Prompt
Can I use a normal SMTP server for password reset emails?
Latest observation
Sep 23, 2026
OpenAI APIWeb search: off
Yes — a normal SMTP server is commonly used for password reset emails.
A few important caveats:
- Use authenticated SMTP from a reputable provider or your own properly configured mail server.
- Send from a domain you control and set up SPF, DKIM, and DMARC so messages are less likely to be flagged as spam.
- Use HTTPS links in the reset email, with:
- a single-use token
- a short expiration time (e.g. 15–60 minutes)
- server-side validation of the token
- Don’t include the new password in the email. Email should only contain a reset link or code.
- Throttle / rate-limit reset requests to reduce abuse.
- Avoid leaking account existence in responses. For example: “If an account exists, we sent an email.”
If you mean “ordinary SMTP” as in something like Postfix, Exchange, Gmail SMTP, SES, SendGrid, etc., then yes, that’s the standard way to send password reset emails.
If you want, I can also show you a secure password reset flow and a sample SMTP setup.