Set Up Transactional Email With SendGrid
Turn on transactional email (sign-up confirmation, password reset, notifications) through SendGrid: create a least-privilege API key, authenticate your domain with the DKIM/return-path CNAMEs, wire the five SMTP env vars, align the default From with the authenticated domain, and send a test.
PremiumTransactional email is a deliverability problem before it is a code problem. Anyone
can point an app at an SMTP server; the hard part is getting the message into the inbox
instead of the spam folder — or worse, getting it silently rejected by the provider.
Three things decide whether your confirm your account and reset your password emails
arrive:
-
Who is allowed to send. A SendGrid API key, scoped to Mail Send only, is the
credential your app authenticates with. Least privilege: if the key leaks, it can send
mail and nothing else. -
Proof that the mail is really from your domain. Domain Authentication publishes
DKIM keys and a return-path under your domain via DNS (a handful of CNAME records).
Without it, receivers can't verify the signature and treat your mail as suspicious —
spam at best, rejected at worst. -
A From address the domain actually vouches for. The sender has to be an address on
the authenticated domain (e.g.noreply@your-domain.com). A leftover placeholder like
from@example.comgets the message rejected outright.
This playbook wires all three, in the order that avoids the common traps, and finishes by
sending a real test email you confirm end to end. Along the way, one rule never bends:
the API key is a secret — it never lands in a log line, a commit, or a screenshot.