If a customer receives a WooCommerce password-reset email but your shared inbox no longer receives its copy, do not start by replacing SMTP. WooCommerce 11.2 deliberately restricts Cc and Bcc on messages containing account-access links.
Which messages changed?
The WooCommerce security change covers Reset password, New account and Confirm email address messages. Previously saved additional recipients are ignored, and the related settings are no longer exposed through the REST settings endpoints. The release notes also identify the Back in Stock verification message as receiving the same protection.
A verification or reset URL can authorize an action on someone else's account. Copying the whole message into a help desk, CRM or shared mailbox increases the number of places holding that access-bearing information. A missing copy can therefore be the intended result, not lost customer mail.
Use a two-recipient diagnostic test
Use a staging customer and a mailbox your team controls. Request one reset through the storefront. Record the time, email type and provider message ID privately, but do not put the reset URL into a ticket or screenshot.
| Customer result |
Shared inbox result |
Interpretation |
| Receives message |
No copy |
Consistent with the new recipient restriction |
| No message |
No copy |
Investigate the trigger and delivery path |
| Receives message |
Receives full copy |
Check custom filters, forwarding and mail-provider rules |
| Receives wrong user's message |
Any |
Stop the test and investigate recipient selection |
Provider acceptance is not the same as arrival in the customer's inbox. Check spam and suppression only after confirming which address was intended. Keep password resets separate from order-status messages, which have different triggers.
Recipient: Intended customer verified. Provider: Message disposition recorded. Support: No secret link in task or logs. Control: Order email tested separately. Explanatory checklist, not a customer test result.
Replace the business process, not the protection
If support needs to know that a reset was requested, use a restricted operational event containing the time, internal account reference and delivery status. It should not contain the token, full message body or reusable account link. Set a short retention period appropriate to the support purpose.
If a CRM expects the copied email, identify the exact fields it uses. A workflow that merely opens a support task usually does not need account-access content. Test the replacement with a synthetic account and confirm that it creates one task, not a new task on every mail retry.
The release notes mention developer recipient filters, but using them to restore blanket copying would reintroduce the exposure this change addresses. Have the integration owner review the need and design a less sensitive event instead.
Verify the whole path
Confirm that the customer can complete the intended action, that unrelated people cannot obtain the link through logging or forwarding, and that the replacement support event arrives without secrets. Then run an ordinary order email as a separate control.
Use our order-status email diagnosis when the missing message is a receipt or order update. HandL WP can review the mail integration when plugins and provider rules disagree about recipients.
Reference: WooCommerce email settings.
References reviewed October 8, 2026. Examples are explanatory, not customer test results.