Configure email delivery and spam protection

Email delivery and bot verification are separate layers. LotPress recommends WP Mail SMTP for authenticated delivery and provides optional customer-owned Cloudflare Turnstile support for contact and vehicle inquiry forms.

Verified with Theme 0.14.2 · Shopper Tools 1.6.3

Understand the delivery path

LotPress sends dealership contact messages and vehicle inquiries through the standard WordPress wp_mail() function. The vehicle form uses the recipient configured in Shopper Tools, then the LotPress sales email, then the WordPress administration email. A valid shopper email is assigned to Reply-To; it is never used as the authenticated sender.

An SMTP or transactional-mail plugin configures wp_mail() globally, so no LotPress-specific mail credentials are required.

Set up WP Mail SMTP

WP Mail SMTP by WPForms is the recommended delivery plugin. Other maintained plugins that correctly configure wp_mail() remain compatible.

  1. Open Plugins → Add New Plugin.
  2. Search for WP Mail SMTP by WPForms, then install and activate it.
  3. Open WP Mail SMTP → Settings and launch the Setup Wizard.
  4. Choose the dealership’s transactional email provider or authenticated SMTP account and complete its connection steps.
  5. Set the From Email to a verified address on the dealership’s domain. Enable Force From Email when available.
  6. Complete the provider’s SPF and DKIM DNS instructions, and review DMARC with the dealership’s email administrator.
  7. Send a test email from WP Mail SMTP. Then submit the LotPress contact form and a vehicle inquiry.

View WP Mail SMTP in the WordPress plugin directory.

Optionally enable Cloudflare Turnstile

Turnstile is optional and disabled by default. The dealership creates and owns its Cloudflare widget.

  1. Sign in to Cloudflare, open Turnstile, and create a Managed widget.
  2. Add the exact hostname visitors use for WordPress, such as www.examplemotors.com. A hostname with www is distinct from the parent hostname.
  3. Copy the site key and secret key.
  4. Open LotPress → Website Settings → Spam Protection. On a standalone Shopper Tools installation, open Inventory → Shopper Tools → Spam Protection.
  5. Enter both keys, enable Turnstile, save, and confirm that its status is active.
  6. Submit the dealership contact form and a vehicle inquiry from a private browser window.

Most visitors will not see an interactive prompt. LotPress uses interaction-only appearance and validates every token on the server before sending email.

Open Cloudflare Turnstile.

Manage Turnstile keys securely

Dashboard keys use one site-wide LotPress configuration. The secret is encrypted before database storage and is never placed back into an HTML field.

Managed installations can define LOTPRESS_TURNSTILE_SITE_KEY and LOTPRESS_TURNSTILE_SECRET_KEY in wp-config.php. Define both together. Never commit a production secret to source control.

Cloudflare testing keys are blocked when WordPress reports a production or staging environment.

Know what LotPress validates

When Turnstile is active, LotPress requires a token, sends it to Cloudflare Siteverify from the WordPress server, and requires a successful response with the exact expected form action and WordPress hostname. Network errors, invalid responses, action mismatches, and hostname mismatches prevent email delivery.

The existing WordPress nonce, honeypot, minimum-completion-time check, validation, and rate limits remain active. LotPress does not send the inquiry message to Cloudflare or log the token, secret, visitor IP address, or message content.

Troubleshoot the setup

  • Turnstile remains off: confirm both keys are present and OpenSSL is available. Re-enter the secret if WordPress security salts changed.
  • Verification always fails: confirm Cloudflare contains the exact active hostname, clear page caches, and verify outbound HTTPS access to challenges.cloudflare.com.
  • Email test succeeds but inquiries do not arrive: confirm the LotPress recipient and check spam, quarantine, and provider logs.
  • Email test fails: rerun the WP Mail SMTP Setup Wizard and verify the provider connection, sender address, DNS authentication, and hosting firewall rules.
Still need help?Tell us what you are trying to accomplish and what happened.
Contact LotPress →