Skip to content
Google WorkspaceAdvanced

Send Landing Page Form Emails Using Google Workspace SMTP on Hostinger

Quick Answer If a plain HTML landing page hosted on Hostinger needs to send form submissions through a Google Workspace mailbox, the recommended implementati...

BI
Bison Technical Team Enterprise IT specialists
Updated 06 Oct 2026 13 min read 0 total views
Structured technical guidanceSafety notes included where requiredSources listed below

Quick Answer

If a plain HTML landing page hosted on Hostinger needs to send form submissions through a Google Workspace mailbox, the recommended implementation is to keep the HTML form on the landing page and submit it to a server-side PHP handler. The PHP handler can use PHPMailer to connect securely to Google Workspace SMTP.

For a direct Google Workspace SMTP connection, use smtp.gmail.com with port 587 and TLS/STARTTLS, or port 465 with SSL. Google also provides smtp-relay.gmail.com as a dedicated SMTP relay option for applications and devices; Google currently recommends SMTP relay for applications. :contentReference[oaicite:0]{index=0}

Advertisement

For the example below, suppose the business mailbox is abc@xyz.com. When a visitor submits the form, the PHP handler can send one notification to abc@xyz.com and a separate confirmation message to the customer's submitted email address.

Recommended Email Flow

The basic architecture should be:

Customer ↓ HTML Landing Page ↓ PHP Form Handler ↓ PHPMailer ↓ Google Workspace SMTP ↓ ┌──────────────────────────────┐ │ Business notification │ → abc@xyz.com │ Customer confirmation │ → customer's email └──────────────────────────────┘

The SMTP credentials must remain on the server. They should never be placed in HTML, JavaScript, or other browser-side code.

Google Workspace SMTP Settings

Setting Value
SMTP server smtp.gmail.com
Port 587
Encryption TLS / STARTTLS
SMTP authentication Enabled
Username Full Google Workspace email address, such as abc@xyz.com
Password App Password where supported
From address abc@xyz.com

Google documents smtp.gmail.com with port 465 for SSL and port 587 for TLS. When using this option, authentication uses the complete Google Workspace email address and an app password. :contentReference[oaicite:1]{index=1}

SMTP Relay Alternative

Google Workspace also provides smtp-relay.gmail.com. Google describes SMTP relay as the recommended option for sending email from applications and devices. SMTP relay can use ports 25, 465, or 587 and can authenticate using configured IP addresses and/or other supported authentication methods. :contentReference[oaicite:2]{index=2}

For a typical shared-hosting landing page, the direct smtp.gmail.com approach can be simpler if the Workspace account is permitted to use an app password. If you want to use Google's SMTP relay instead, configure the relay service in the Google Workspace Admin console first rather than simply changing the hostname in PHP.

Important Change to Google Workspace Authentication

Do not use the normal Google Workspace account password as the SMTP password for a new website integration. Google has discontinued less-secure username/password access for third-party apps and devices. Google's current documentation specifies an app password for the Gmail SMTP-server option, while app passwords require 2-Step Verification. :contentReference[oaicite:3]{index=3}

App passwords may not be available for every Google Workspace account. Google lists organizational restrictions and Advanced Protection among reasons the App Password option may be unavailable. :contentReference[oaicite:4]{index=4}

Security warning: Never place a Google Workspace password, app password, SMTP credential, API key, or other secret in the HTML page or JavaScript. Anyone visiting the page could potentially obtain credentials exposed in browser-side code.

HTML Landing Page Form

The landing page can remain a normal HTML page. Change the form so that it submits to a PHP endpoint on the same hosting account.

<form action="/send-mail.php" method="post"> <input type="text" name="name" placeholder="Your Name" maxlength="100" required> <input type="email" name="email" placeholder="Your Email" maxlength="254" required> <input type="tel" name="phone" placeholder="Phone Number" maxlength="30"> <textarea name="message" placeholder="Your Enquiry" maxlength="5000" required></textarea> <button type="submit">Submit</button> </form>

The exact fields should match the fields used on the advertising landing page.

Server-Side PHP Handler

The PHP handler receives the submitted information, validates it, and sends the messages through SMTP. PHPMailer is preferable to relying on basic PHP mail() for an authenticated SMTP integration. Hostinger also recommends SMTP-based sending for improved functionality and deliverability. :contentReference[oaicite:5]{index=5}

A PHPMailer SMTP configuration for Google Workspace can use:

$mail->isSMTP(); $mail->Host = 'smtp.gmail.com'; $mail->SMTPAuth = true; $mail->Username = 'abc@xyz.com'; $mail->Password = 'YOUR_GOOGLE_APP_PASSWORD'; $mail->SMTPSecure = PHPMailer\PHPMailer\PHPMailer::ENCRYPTION_STARTTLS; $mail->Port = 587;

The sender should normally be the authenticated mailbox:

$mail->setFrom('abc@xyz.com', 'Website Enquiries');

Do not use the customer's submitted email address as the From address. Instead, use it as the Reply-To address:

$mail->addReplyTo($customerEmail, $customerName);

This keeps the message authenticated as being sent by your domain while allowing you to click Reply and respond directly to the customer.

Sending the Business Notification

The first email should contain the customer's submitted information and be sent to the business mailbox.

$mail->setFrom('abc@xyz.com', 'Website Enquiries'); $mail->addAddress('abc@xyz.com', 'Website Enquiries'); $mail->addReplyTo($customerEmail, $customerName); $mail->Subject = 'New Landing Page Enquiry'; $mail->Body = ' <h2>New Website Enquiry</h2> <p><strong>Name:</strong> ' . htmlspecialchars($customerName) . '</p> <p><strong>Email:</strong> ' . htmlspecialchars($customerEmail) . '</p> <p><strong>Phone:</strong> ' . htmlspecialchars($customerPhone) . '</p> <p><strong>Message:</strong></p> <p>' . nl2br(htmlspecialchars($customerMessage)) . '</p> ';

Sending the Customer Confirmation

The second email should be a separate message addressed to the email address entered by the customer.

$confirmation = new PHPMailer(true); $confirmation->isSMTP(); $confirmation->Host = 'smtp.gmail.com'; $confirmation->SMTPAuth = true; $confirmation->Username = 'abc@xyz.com'; $confirmation->Password = 'YOUR_GOOGLE_APP_PASSWORD'; $confirmation->SMTPSecure = PHPMailer\PHPMailer\PHPMailer::ENCRYPTION_STARTTLS; $confirmation->Port = 587; $confirmation->setFrom('abc@xyz.com', 'Your Company'); $confirmation->addAddress($customerEmail, $customerName); $confirmation->addReplyTo('abc@xyz.com', 'Your Company'); $confirmation->Subject = 'We received your enquiry'; $confirmation->Body = ' <h2>Thank you for contacting us</h2> <p>Dear ' . htmlspecialchars($customerName) . ',</p> <p>We have received your enquiry and will contact you shortly.</p> <p>Regards,<br>Your Company</p> ';

In production code, validate all submitted values before using them and handle exceptions so that SMTP errors are logged server-side rather than exposing technical details to visitors.

Recommended Sender and Reply-To Configuration

Email From To Reply-To
Business notification abc@xyz.com abc@xyz.com Customer's submitted email
Customer confirmation abc@xyz.com Customer's submitted email abc@xyz.com

This is preferable to dynamically changing the sender to the visitor's email address.

Installing PHPMailer on Hostinger

Hostinger documents PHPMailer as an option for PHP websites and explains installation through Composer or manual installation. On plans where Composer is available, Composer is generally the cleaner approach for maintaining the dependency. :contentReference[oaicite:6]{index=6}

A typical project structure can look like:

public_html/ ├── index.html ├── send-mail.php ├── config.php └── vendor/ └── autoload.php

If possible, keep the SMTP configuration in a server-side configuration file outside the publicly accessible web directory. If the hosting environment does not permit a location outside public_html, protect the configuration appropriately and ensure it cannot be downloaded or displayed as source code.

Do You Need to Open an SMTP Port on the Domain?

No. You normally do not add an SMTP port to DNS and you do not need to open an incoming SMTP port on the website.

Your PHP application makes an outbound connection from Hostinger to Google's SMTP service. The relevant setting is therefore in the PHP/PHPMailer configuration:

$mail->Host = 'smtp.gmail.com'; $mail->Port = 587; $mail->SMTPSecure = PHPMailer\PHPMailer\PHPMailer::ENCRYPTION_STARTTLS;

If the Hostinger server cannot establish the outbound connection, check with Hostinger whether outbound SMTP connections to the required Google service and port are permitted for the hosting account.

SPF, DKIM and DMARC

SMTP authentication and domain authentication are related but different. Your sending domain should also have appropriate email authentication configured.

SPF

SPF identifies authorized sending infrastructure for your domain. Google recommends setting up SPF or DKIM for senders, and all systems that send email for the domain should be considered when creating the SPF record. :contentReference[oaicite:7]{index=7}

If Google Workspace is the relevant sender for your domain, Google's SPF documentation provides the appropriate Google SPF configuration. Do not create a second SPF TXT record if your domain already has one; consolidate authorized senders into the existing SPF record. :contentReference[oaicite:8]{index=8}

DKIM

DKIM adds a cryptographic signature to outgoing messages. Google Workspace administrators can generate a DKIM record in the Google Admin console and publish the required public key in DNS. Google recommends a 2048-bit key when the DNS provider supports it. :contentReference[oaicite:9]{index=9}

DMARC

DMARC builds on SPF and DKIM and lets the domain owner specify how receiving systems should handle messages that fail authentication alignment. It is particularly important when a domain is used for business communication and advertising lead generation.

Configure DMARC carefully, especially if other systems besides Google Workspace send mail on behalf of the domain. A restrictive DMARC policy can affect legitimate third-party senders that have not been configured correctly.

Spam Protection for a Google Ads Landing Page

A public advertising landing page should not blindly send every POST request as an email. Bots can repeatedly submit the form and potentially consume sending limits or damage the reputation of the sending system.

Consider implementing:

  • Server-side validation of every submitted field.
  • Reasonable maximum lengths for text fields.
  • Email format validation.
  • Rate limiting by IP or another appropriate mechanism.
  • Google reCAPTCHA or another appropriate anti-abuse mechanism.
  • A honeypot field for simple automated submissions.
  • Logging of failed submissions and SMTP errors without storing unnecessary personal information.
  • HTTPS for the entire landing page and form submission.
Security warning: Do not disable TLS certificate verification merely to make an SMTP connection work. Doing so weakens the security of the connection and can expose credentials or email contents to interception.

Hostinger Email Sending Limits

Hostinger documents limits for server-based email sending, including a limit of 10 emails per minute and up to 100 emails per day for server-based sending on the referenced hosting plans. These limits are separate from Google's own sending limits. :contentReference[oaicite:10]{index=10}

For a Google Ads lead-generation landing page, do not assume that a basic PHP mail setup is suitable for large volumes. If advertising produces significant lead volume, use an appropriate transactional email service or a properly configured Google Workspace relay architecture rather than relying on an unrestricted server-side mail function.

How to Test the Form

Before sending paid Google Ads traffic to the landing page, test the complete delivery chain.

  1. Open the landing page using HTTPS.
  2. Submit a test enquiry using a real test name and message.
  3. Confirm that the business notification arrives at abc@xyz.com.
  4. Confirm that the customer's confirmation arrives at the submitted customer address.
  5. Reply to the business notification and verify that the Reply-To address goes to the customer.
  6. Check the message headers for SPF and DKIM authentication.
  7. Check spam/junk folders if a message does not appear in the inbox.
  8. Test invalid email addresses and missing required fields.
  9. Test repeated submissions to ensure basic anti-spam protection works.
  10. Check the PHP/server error log if the form reports a sending failure.

How to Check SPF and DKIM

When a test message arrives in Gmail, open the message and inspect its authentication information or use Gmail's Show original feature. Google explains that authentication results can show whether SPF and DKIM passed. :contentReference[oaicite:11]{index=11}

A properly authenticated message should show successful authentication results appropriate to the configured sending infrastructure.

Common Problems

Problem Likely area to check
SMTP authentication failed Google Workspace authentication, 2-Step Verification, App Password, or account restrictions
Connection timed out Hostinger outbound SMTP connectivity or server/network restrictions
Form submits but no email arrives PHP handler, PHPMailer exception, SMTP configuration, spam filtering, or recipient address
Email goes to spam SPF, DKIM, DMARC, message content, sender reputation, or recipient filtering
Reply goes to the wrong address Incorrect Reply-To configuration
Customer receives no confirmation Customer email validation, SMTP delivery, spam filtering, or application error
App Password option is unavailable Workspace administrator policy, account configuration, security-key-only 2-Step Verification, or Advanced Protection

Recommended Configuration for This Landing Page

For a simple Hostinger-hosted HTML landing page with a Google Workspace mailbox, a practical starting configuration is:

Component Recommended configuration
Landing page HTML
Form handler PHP
Email library PHPMailer
SMTP server smtp.gmail.com
SMTP port 587
Encryption STARTTLS
Authentication Google Workspace account + supported App Password
Business notification abc@xyz.com
Customer confirmation Submitted customer email
From abc@xyz.com
Customer Reply-To Customer's submitted email
Security HTTPS, server-side validation, rate limiting and anti-spam protection

If App Password authentication is not available or you want a more application-oriented Google Workspace configuration, investigate Google's SMTP relay service instead. Google specifically recommends SMTP relay for applications and devices. :contentReference[oaicite:12]{index=12}

Frequently Asked Questions

Can a plain HTML page send email directly through Google Workspace?

No. Browser-side HTML and JavaScript should not contain SMTP credentials. The form should submit to a server-side application such as PHP, which performs the authenticated SMTP operation.

Should I use port 587 or 465?

Port 587 with TLS/STARTTLS is a good choice for the PHPMailer configuration described here. Google also supports port 465 for SSL. :contentReference[oaicite:13]{index=13}

Can I use my normal Google Workspace password?

You should not use the normal account password for this type of integration. Google's documented Gmail SMTP-server method uses an app password, and app passwords require 2-Step Verification. :contentReference[oaicite:14]{index=14}

Should the customer's email be the From address?

No. Use your authenticated business mailbox as the From address and put the customer's address in Reply-To. This is a better approach for authentication and email delivery.

Do I need to configure port 587 in DNS?

No. SMTP ports are not configured as DNS records. Port 587 is specified in the server-side SMTP configuration.

Can Hostinger send through Google Workspace?

Yes, PHP applications can use SMTP connections to external email services when the hosting environment permits them. Hostinger documents PHPMailer and SMTP-based email integrations. :contentReference[oaicite:15]{index=15}

Should I use PHP mail() instead of PHPMailer?

For an authenticated Google Workspace SMTP integration, PHPMailer is generally the more appropriate implementation because it provides direct SMTP configuration and authentication. Hostinger recommends SMTP-based approaches for improved functionality and deliverability. :contentReference[oaicite:16]{index=16}

What if the App Password option does not appear in Google Workspace?

Check the Google Workspace organization's authentication policies and account security configuration. Google lists several circumstances in which App Passwords may be unavailable. If necessary, use an administrator-configured SMTP relay or another supported authentication method. :contentReference[oaicite:17]{index=17}

Will SPF and DKIM guarantee that messages reach the inbox?

No. SPF and DKIM authenticate the sending domain, but receiving systems also consider spam signals, sender reputation, message content, and other factors. Google explicitly notes that authentication alone does not guarantee delivery. :contentReference[oaicite:18]{index=18}

Conclusion

For a Hostinger-hosted HTML landing page, the clean implementation is to submit the form to a PHP handler and use PHPMailer to send authenticated email through Google Workspace. For the direct Gmail SMTP method, configure smtp.gmail.com, port 587, and TLS/STARTTLS, with a supported Google Workspace authentication method. :contentReference[oaicite:19]{index=19}

The business notification should go to abc@xyz.com, while a separate confirmation can be sent to the customer's submitted email. Keep SMTP credentials entirely server-side, validate and protect the form against abuse, and verify SPF/DKIM authentication before directing paid Google Ads traffic to the landing page.

Sources

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy. Unsubscribe at any time.