Prompt
How do I send password reset emails from my app without setting up SMTP myself?
Latest observation
Oct 9, 2026
OpenAI APIWeb search: off
You have a few good options that let you send password reset emails without running your own SMTP server:
1) Use a transactional email provider
This is the most common approach. Services handle deliverability, retries, bounces, spam complaints, and APIs for sending email.
Popular choices:
- SendGrid
- Mailgun
- Amazon SES
- Postmark
- Resend
- SparkPost
How it works
- User requests password reset.
- Your app generates a secure, time-limited reset token.
- Your app calls the provider’s API to send the email.
- The email contains a reset link with the token.
- User clicks the link and sets a new password.
Why this is better than self-hosting SMTP
- No mail server maintenance
- Better deliverability
- Easier scaling
- Less chance of being flagged as spam
- APIs are usually simpler than raw SMTP
2) Use an auth provider with built-in email workflows
If you don’t want to build password reset logic yourself, use an authentication platform that already supports it.
Examples:
- Auth0
- Firebase Authentication
- Clerk
- Supabase Auth
- AWS Cognito
- Okta
These platforms can:
- Generate reset tokens
- Send reset emails
- Handle verification and security
- Provide hosted reset pages or customizable templates
This is often the fastest path if you’re okay outsourcing auth.
3) Use a hosted email API + your own reset endpoint
If you want to keep control of the reset flow but avoid SMTP, combine:
- Your app’s backend for token creation/validation
- An email API for delivery
Typical stack:
- Backend generates token
- Store hashed token + expiry in DB
- Send email via provider API
- Reset page verifies token and updates password
Recommended implementation pattern
No matter which provider you use, keep these practices:
- Generate a cryptographically random token
- Store only a hashed version of the token
- Set a short expiration, e.g. 15–60 minutes
- Make the link one-time use
- Don’t reveal whether an email exists in your system
- Rate-limit reset requests
- Use HTTPS only
Example flow
Reset link:
https://yourapp.com/reset-password?token=abc123
Backend checks:
- token exists
- token not expired
- token not already used
Then:
- let user set new password
- invalidate token
- optionally log out other sessions
If you want the simplest setup
- Firebase/Auth0/Clerk if you want built-in auth + email flows
- Resend/Postmark/SendGrid if you want to keep your own auth logic but use an email API
If you want, I can show you:
- a Node.js example using Resend/SendGrid, or
- a full secure password reset flow you can drop into your app.