Prompt
How do I send a login alert email?
Latest observation
Sep 23, 2026
OpenAI APIWeb search: off
A common way to send a login alert email is:
-
Detect a successful login
- In your auth flow, add a hook right after authentication succeeds.
-
Gather alert details
- User email/name
- Login time
- IP address
- Approximate location/device/browser
- A link to “report this wasn’t me” or review sessions
-
Send an email from your backend
- Use an email service like:
- SendGrid
- Mailgun
- Amazon SES
- Postmark
- SMTP via Nodemailer
- Use an email service like:
-
Format the email clearly
- Subject:
New login to your account - Body: mention time, device, IP, and what to do if unexpected
- Subject:
-
Avoid blocking login
- Send the email asynchronously/background job so login stays fast.
Example email content
Subject: New login to your account
Body:
We noticed a new login to your account on Sep 23, 2026 at 10:42 AM UTC.
Device: Chrome on Windows
IP Address: 203.0.113.42If this was you, you can ignore this email.
If not, please reset your password immediately.
Example in Node.js using Nodemailer
import nodemailer from "nodemailer";
const transporter = nodemailer.createTransport({
service: "gmail",
auth: {
user: process.env.EMAIL_USER,
pass: process.env.EMAIL_PASS,
},
});
async function sendLoginAlert(userEmail, details) {
await transporter.sendMail({
from: process.env.EMAIL_USER,
to: userEmail,
subject: "New login to your account",
text: `We noticed a new login.\n\nTime: ${details.time}\nIP: ${details.ip}\nDevice: ${details.device}\n\nIf this wasn't you, please reset your password.`,
});
}
Call sendLoginAlert(...) after a successful login.
Best practices
- Send alerts only for:
- new devices
- new locations
- suspicious logins
- Include a secure “review sessions” link
- Don’t expose too much sensitive info
- Rate-limit alerts to avoid spam
If you want, I can show you how to do this in Python, Node.js, PHP, Django, or Firebase.