindly send every POST request as an email. Bots can repeatedly submit the form and potentially consume sending limits or damage the reputation of the sending system.
Consider implementing:
- Server-side validation of every submitted field.
- Reasonable maximum lengths for text fields.
- Email format validation.
- Rate limiting by IP or another appropriate mechanism.
- Google reCAPTCHA or another appropriate anti-abuse mechanism.
- A honeypot field for simple automated submissions.
- Logging of failed submissions and SMTP errors without storing unnecessary personal information.
- HTTPS for the entire landing page and form submission.
Hostinger Email Sending Limits
Hostinger documents limits for server-based email sending, including a limit of 10 emails per minute and up to 100 emails per day for server-based sending on the referenced hosting plans. These limits are separate from Google's own sending limits. :contentReference[oaicite:10]{index=10}
For a Google Ads lead-generation landing page, do not assume that a basic PHP mail setup is suitable for large volumes. If advertising produces significant lead volume, use an appropriate transactional email service or a properly configured Google Workspace relay architecture rather than relying on an unrestricted server-side mail function.
How to Test the Form
Before sending paid Google Ads traffic to the landing page, test the complete delivery chain.
- Open the landing page using HTTPS.
- Submit a test enquiry using a real test name and message.
- Confirm that the business notification arrives at abc@xyz.com.
- Confirm that the customer's confirmation arrives at the submitted customer address.
- Reply to the business notification and verify that the Reply-To address goes to the customer.
- Check the message headers for SPF and DKIM authentication.
- Check spam/junk folders if a message does not appear in the inbox.
- Test invalid email addresses and missing required fields.
- Test repeated submissions to ensure basic anti-spam protection works.
- Check the PHP/server error log if the form reports a sending failure.
How to Check SPF and DKIM
When a test message arrives in Gmail, open the message and inspect its authentication information or use Gmail's Show original feature. Google explains that authentication results can show whether SPF and DKIM passed. :contentReference[oaicite:11]{index=11}
A properly authenticated message should show successful authentication results appropriate to the configured sending infrastructure.
Common Problems
| Problem | Likely area to check |
|---|---|
| SMTP authentication failed | Google Workspace authentication, 2-Step Verification, App Password, or account restrictions |
| Connection timed out | Hostinger outbound SMTP connectivity or server/network restrictions |
| Form submits but no email arrives | PHP handler, PHPMailer exception, SMTP configuration, spam filtering, or recipient address |
| Email goes to spam | SPF, DKIM, DMARC, message content, sender reputation, or recipient filtering |
| Reply goes to the wrong address | Incorrect Reply-To configuration |
| Customer receives no confirmation | Customer email validation, SMTP delivery, spam filtering, or application error |
| App Password option is unavailable | Workspace administrator policy, account configuration, security-key-only 2-Step Verification, or Advanced Protection |
Recommended Configuration for This Landing Page
For a simple Hostinger-hosted HTML landing page with a Google Workspace mailbox, a practical starting configuration is:
| Component | Recommended configuration |
|---|---|
| Landing page | HTML |
| Form handler | PHP |
| Email library | PHPMailer |
| SMTP server | smtp.gmail.com |
| SMTP port | 587 |
| Encryption | STARTTLS |
| Authentication | Google Workspace account + supported App Password |
| Business notification | abc@xyz.com |
| Customer confirmation | Submitted customer email |
| From | abc@xyz.com |
| Customer Reply-To | Customer's submitted email |
| Security | HTTPS, server-side validation, rate limiting and anti-spam protection |
If App Password authentication is not available or you want a more application-oriented Google Workspace configuration, investigate Google's SMTP relay service instead. Google specifically recommends SMTP relay for applications and devices. :contentReference[oaicite:12]{index=12}
Frequently Asked Questions
Can a plain HTML page send email directly through Google Workspace?
No. Browser-side HTML and JavaScript should not contain SMTP credentials. The form should submit to a server-side application such as PHP, which performs the authenticated SMTP operation.
Should I use port 587 or 465?
Port 587 with TLS/STARTTLS is a good choice for the PHPMailer configuration described here. Google also supports port 465 for SSL. :contentReference[oaicite:13]{index=13}
Can I use my normal Google Workspace password?
You should not use the normal account password for this type of integration. Google's documented Gmail SMTP-server method uses an app password, and app passwords require 2-Step Verification. :contentReference[oaicite:14]{index=14}
Should the customer's email be the From address?
No. Use your authenticated business mailbox as the From address and put the customer's address in Reply-To. This is a better approach for authentication and email delivery.
Do I need to configure port 587 in DNS?
No. SMTP ports are not configured as DNS records. Port 587 is specified in the server-side SMTP configuration.
Can Hostinger send through Google Workspace?
Yes, PHP applications can use SMTP connections to external email services when the hosting environment permits them. Hostinger documents PHPMailer and SMTP-based email integrations. :contentReference[oaicite:15]{index=15}
Should I use PHP mail() instead of PHPMailer?
For an authenticated Google Workspace SMTP integration, PHPMailer is generally the more appropriate implementation because it provides direct SMTP configuration and authentication. Hostinger recommends SMTP-based approaches for improved functionality and deliverability. :contentReference[oaicite:16]{index=16}
What if the App Password option does not appear in Google Workspace?
Check the Google Workspace organization's authentication policies and account security configuration. Google lists several circumstances in which App Passwords may be unavailable. If necessary, use an administrator-configured SMTP relay or another supported authentication method. :contentReference[oaicite:17]{index=17}
Will SPF and DKIM guarantee that messages reach the inbox?
No. SPF and DKIM authenticate the sending domain, but receiving systems also consider spam signals, sender reputation, message content, and other factors. Google explicitly notes that authentication alone does not guarantee delivery. :contentReference[oaicite:18]{index=18}
Conclusion
For a Hostinger-hosted HTML landing page, the clean implementation is to submit the form to a PHP handler and use PHPMailer to send authenticated email through Google Workspace. For the direct Gmail SMTP method, configure smtp.gmail.com, port 587, and TLS/STARTTLS, with a supported Google Workspace authentication method. :contentReference[oaicite:19]{index=19}
The business notification should go to abc@xyz.com, while a separate confirmation can be sent to the customer's submitted email. Keep SMTP credentials entirely server-side, validate and protect the form against abuse, and verify SPF/DKIM authentication before directing paid Google Ads traffic to the landing page.
Sources
- Google Workspace Admin Help – Send email from a printer, scanner, or app
- Google Workspace Admin Help – Route outgoing SMTP relay messages through Google
- Google Account Help – Sign in with app passwords
- Google Workspace Admin Help – Set up DKIM
- Google Workspace Admin Help – Set up SPF
- Gmail Help – Check if your Gmail message is authenticated
- Hostinger Tutorials – How to send emails from your web server with PHPMailer
Was this guide useful?
Your answer helps us keep BISONKB accurate and practical.