An email has a visible From header and a separate envelope sender used for delivery errors. In PHPMailer, call setFrom() for the visible author and set Sender only when your mail service permits a different bounce address.
Last updated: October 10, 2026.
<?php
use PHPMailer\PHPMailer\PHPMailer;
$mail = new PHPMailer(true);
$mail->isSMTP();
$mail->Host = 'smtp.example.com';
$mail->SMTPAuth = true;
$mail->Username = getenv('SMTP_USERNAME');
$mail->Password = getenv('SMTP_PASSWORD');
$mail->SMTPSecure = PHPMailer::ENCRYPTION_STARTTLS;
$mail->Port = 587;
$mail->setFrom('[email protected]', 'Example Alerts');
$mail->Sender = '[email protected]';
$mail->addAddress($recipient);
$mail->Subject = 'Account notice';
$mail->Body = 'Your account notice is ready.';
$mail->send();Both addresses should belong to domains authorized by the authenticated mail account. Store SMTP credentials outside the web root and rotate them if they are exposed. Many providers rewrite or reject an unauthorized envelope sender.
Understand which address PHPMailer controls
PHPMailer documents the public Sender property as the envelope sender. With SMTP it becomes the address used in the MAIL FROM command. With the local sendmail transport, it can be passed through the -f option when the host allows that behavior.
The receiving system usually creates the final Return-Path header from the SMTP envelope. Do not add that header manually. Keep reply handling separate with addReplyTo() when replies should go somewhere other than the visible sender.
Prefer authenticated SMTP on shared hosting
A shared host may override sendmail parameters, restrict -f, or force a local account as the envelope sender. An authenticated SMTP service makes the sending identity and error response clearer. Follow the provider’s SPF, DKIM, and DMARC requirements, and use a dedicated bounce mailbox or return-path domain when supported.
If delivery still fails, capture PHPMailer SMTP diagnostics without exposing credentials or message content. Continue with sending through SMTP, PHP email delivery troubleshooting, and queueing and retrying email.