Prompt
How should I send auth emails from my app?
Latest observation
The best way to send auth emails from your app is to use a transactional email provider rather than sending directly from your app server.
Recommended approach
1. Use a dedicated email service
Common options:
- Postmark — excellent for transactional emails
- SendGrid
- Amazon SES
- Mailgun
- Resend
These providers handle deliverability, retries, reputation, bounce tracking, and authentication better than a raw SMTP setup.
2. Configure a domain for email
Use a domain you control, like:
no-reply@yourapp.comsecurity@yourapp.com
Set up:
- SPF
- DKIM
- DMARC
This helps messages avoid spam folders and improves trust.
3. Separate auth emails from marketing emails
Keep password reset, verification, login code, and security alerts on a separate transactional sending stream or subdomain, such as:
auth.yourapp.commail.yourapp.com
This protects deliverability if marketing campaigns get complaints.
4. Prefer short-lived tokens or magic links
For auth flows, send:
- email verification links
- password reset links
- magic login links
- one-time codes
Best practice:
- tokens should expire quickly
- tokens should be single-use
- never include sensitive data in the email itself
5. Use templates and consistent branding
Make auth emails:
- simple
- mobile-friendly
- clear about what action to take
- branded enough that users trust them
Include:
- why they got the email
- what action will happen
- expiration time
- support/contact link
6. Send asynchronously
Don’t block user sign-up/login on email delivery. Put email sending in a background job or queue so your app remains fast and reliable.
7. Monitor delivery and abuse
Track:
- sends
- bounces
- complaints
- opens/clicks if useful
- failed delivery attempts
Also rate-limit auth email requests to prevent abuse.
If you want a practical default
A strong setup is:
- Provider: Postmark or SES
- From address:
security@yourapp.com - Domain auth: SPF + DKIM + DMARC
- Flow: background job + expiring single-use token
- Email type: plain, branded transactional template
What not to do
Avoid:
- sending from your app server’s raw SMTP without authentication
- using personal Gmail/Outlook accounts
- mixing marketing and auth email on the same sender identity
- putting passwords in emails
- using long-lived or reusable login tokens
If you want, I can also recommend the best setup for your stack, like Node.js, Python, Ruby, Go, or Next.js.