Prompt
How do I log authentication email events?
Latest observation
Sep 23, 2026
OpenAI APIWeb search: off
To log authentication email events, you generally want to capture when an email-related auth action happens, who it was for, what type of event it was, and whether it succeeded.
Common email auth events to log
Examples:
- Verification email sent
- Password reset email sent
- Magic link email sent
- Email verified
- Password reset link used
- Login via email link completed
- Email delivery failed
- Token expired / invalid
What to include in each log entry
A good auth email log entry usually contains:
- Timestamp
- Event type
- User ID / account ID
- avoid logging full email if not necessary; use a user ID or partially masked email
- Masked email address or hashed email
- Status: success / failure
- Request ID / correlation ID
- IP address and/or user agent if relevant
- Provider used to send the email (e.g. SES, SendGrid, Mailgun)
- Failure reason if applicable
- Environment: dev / staging / prod
Example log format
JSON
{
"timestamp": "2026-09-23T12:34:56Z",
"event": "auth.email.verification_sent",
"user_id": "user_12345",
"email": "j***@example.com",
"status": "success",
"provider": "sendgrid",
"request_id": "req_abc123",
"ip_address": "203.0.113.10"
}
Recommended approach
1. Log at the application layer
When your auth service triggers an email, emit a structured log event:
- before sending
- after send result
- when the token/link is used
- when verification/reset completes
2. Use structured logging
Prefer JSON logs over plain text so they’re searchable and easy to monitor.
3. Separate audit logs from debug logs
Authentication email events are usually security/audit events, so keep them in an audit log stream with restricted access.
4. Avoid sensitive data
Do not log:
- full email contents
- passwords
- raw reset tokens
- magic link tokens
- verification codes in plain text
If you need to correlate tokens, log a hash or token ID instead.
5. Alert on failures
Set alerts for:
- repeated email send failures
- too many reset requests per user/IP
- verification or reset tokens used unexpectedly
- suspicious login link activity
Example pseudocode
logger.info("auth.email.verification_sent", extra={
"user_id": user.id,
"email": mask_email(user.email),
"status": "success",
"provider": "ses",
"request_id": request.id
})
If you want, I can also show:
- a Python / Node / Go example
- how to log this in AWS CloudWatch / ELK / Datadog
- how to design an audit schema for auth email events