Opens in a new tab
Turquoise abstract wavy W logo on a black background
Turquoise abstract wavy W logo on a black background
White WP PowerSuite logo on a black background
White WP PowerSuite logo on a black background
[wpps_ai_summarize]
On This Page
Last updated: 08/09/2026

Admin Login Notification

Notifies you by email when an administrator logs in—useful for spotting unfamiliar access.

Overview

Know when an administrator signs in without keeping the WordPress dashboard open. Admin Login Alerts emails your chosen recipients after a qualifying administrative login, with the username, roles, date and time, IP address, and optional request context. It gives owners and maintenance teams a direct notification they can review alongside expected site activity.

Choose up to 20 recipients, reduce repeat notifications with throttling and IP exclusions, and optionally include supported Magic Login, OAuth, and Temporary Login events. Admin Login Alerts is a Pro module in WP PowerSuite. It sends nothing until at least one recipient is saved, and it focuses on administrative access rather than ordinary customer or subscriber sign-ins.

Solid black square
Solid black square
Who is this for?
  • Site owners who want email visibility into administrator sign-ins
  • Agencies monitoring administrative access to client websites
  • Teams sharing responsibility for a WordPress site’s maintenance
  • Administrators using supported password, social, or temporary login workflows

Features

Administrator Sign-In Emails
Notify configured addresses when a qualifying account with administrative access signs in.
Up to 20 Recipients
Send alerts to the owner, agency, or other responsible recipients instead of relying on one predefined inbox.
Useful Login Context
Include the username, roles, time, and IP address, with optional user-agent and geographic information.
Alternative Login Coverage
Optionally include supported Magic Login, PowerSuite OAuth, and Temporary Login events for qualifying administrators.
Repeat-Alert Throttling
Limit repeat emails for the same user and IP, with a five-minute default and an adjustable 0–60 minute interval.
IP-Based Notification Exclusions
Exclude known addresses or wildcard patterns from alert emails without blocking their login.
Strict Login Detection
Optionally require a wp-admin redirect when identifying dashboard-style password logins.
Built-In Test Email
Send a clearly marked test from settings to check the alert email before relying on the workflow.

Receive WordPress Administrator Login Notifications by Email

On a site maintained by several people, an administrator sign-in may be routine or unexpected. An owner might be away from WordPress while an agency carries out maintenance, or a team may want to know when an administrative account is used outside an agreed work session. Admin Login Alerts brings the qualifying sign-in to the inboxes you choose instead of requiring someone to keep checking an admin screen for evidence of access.
The notification is triggered by the supported successful-login workflow and includes the account and request details needed for an initial review. It does not decide that a login is malicious, stop the session, or ask you to approve access before it happens. Its value is visibility: a message can be compared with the work you expected, and unfamiliar activity can be investigated through the site's normal account-management and security processes.

Focus on Administrative Access, Not Every Customer Login

Admin Login Alerts targets users with the manage_options capability by default rather than emailing for every account on a busy site. Password logins are also evaluated for a dashboard-style context. WooCommerce My Account nonce-based logins, REST authentication, and XML-RPC are excluded from that password-login detection. This keeps ordinary storefront and programmatic authentication from automatically becoming administrator email traffic simply because WordPress exposes several sign-in paths.
By default, an empty redirect or a wp-admin destination can qualify. A homepage landing after Change Login URL can still produce an alert, so a customized post-login destination does not necessarily hide the underlying administrative sign-in. Strict Login Detection is available when you want a wp-admin redirect required instead. These are defined detection rules, not a claim that every custom authentication interface is automatically recognized.

Include Supported Passwordless, Social, and Temporary Logins

A website can use more than a password form to authenticate an administrator. With alternative-login notifications enabled, Admin Login Alerts also listens for the supported completion events from Magic Login, PowerSuite OAuth, and Temporary Login. That gives a maintenance team visibility when a qualifying administrative account reaches WordPress through one of those integrations rather than the conventional password screen.
This option is on by default, but the administrator qualification and configured recipient requirements still matter. It does not turn the module into a notification system for every subscriber who uses social login or every temporary visitor regardless of their access. The supported PowerSuite 2FA verification action is also recognized in password-login detection, allowing the completed authentication workflow to participate without treating an unfinished second-factor challenge as the event being reported.

Make Alert Emails Useful Without Sending Credentials

The HTML email includes the username, account roles, date and time, and detected IP address. User-agent information is enabled by default and can be omitted when you do not need it. Optional geographic lookup adds city, region, and ISP context for public addresses through ipwho.is; it is disabled by default and cached rather than requested afresh for every repeated notification. Private IP addresses are excluded from that external lookup.
These details provide context, not proof of who was physically using a device. The message never includes passwords or session tokens. Its Secure account link points to the site's lost-password destination; it is a route into the configured recovery workflow, not a one-click session-revocation button. Choose recipients who should receive this account and network information, especially when enabling the optional lookup or user-agent details across a client or team site.

Reduce Repeat Alerts and Exclude Known Sources

Useful notifications can become noise when the same administrator signs in repeatedly while testing or maintaining a site. Admin Login Alerts prevents duplicate sends within the same PHP request and applies a separate per-user, per-IP throttle. The default interval is five minutes, with a setting from zero to 60 minutes; zero disables that throttle. This lets you decide how much repetition is useful without implying that notifications are a complete event-by-event audit history.
You can also exclude individual IP addresses or wildcard patterns from notification delivery. These are email exceptions, not firewall rules, and they do not prevent or authorize a login. IP interpretation matters as well: the module can use Cloudflare's connecting-IP value and a suitable custom header you control, while rejecting common spoofable forwarding headers. Configure that around the actual server setup rather than treating any client-supplied header as trustworthy account-location evidence.

Send Alerts to the Right People and Test the Workflow

The recipient list starts empty, so simply enabling Admin Login Alerts does not begin sending email to an assumed administrator address. Save at least one recipient, using the supported comma-separated or newline-separated list, and include up to 20 addresses. This gives an owner and maintenance team a deliberate notification policy rather than silently broadcasting administrative activity to every WordPress administrator account.
The built-in test sends an email with a [TEST] subject prefix and is limited to three tests per user within five minutes. It provides a practical check of the email workflow, but it does not prove that every login detection setting matches your site. A complete review should also consider a representative real sign-in, the selected strict-detection mode, any alternative-login integrations, and the IP exclusions and throttle that might intentionally suppress a repeat message.

Use Alerts Alongside an Activity History

An email notification and a searchable activity log serve different needs. Admin Login Alerts brings qualifying administrative access to an inbox. Activity Log provides a separate history of supported WordPress events, including user and administrative activity, when that module is enabled. Together they support an initial notification followed by a more detailed review, without asking the alert email itself to explain everything that happened after authentication.
For a quick Users-screen reference, Last Login Column can show the most recently recorded login for an account. Neither that timestamp nor an email alert should be confused with active threat blocking. Admin Login Alerts reports a qualifying sign-in; it does not add a password challenge, block failed attempts, or monitor each action within the session. Keep the notification settings aligned with the visibility your team actually needs.

Use Cases

  • Owner Awareness
    Send qualifying administrator login notifications to a site owner's chosen inbox.
  • Agency Maintenance Oversight
    Notify responsible team members when supported administrative access occurs on a client website.
  • Alternative Login Monitoring
    Include qualifying Magic Login, PowerSuite OAuth, and Temporary Login events alongside password-based access.
  • Low-Noise Administrative Alerts
    Use throttling and known-IP exclusions to reduce repeated emails during routine work.

Frequently Asked Questions

Related Modules

Letter-based profile images with customizable colors—great when you want a polished look without relying on Gravatar.
Disabled
Let members update their login name from their profile when life changes—fix a typo, drop an old email-style handle, or match a...
Disabled
Brand the login page with colors, background, and layout options.
Disabled
Pick where users land after login—global default, optional per-role URLs on supported plans, and WooCommerce-friendly behavior.
Disabled
View active WordPress login sessions, force logout users, and limit concurrent sessions by role.
Disabled
GitHub login for your site—great for technical audiences, with optional new-user signup.
Disabled
Your logo on the login page for a branded sign-in experience.
Disabled
Last login time in the Users table so you can see who has been active recently.
Disabled
Same friendly login error every time—stops people from fishing for valid usernames.
Disabled
Use a custom login URL instead of the default one bots love to hammer; bookmark your new address.
Disabled