The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →To blind-copy someone on a message sent with PHP’s mail(), add a Bcc header in the function’s additional headers. PHP 7.2.0 and later support passing headers as an array; older PHP versions need a CRLF-separated header string. Include a From header and keep untrusted input out of header values unless it has been validated.
Use an array of headers in PHP 7.2.0 or later
The PHP manual’s mail() example supports an array for additional headers. Set Bcc to the address that should receive a blind copy:
<?php
$to = '[email protected]';
$subject = 'Example message';
$message = "Hellorn";
$headers = [
'From' => 'Website <[email protected]>',
'Bcc' => '[email protected]',
];
$accepted = mail($to, $subject, $message, $headers);
?>
Replace the example addresses and message with your application’s values. The primary recipient belongs in $to; the blind-copy recipient belongs in the Bcc additional header. This array form is available starting with PHP 7.2.0, according to the PHP mail() manual.
Use a header string on older PHP versions
Before PHP 7.2.0, pass additional headers as a string, separating each header with CRLF (rn):
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
$headers = "From: Website <[email protected]>rn";
$headers .= "Bcc: [email protected]";
$accepted = mail($to, $subject, $message, $headers);
Use a valid line break between headers; do not place a second header inside an unvalidated value. The PHP manual documents both the additional-header argument and the newer array form at php.net/manual/en/function.mail.php.
Protect header values from injection
Do not insert raw request data into a header. An attacker who can supply line breaks in a value may be able to add unintended headers. PHP’s manual warns that externally sourced header data should be sanitized to prevent unwanted headers from being injected. Validate email addresses and reject CR or LF characters in any dynamic header value before building the headers; when possible, use fixed, application-controlled header names and values.
Rank #2
The From header should be supplied either in the additional headers or through the configured default, as the PHP manual explains. The example includes it explicitly so the sender is clear in the script.
Understand what mail() returning true means
A true return means PHP accepted the message for delivery; it does not confirm delivery to the recipient’s mail server or inbox. A false return means the call was not accepted. The PHP manual makes this distinction explicit in its return-value guidance.
Recommended Free Tools
For troubleshooting, check the return value and investigate the configured mail transport and its logs. A successful function call alone cannot tell you whether the message was later rejected, filtered, or otherwise failed to arrive.
Check the active mail transport and PHP configuration
The way PHP hands off mail depends on the platform and deployment configuration. The PHP configuration reference lists sendmail_path, sendmail_from, SMTP, and smtp_port. It documents /usr/sbin/sendmail -t -i as the default sendmail_path; this is a documented default, not proof that a particular host uses it. Check the active configuration and hosting environment in the PHP mail configuration reference.
Rank #4
PHP’s manual distinguishes its Windows implementation, which talks directly to an SMTP server, from the sendmail implementation used elsewhere; handling of custom headers differs. If a BCC header behaves unexpectedly, verify the actual PHP version, platform, transport, and host settings rather than assuming a local development setup matches production. The configuration reference also notes that mail.mixed_lf_and_crlf was added in PHP 8.2.4.
Choose another approach for large sending volumes
The PHP manual cautions that mail() is not suitable for sending large volumes in a loop. Its Windows SMTP implementation opens and closes an SMTP socket for each message. For high-volume sending, the manual points readers toward PEAR mail packages; assess the sending method against your volume and the mail service your host provides.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




