My user enters message with special characters as follows:
this is a test of &&, &&, % as well as \'\' "", &
You can use DOMDocument to create xml document and append required elements and text. All characters like & will be converted to & etc.
DOMDocument
&