Prompt
How do I send password reset emails from my app without using a marketing tool?
Latest observation
You can send password reset emails yourself using a transactional email setup, without a marketing tool. The basic pieces are:
1. Use an email-sending service or SMTP server
You need something that can reliably deliver email from your app:
- Transactional email providers: Amazon SES, SendGrid, Mailgun, Postmark, Resend, etc.
- Your own SMTP server: possible, but usually harder to deliver reliably
For password reset emails, a transactional provider is the usual choice.
2. Create a reset token in your app
When the user requests a password reset:
- Generate a cryptographically secure random token
- Store a hashed version of the token in your database
- Set an expiration time like 15–60 minutes
- Associate it with the user account
Then email the user a link like:
https://yourapp.com/reset-password?token=XYZ
3. Send the email through your backend
Your app server should send the email, not the frontend.
Example flow:
- User enters email address
- Backend looks up user
- Backend creates reset token
- Backend sends email with reset link
- User clicks link
- App verifies token and expiry
- User sets a new password
- Token is invalidated after use
4. Build a simple email template
Password reset emails are usually plain and transactional:
- Subject:
Reset your password - One clear call-to-action button or link
- Expiration warning
- Support note if they didn’t request it
Example body:
Someone requested a password reset for your account.
Click the link below to reset your password. This link expires in 30 minutes.
5. Configure sending correctly
To avoid landing in spam:
- Set up SPF
- Set up DKIM
- Set up DMARC
- Use a verified sending domain like
no-reply@yourapp.com
6. Add security protections
Important best practices:
- Don’t reveal whether an email exists in your system
- Rate-limit reset requests
- Make tokens single-use
- Store hashed tokens, not plain text
- Expire tokens quickly
- Log reset attempts for abuse monitoring
7. Minimal implementation outline
Pseudo-flow:
POST /forgot-password
- receive email
- generate token
- store hashed token + expiry
- send email with reset link
POST /reset-password
- receive token + new password
- verify token hash and expiry
- update password
- delete token
8. Example provider options
If you want something simple:
- Resend: easy developer experience
- Postmark: great for transactional email
- Amazon SES: cheap, scalable, more setup
- SendGrid/Mailgun: common and well-documented
9. If you want to send directly via code
You’d usually use an SDK or SMTP library. For example:
- Node.js:
nodemailer, or provider SDK - Python:
smtplibor provider SDK - Ruby/PHP/Go: provider libraries or SMTP
If you tell me your stack, I can show you a concrete password-reset email implementation for it.