Operations

Set Up Transactional Email With SendGrid

Turn on transactional email (sign-up confirmation, password reset, notifications) through SendGrid: create a least-privilege API key, authenticate your domain with the DKIM/return-path CNAMEs, wire the five SMTP env vars, align the default From with the authenticated domain, and send a test.

Premium

Transactional email is a deliverability problem before it is a code problem. Anyone
can point an app at an SMTP server; the hard part is getting the message into the inbox
instead of the spam folder — or worse, getting it silently rejected by the provider.

Three things decide whether your confirm your account and reset your password emails
arrive:

  1. Who is allowed to send. A SendGrid API key, scoped to Mail Send only, is the
    credential your app authenticates with. Least privilege: if the key leaks, it can send
    mail and nothing else.
  2. Proof that the mail is really from your domain. Domain Authentication publishes
    DKIM keys and a return-path under your domain via DNS (a handful of CNAME records).
    Without it, receivers can't verify the signature and treat your mail as suspicious —
    spam at best, rejected at worst.
  3. A From address the domain actually vouches for. The sender has to be an address on
    the authenticated domain (e.g. noreply@your-domain.com). A leftover placeholder like
    from@example.com gets the message rejected outright.

This playbook wires all three, in the order that avoids the common traps, and finishes by
sending a real test email you confirm end to end. Along the way, one rule never bends:
the API key is a secret — it never lands in a log line, a commit, or a screenshot.

Steps

Subscriber-only content. View plans