DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk3 min

How to Add BCC to a PHP mail() Script

Add a blind-copy recipient to PHP mail() using the Bcc additional header, with examples for modern and older PHP versions and notes on delivery and configuration.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To blind-copy someone on a message sent with PHP’s mail(), add a Bcc header in the function’s additional headers. PHP 7.2.0 and later support passing headers as an array; older PHP versions need a CRLF-separated header string. Include a From header and keep untrusted input out of header values unless it has been validated.

Use an array of headers in PHP 7.2.0 or later

The PHP manual’s mail() example supports an array for additional headers. Set Bcc to the address that should receive a blind copy:

<?php
$to = '[email protected]';
$subject = 'Example message';
$message = "Hellorn";

$headers = [
    'From' => 'Website <[email protected]>',
    'Bcc' => '[email protected]',
];

$accepted = mail($to, $subject, $message, $headers);
?>

Replace the example addresses and message with your application’s values. The primary recipient belongs in $to; the blind-copy recipient belongs in the Bcc additional header. This array form is available starting with PHP 7.2.0, according to the PHP mail() manual.

Use a header string on older PHP versions

Before PHP 7.2.0, pass additional headers as a string, separating each header with CRLF (rn):

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
$headers = "From: Website <[email protected]>rn";
$headers .= "Bcc: [email protected]";

$accepted = mail($to, $subject, $message, $headers);

Use a valid line break between headers; do not place a second header inside an unvalidated value. The PHP manual documents both the additional-header argument and the newer array form at php.net/manual/en/function.mail.php.

Protect header values from injection

Do not insert raw request data into a header. An attacker who can supply line breaks in a value may be able to add unintended headers. PHP’s manual warns that externally sourced header data should be sanitized to prevent unwanted headers from being injected. Validate email addresses and reject CR or LF characters in any dynamic header value before building the headers; when possible, use fixed, application-controlled header names and values.

The From header should be supplied either in the additional headers or through the configured default, as the PHP manual explains. The example includes it explicitly so the sender is clear in the script.

Understand what mail() returning true means

A true return means PHP accepted the message for delivery; it does not confirm delivery to the recipient’s mail server or inbox. A false return means the call was not accepted. The PHP manual makes this distinction explicit in its return-value guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For troubleshooting, check the return value and investigate the configured mail transport and its logs. A successful function call alone cannot tell you whether the message was later rejected, filtered, or otherwise failed to arrive.

Check the active mail transport and PHP configuration

The way PHP hands off mail depends on the platform and deployment configuration. The PHP configuration reference lists sendmail_path, sendmail_from, SMTP, and smtp_port. It documents /usr/sbin/sendmail -t -i as the default sendmail_path; this is a documented default, not proof that a particular host uses it. Check the active configuration and hosting environment in the PHP mail configuration reference.

PHP’s manual distinguishes its Windows implementation, which talks directly to an SMTP server, from the sendmail implementation used elsewhere; handling of custom headers differs. If a BCC header behaves unexpectedly, verify the actual PHP version, platform, transport, and host settings rather than assuming a local development setup matches production. The configuration reference also notes that mail.mixed_lf_and_crlf was added in PHP 8.2.4.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose another approach for large sending volumes

The PHP manual cautions that mail() is not suitable for sending large volumes in a loop. Its Windows SMTP implementation opens and closes an SMTP socket for each message. For high-volume sending, the manual points readers toward PEAR mail packages; assess the sending method against your volume and the mail service your host provides.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.