Transactional email is the mail your website or app sends to one person because of something they did: a password reset, an order receipt, an OTP or a login alert. It has to arrive quickly and land in the inbox, so how you send it matters more than how much you send. This short guide shows which sending routes work on Domain India hosting and what every route needs in DNS.
For a contact form or a few messages a day on shared hosting, send with PHP mail() and the -f envelope sender; SMTP from PHP fails on our cPanel servers because the socket functions it needs are disabled. For password resets, receipts and anything at volume, use a transactional email API such as Amazon SES, SendGrid, Mailgun, Postmark or Resend over HTTPS. Whichever you choose, publish SPF, DKIM and DMARC for your domain before you send.
For provider-by-provider details and code samples, read Email services compared: SendGrid, SES, Mailgun, Postmark, Resend. For sending from PHP on shared hosting, read Sending email from PHP. This page is the short version.
1. The three ways to send
| Route | Where it works | Good for | Watch out for |
|---|---|---|---|
| PHP mail() with -f | cPanel, DirectAdmin and Webuzo shared hosting | Contact forms and low-volume notices | Outgoing limits per account; no delivery tracking |
| SMTP from your code | Your own VPS or server | Apps that already speak SMTP | Fails from PHP on our cPanel servers (socket functions disabled); on DirectAdmin, test on your plan |
| Email API over HTTPS | Anywhere your code can make an HTTPS request | Password resets, receipts, OTPs, any real volume | Needs an account with the provider and its DNS records |
2. Sending from Domain India shared hosting
Shared hosting disables some PHP functions for security. On our cPanel servers these include fsockopen and stream_socket_client, which SMTP libraries use, so PHPMailer in SMTP mode, Symfony Mailer's SMTP transport and most WordPress SMTP plugins fail with a "disabled for security reasons" error. Composer isn't pre-installed on shared hosting, so run composer.phar over jailed SSH (on request), or build your project on your own computer and upload it with the vendor/ folder.
What works:
- PHP
mail()with-f [email protected]. The dependable route. PHPMailer can still compose the message; the working pattern is in How to use PHPMailer for contact forms. - An email API over HTTPS. On our cPanel servers,
curl_exec()keeps working, so provider SDKs and API mailers connect normally. On our DirectAdmin serverscurl_execis usually disabled for websites;file_get_contents()on anhttps://URL works, but test your library first. Details are in PHP disabled functions on shared hosting.
Outgoing mail from the server itself is limited per account: 200 messages per hour on cPanel and 1,000 per day (200 per mailbox by default) on DirectAdmin. Mail sent through an API provider does not count against these limits, because it leaves from the provider's servers.
3. Choosing a provider
All the major providers work the same way: you verify your domain, add the DNS records they give you, create an API key and send with an HTTPS request. They differ in price, dashboards and policy.
Free tiers and prices change often, so check each provider's pricing page on the day you sign up. Keep marketing mail on a separate account, subdomain or provider, so a complaint about a newsletter cannot hurt your password resets.
4. SPF, DKIM and DMARC: required for every route
Add the records wherever your domain's DNS is managed: usually your hosting control panel's zone editor if the domain uses your hosting nameservers. See How to change your domain DNS settings.
SPF lists who may send for your domain. A domain can have only one SPF record, so add each provider to the existing one instead of creating a second:
yourdomain.com. TXT "v=spf1 +a +mx include:sendgrid.net ~all"Replace include:sendgrid.net with the value your provider gives you. Keep whatever your hosting control panel already put in the record.
DKIM signs each message. The provider gives you one or more CNAME or TXT records to add. For mail sent by your hosting server, DKIM is on by default for new cPanel accounts; on DirectAdmin the selector is x, and most domains already have a key. Check with cPanel's Email Deliverability tool or How to check and manage DKIM in DirectAdmin.
DMARC tells receivers what to do when SPF or DKIM does not match your From domain. Start by monitoring:
_dmarc.yourdomain.com. TXT "v=DMARC1; p=none; rua=mailto:[email protected]"Read the reports for a few weeks, then move to p=quarantine and later p=reject.
Since 2024, Gmail and Yahoo require every sender to authenticate with SPF or DKIM. Bulk senders (Gmail's threshold is about 5,000 messages a day to its users) must have SPF, DKIM and DMARC, with the From domain aligned, keep the spam complaint rate below 0.3%, and offer one-click unsubscribe on marketing mail.
5. Handle bounces and test before you launch
- Suppress hard bounces. Every provider can post bounce and complaint events to a webhook. Mark those addresses as undeliverable in your database and stop sending to them.
- Send from your own domain. Never from a Gmail or Yahoo address: their DMARC policies make receivers reject it.
- Test on a tool such as mail-tester.com before going live, and during development use a mail catcher (Mailpit or a service such as Mailtrap) so real users never receive test mail.
Frequently asked questions
Can I use SMTP from PHP on Domain India cPanel hosting?
No. Our cPanel servers disable the PHP socket functions that SMTP libraries use, such as fsockopen and stream_socket_client, so SMTP from PHP fails with a "disabled for security reasons" error. Use PHP mail() with the -f envelope sender, or a transactional email API over HTTPS.
How many emails can I send from shared hosting?
Outgoing mail sent by the hosting server is limited per account: 200 messages per hour on cPanel and 1,000 messages per day (200 per mailbox by default) on DirectAdmin. Mail sent through an external email API does not count against these limits.
Which transactional email provider should I choose?
Amazon SES is usually the lowest cost at volume, SendGrid and Mailgun offer detailed dashboards, Postmark is dedicated to transactional mail, and Resend has a simple developer experience. Check current prices on each provider's site, then compare them in our email services guide.
Do I need SPF, DKIM and DMARC for an email API?
Yes. Add the provider to your single SPF record, publish the DKIM records it gives you, and add a DMARC record. Without them, receivers such as Gmail are likely to send your mail to spam or reject it.
Why do my password-reset emails go to spam?
The usual causes are a missing DKIM or DMARC record, a From address that does not match the sending domain, sending without the -f envelope sender on shared hosting, or a new domain with no sending reputation. Test a message on a tool such as mail-tester.com to see which check fails.
Ready to send? Set up the PHP route with Sending email from PHP, compare providers in Email services compared, or run your app on the App Platform or a VPS. If mail from your account is not leaving the server, open a support ticket.
Our support team can check your SPF, DKIM and DMARC records for a domain hosted with Domain India. Live chat is available 24/7.
Open a support ticket