# Zoho SMTP configuration — awaiting owner credentials

Private configuration: `/home/www/cas7.net/private/mailserver.json`.

This file lives outside public_html and the Git checkout. Its directory is owner-only (700), and its file permissions are 600. Do not copy it into public assets, Git, `.openai/hosting.json`, a deployment archive, or chat output.

The owner should fill `smtp.password` with a Zoho app-specific password and confirm `smtp.username` is the full authenticating mailbox address. If info@cas7.net is an alias, authenticate using the mailbox that owns it. The sender must be that mailbox or one of its authorized aliases.

Defaults are `smtppro.zoho.com`, port 465, implicit TLS (`smtps`), sender and recipient info@cas7.net. The SMTP host must match the account's region and account type as shown in Zoho settings. Port 587 is also supported by the configuration format when paired with `starttls`.

Leave `enabled` false until the owner confirms that credentials are entered. No credential testing, messages, runtime environment changes, or deployment are performed in this preparation step.

Run `php scripts/check-mail-config.php` for an offline structure and permissions check. It reports missing field names and flags only, never credential values, and never makes a network request.

The current hosted application still has its existing HTTPS email integration and stores inquiries in D1. Sites does not support direct SMTP sockets. After the owner's confirmation, implement and configure an authenticated HTTPS-to-SMTP relay on an SMTP-capable server, using this private configuration. Keep SMTP credentials on the relay server; the Site needs only the relay URL and a separate authentication secret. Enforce certificate verification, fixed configured recipients, request authentication, bounded payloads, and replay protection; never create an open mail relay. Determine the relay service user before granting the minimum necessary file access.

Then test Zoho authentication and a delivery to info@cas7.net, connect the contact endpoint, preserve inquiry storage on mail failure, update owner documentation, and deploy. No relay is live yet.

Zoho reference: https://www.zoho.com/mail/help/zoho-smtp.html
