Prompt
I'm building a small SaaS and need password reset and verification emails.
Latest observation
Sep 24, 2026
OpenAI APIWeb search: off
For a small SaaS, the simplest reliable setup is:
-
Use a transactional email provider
- Good options: Postmark, Resend, SendGrid, Mailgun, or Amazon SES
- For password reset and verification, you want high deliverability, fast sending, and good logs
-
Create two email templates
- Email verification
- “Welcome to X — verify your email”
- Include a secure, single-use verification link
- Password reset
- “Reset your password”
- Include a secure, single-use reset link with expiration
- Email verification
-
Use tokenized links
- Generate a random token server-side
- Store only a hashed version of the token in your DB
- Set an expiration time, e.g. 15–60 minutes
- Mark token as used after successful action
-
Security basics
- Tokens should be:
- long, random, unguessable
- single-use
- short-lived
- Never put passwords or sensitive data in the email
- Rate-limit resend/reset requests
- Return generic responses like “If an account exists, we sent an email” to avoid account enumeration
- Tokens should be:
-
Recommended email content
- Keep it short
- Clear CTA button
- Plain text fallback
- Include support contact
- Mention expiry
Example structure:
Verification email
- Subject:
Verify your email for Acme - Body:
- “Thanks for signing up. Click below to verify your email.”
- Button:
Verify email - “This link expires in 24 hours.”
Password reset email
- Subject:
Reset your Acme password - Body:
- “We received a request to reset your password.”
- Button:
Reset password - “If you didn’t request this, you can ignore this email. This link expires in 30 minutes.”
If you want, I can also give you:
- a database schema for reset/verification tokens,
- example email templates in HTML + text,
- or a ready-to-use implementation in Node, Python, or Rails.