Skip to main content
When enabled, every email (auth flows and emails.send() calls) routes through your SMTP server. Toggle off to revert; credentials are preserved. A self-hosted instance cannot turn SMTP off while required email verification depends on it.
Self-hosted instances need this to send any email at all. The zero-setup managed sender routes through InsForge Cloud and is only available to cloud-linked projects. A self-hosted instance with no SMTP configured cannot deliver auth emails, so email verification, magic links, and password resets will not be delivered until you complete the setup below.

Concepts

Provider is resolved on every send, so saves take effect on the next request. InsForge runs transporter.verify() before saving, so a persisted config always works. Passwords are encrypted at rest with AES-256-GCM and never returned by the API.

Usage

Configure SMTP under Authentication → Email.
1

Enable custom SMTP

Flip the switch on the SMTP Provider card.
2

Enter credentials

Host, port (25, 465, 587, 2525), username, password, sender email, sender name. Private IPs and self-signed certs are rejected.
3

Save

InsForge runs an SMTP handshake before persisting. Bad credentials fail fast.
4

Edit templates (optional)

The Email Templates card unlocks the four auth templates.
The From: header is always your configured sender. SDK callers cannot spoof it.

Email templates

Templates render locally from email.templates. Variables use {{ variable }} and are HTML-escaped. Variables: {{ token }} (code templates), {{ link }} (link templates, must start with http:// or https://), {{ name }} and {{ email }} (all templates).

Considerations

  • Rate limiting. Min interval (seconds) caps per-recipient frequency. Sends within the cooldown return HTTP 429. Defaults to 60; 0 disables.
  • SSRF protection. Private, loopback, link-local, and carrier-NAT ranges are rejected.
  • Audit log. Config saves log UPDATE_SMTP_CONFIG; template edits log UPDATE_EMAIL_TEMPLATE.

More resources