# Send email from PHP

Five steps: install Guzzle, create a test key, send to the sandbox, read the log, then verify a domain so you can send to anyone. Using Laravel? The [Laravel quickstart](/docs/quickstart/laravel) uses the `Http` facade instead.

## 1. Install

No SDK needed. The API is plain JSON over HTTPS; any HTTP client works, and Guzzle is the one most PHP projects already have.

**shell**

```bash
composer require guzzlehttp/guzzle
```

## 2. Create an API key

[Sign in](/login), open **API keys** in the dashboard and create a **test** key. It starts with `av_test_`. Export it so the script can read it:

**shell**

```bash
export AVELTO_API_KEY=av_test_...
```

> **Sandbox rules.** Test keys never deliver anything; they run the pipeline and record events. The sandbox sender `you@sandbox.avelto.dev` only delivers to your account's verified owner email and to the simulator addresses `delivered@`, `bounced@` and `complained@sandbox.avelto.dev`. Anything else is refused with `403 sandbox_recipient_not_allowed`. To send to anyone, verify a domain (step 5).

## 3. Send your first email

Every request carries the key as a bearer token. Guzzle throws on a non-2xx status; the `catch` reads the `code` and `message` from the error envelope.

**PHP**

```php
<?php
// send.php
require "vendor/autoload.php";

use GuzzleHttp\Client;
use GuzzleHttp\Exception\ClientException;

$client = new Client([
    "base_uri" => "https://api-staging.avelto.dev",
    "headers" => ["Authorization" => "Bearer " . getenv("AVELTO_API_KEY")],
]);

try {
    $res = $client->post("/v1/emails", ["json" => [
        "from" => "you@sandbox.avelto.dev",
        "to" => "delivered@sandbox.avelto.dev",
        "subject" => "Hello from Avelto",
        "text" => "It works.",
    ]]);
} catch (ClientException $e) {
    $error = json_decode((string) $e->getResponse()->getBody(), true)["error"];
    fwrite(STDERR, $e->getResponse()->getStatusCode() . " {$error["code"]}: {$error["message"]}\n");
    exit(1);
}

$email = json_decode((string) $res->getBody(), true);
echo $email["id"], "\n"; // "9c1f4a52-6f6e-4b8f-9b8e-2e1a5c7d3f10"
```

**shell**

```bash
php send.php
```

The API answers `201 Created` with the email id:

```http
HTTP/1.1 201 Created
Content-Type: application/json

{ "id": "9c1f4a52-6f6e-4b8f-9b8e-2e1a5c7d3f10" }
```

> **Retrying safely.** Send an `Idempotency-Key` header (any unique string, such as your order id) with every `POST /v1/emails`. If the request times out or comes back `429`, `502`, `503` or `504`, wait a moment and send it again unchanged with the same key: the API returns the original email id instead of sending twice. See [Idempotency](/docs/send-email).

## 4. Check the log

Fetch the email by id with the same client. `status` moves from `queued` to `sent` to `delivered`, and `events` records each step: `email.queued`, `email.sent`, `email.delivered`.

**PHP**

```php
$email = json_decode((string) $client->get("/v1/emails/{$email["id"]}")->getBody(), true);

echo $email["status"], "\n"; // "queued", then "sent", then "delivered"
foreach ($email["events"] as $e) {
    echo $e["type"], " ", $e["occurred_at"], "\n";
}
```

```json
{
  "id": "9c1f4a52-6f6e-4b8f-9b8e-2e1a5c7d3f10",
  "mode": "test",
  "from": "you@sandbox.avelto.dev",
  "to": ["delivered@sandbox.avelto.dev"],
  "subject": "Hello from Avelto",
  "status": "delivered",
  "events": [
    {
      "id": "e1f0c3a4-8b2d-4c6e-9a1f-5d7b3e2c8a90",
      "type": "email.queued",
      "payload": {},
      "occurred_at": "2026-09-17T10:12:04.000Z"
    },
    {
      "id": "a7c2e9d1-3f4b-4a8e-b6c0-2d9e1f7b5c34",
      "type": "email.sent",
      "payload": { "test": true, "ses_message_id": "test-9c1f4a52-6f6e-4b8f-9b8e-2e1a5c7d3f10" },
      "occurred_at": "2026-09-17T10:12:06.000Z"
    },
    {
      "id": "c4b8d2f6-7e1a-4d3c-8f9b-6a2e0c5d1b78",
      "type": "email.delivered",
      "payload": { "test": true, "recipients": ["delivered@sandbox.avelto.dev"] },
      "occurred_at": "2026-09-17T10:12:06.000Z"
    }
  ]
}
```

## 5. Verify a domain

Add a domain, publish the DNS records it prints (three DKIM CNAMEs, an SPF TXT and a DMARC TXT), then poll `GET /v1/domains/:id` until `status` is `verified`. The GET re-checks DNS on every call. Use a subdomain such as `mail.acme.com`.

**PHP**

```php
<?php
// verify_domain.php (same $client as send.php)
$res = $client->post("/v1/domains", ["json" => ["name" => "mail.acme.com"]]);
$domain = json_decode((string) $res->getBody(), true);

foreach ($domain["dns_records"] as $r) {
    echo "{$r["type"]}\t{$r["name"]}\t{$r["value"]}\t({$r["purpose"]})\n";
}

// Publish the records, then poll. GET re-checks DNS on every call.
while ($domain["status"] === "pending") {
    sleep(30);
    $domain = json_decode((string) $client->get("/v1/domains/{$domain["id"]}")->getBody(), true);
}
echo $domain["status"], "\n"; // "verified" or "failed"
```

**shell**

```bash
php verify_domain.php
```

Once the domain is verified, switch `AVELTO_API_KEY` to a live key (`av_live_`) and change `from` to an address on it, such as `hello@mail.acme.com`. Nothing else changes.

## Next

- [Send email](/docs/send-email): every field, attachments, tags, scheduling and idempotency.
- [Webhooks](/docs/webhooks): get events pushed to your app.
- [Test mode](/docs/test-mode): test keys, the sandbox sender and the simulator addresses.

---

Rendered page: https://staging.avelto.dev/docs/quickstart/php
