Prompt
How do I send login notification emails?
Latest observation
Sep 23, 2026
OpenAI APIWeb search: off
To send login notification emails, you generally need to:
-
Detect a successful login
- Hook into your authentication flow after the user’s credentials are verified.
- Trigger a notification only for successful logins, not failed attempts.
-
Collect useful details
- User email / name
- Login time
- IP address
- Device / browser info
- Approximate location (optional, if you support it)
-
Send the email asynchronously
- Use a background job / queue so login isn’t slowed down.
- Example providers: SendGrid, Amazon SES, Mailgun, Postmark, SMTP.
-
Use a template
- Example subject:
New login to your account - Example body:
- “We noticed a login to your account on Jan 23 at 10:42 AM from Chrome on Windows, IP 203.0.113.10.”
- “If this wasn’t you, reset your password immediately.”
- Example subject:
-
Add security best practices
- Don’t include sensitive data in the email.
- Rate-limit notifications if the same user logs in frequently.
- Consider sending only for new devices, new locations, or suspicious logins to avoid email fatigue.
- Include a clear action link for password reset or account review.
-
Audit and monitor
- Log when notifications are sent.
- Handle email failures gracefully.
Example flow
- User logs in successfully
- Your app saves a login event
- A background worker sends an email notification
- If the login is unusual, flag it for extra verification
Pseudocode
if authenticate(username, password):
login_event = {
"user_id": user.id,
"ip": request.ip,
"user_agent": request.user_agent,
"timestamp": now()
}
queue_email_notification(user.email, login_event)
If you want, I can show you how to implement this in a specific stack like Node.js, Python/Django, Laravel, Rails, or ASP.NET.