Add a blind-copy recipient in the additional headers passed to PHP’s mail() function. PHP 7.2.0 and later accept headers as an array; older PHP versions require a CRLF-separated header string. Include a From header, and validate any untrusted values before putting them in headers.
Using BCC with PHP 7.2.0 or later
Since PHP 7.2.0, the fourth argument to mail() can be an array of additional headers. Set a Bcc entry alongside From:
<?php
$to = 'person@example.com';
$subject = 'Example message';
$message = "Hellorn";
$headers = [
'From' => 'Website <webmaster@example.com>',
'Bcc' => 'archive@example.com',
];
$accepted = mail($to, $subject, $message, $headers);
The To argument names the visible primary recipient; the Bcc header adds the blind-copy recipient. The PHP manual’s mail() documentation includes array-form headers and a BCC example.
Using BCC on older PHP versions
For PHP versions earlier than 7.2.0, provide additional headers as a string, with each header separated by CRLF (rn):
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
$headers = "From: Website <webmaster@example.com>rn" .
"Bcc: archive@example.com";
$accepted = mail($to, $subject, $message, $headers);
Use the same header names and provide a From header. The array form is available from PHP 7.2.0 onward; the PHP manual documents both forms.
Keep untrusted input out of headers
Do not insert request data or other externally supplied values directly into a header. A malicious value containing line breaks could add unwanted headers. PHP’s manual warns: “If outside data are used to compose this header, the data should be sanitized so that no unwanted headers could be injected.” Validate values against the format you expect before using them, especially recipient addresses and display names.
Rank #2
What a successful mail() return means
mail() returns true when the message is accepted for delivery and false otherwise. A true result does not confirm that the recipient’s mail server delivered the message or that it reached the recipient. The PHP manual explicitly cautions that acceptance is not proof of arrival.
If delivery fails, check the return value and the configured mail transport and its logs. The active settings depend on the server and environment; local development settings may not match production.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Check the PHP mail transport in your environment
PHP’s mail configuration includes sendmail_path, sendmail_from, SMTP, and smtp_port. The documented default for sendmail_path is /usr/sbin/sendmail -t -i. The PHP mail configuration reference also notes that mail.mixed_lf_and_crlf was added in PHP 8.2.4.
Platform affects how PHP hands off a message. On Windows, PHP connects directly to an SMTP server; the manual notes differences in custom-header handling compared with the sendmail implementation. Confirm the active PHP configuration and hosting setup rather than assuming that a script behaves identically across platforms.
Rank #4
When mail() is not the right fit
The PHP manual advises against using mail() in a loop for large volumes. Its Windows implementation opens and closes an SMTP socket for each message. For high-volume sending, consult the manual’s guidance on PEAR mail packages or use a mail-sending approach suited to your transport and workload.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

