=== MailQuell Email Verification ===
Contributors: mailquell
Tags: email verification, disposable email, woocommerce, fake registrations, contact form 7
Requires at least: 6.0
Tested up to: 6.8
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Blocks fake, mistyped and disposable email addresses on registration, WooCommerce checkout, comments and contact forms.

== Description ==

MailQuell checks an email address the moment a visitor submits a form, and refuses it if it cannot receive email. You get real customers, real leads and fewer bounced order emails, without adding anything visible to your forms.

**Where it checks addresses**

* WordPress registration
* Comments (visitors only, not logged-in users)
* WooCommerce checkout (classic checkout and the block checkout)
* WooCommerce "My account" registration
* Contact Form 7
* WPForms
* Gravity Forms
* Elementor Pro forms

Each one can be switched on or off in Settings > MailQuell.

**What it refuses**

You decide. By default it refuses:

* **Invalid** addresses: the domain does not exist, has no mail server, or the mailbox does not exist.
* **Disposable** addresses from temporary inbox services.
* **Disabled** mailboxes.

You can also refuse role addresses (info@, sales@ …), catch-all domains and other risky addresses.

**Built so it never costs you a customer**

* If MailQuell does not answer within the time you set (4 seconds by default), the address is accepted.
* If your account runs out of credits, or the key is wrong, addresses are accepted and the settings page tells you why.
* Results are cached (30 days by default), so the same address is not checked, or charged, twice.
* An allowlist lets you skip addresses or whole domains, such as your own.

**Requirements**

A MailQuell account and an API key. The free plan includes 200 checks every month plus 100 welcome credits. Each check uses one credit.

== External service ==

This plugin sends data to the MailQuell API to work. It is only used after you enter an API key.

* **What is sent:** the email address typed into a form you enabled, when that form is submitted, together with your API key and your site's address (in the user agent). Nothing else from the form is sent. When you use the "Test an address" button, the address you type is sent.
* **Where:** `https://api.mailquell.com/v1/verify`
* **Why:** to check whether the address can receive email.

MailQuell does not send any email to the address. See the [MailQuell Terms of Service](https://mailquell.com/terms) and [Privacy Policy](https://mailquell.com/privacy).

The plugin adds suggested text for your own privacy policy under Settings > Privacy.

== Installation ==

1. Upload the plugin in Plugins > Add New > Upload Plugin, then activate it.
2. Create a free account at [mailquell.com](https://mailquell.com) and confirm your email address.
3. In MailQuell, open Developer Hub > API Keys and create a key with write permission.
4. In WordPress, open Settings > MailQuell, paste the key and save.
5. Use "Test an address" to check that everything works.

== Frequently Asked Questions ==

= What happens if MailQuell is down or slow? =

The address is accepted. The plugin never blocks a form because of a problem on our side. The number of checks that could not be done is shown on the settings page.

= Does it slow down my checkout? =

A check usually takes well under a second. You can set the maximum wait between 2 and 10 seconds. Addresses already checked are answered from the cache instantly.

= Which credits does it use? =

Your daily plan credits first, then your instant credits if the daily ones run out.

= Can a bot use up my credits? =

Each visitor can have at most 10 new addresses checked per hour (addresses already checked are free). Past that, their submissions go through unchecked and the settings page counts them. Developers can change the number with the `mailquell_lookups_per_visitor_per_hour` filter. Keep a captcha on public forms too.

= Can I change the error message? =

Yes, in the settings. Developers can also use the `mailquell_rejection_message` filter, which receives the message, the status and the address.

= Does it check logged-in users? =

Comments from logged-in users are not checked. Checkout and forms check the address that was typed.

= Can I use my own API address? =

Yes. Add `define( 'MAILQUELL_API_URL', 'https://your-api.example.com' );` to wp-config.php.

== Changelog ==

= 1.0.0 =
* First release: registration, comments, WooCommerce (classic and block checkout, account registration), Contact Form 7, WPForms, Gravity Forms and Elementor Pro forms.
