# Is your Supabase email setup production-ready?

Find what blocks your Supabase Auth email before launch. We check your sender route, URLs, domain records, and templates, then hand you a prioritized fix list.

- No signup
- SPF, DKIM, and DMARC checks
- Optional SMTP test

## Sender route

How Supabase sends your auth email today. It's the most important production decision.

**Current sender route**  
Pick the route you use now, or Not sure.  
- Not sure  
- Supabase project URL or ref  
  Optional. Keeps the report tied to one project.

## Auth URLs

Where users land after they click a confirmation, magic link, or reset email.

**Site URL**  
Your production default destination.  
**Redirect URLs**  
One per line or comma-separated. List every callback, preview, and deep-link target.

## Sender domain & DNS

Authenticate the domain your auth email is sent from so it reaches the inbox.

**Sender domain**  
The domain your auth email is sent from.  
**From domain**  
Optional if it differs from the sender domain.  
**Custom sender domain**  
Does auth email send from a domain you control?  
- Not sure

**DKIM selector**  
Needed to look up the DKIM record.  
**DMARC status**  
Use your current policy if you know it.  
- Not checked

**SPF**  
**DKIM**

## Launch and volume

Tell us how much auth email you expect so we can flag rate-limit risk.

**Expected volume**  
Pick the closest match.  
- Not sure yet  
- Near launch or expecting a signup burst  
  Treat default sender and untested routes as higher risk.

**Auth flows & template checklist**  
Select the flows you use and check off ready templates. Both feed your readiness score.

**Auth email flows used**  
- Signup confirmation  
- Magic link  
- Password reset  
- Invite  
- Email change  
- Reauthentication

**Template readiness**  
- Branding matches the app  
- Primary link opens production app  
- Supabase variables reviewed  
- Support/contact path included  
- Expiration and resend copy clear

## What makes Supabase Auth email production-ready?

A production-ready Supabase email setup has a confirmed sender route, production Site URL, exact redirect allow list entries, tested auth flows, authenticated sender DNS, and templates that make the next action obvious.

For most launches, the default Supabase sender is the first thing to replace. Use custom SMTP, a Send Email Hook, or Dreamlit so signup confirmation, magic link, password reset, invite, email change, and reauthentication email are not blocked by development-oriented limits.

## What the report prioritizes.

- ### Default sender and rate-limit risk

If you are near launch or expecting a signup burst, treat the default Supabase sender as a launch blocker until a production route is confirmed.

- ### Custom SMTP vs Send Email Hook

Custom SMTP keeps Supabase responsible for sending through your provider. Send Email Hook lets your app or Dreamlit own the email workflow, template, and delivery path.

- ### Magic link and password reset URLs

Site URL is the fallback destination. Redirect URLs must include every callback, preview, localhost, and mobile deep-link target your app actually sends.

- ### Sender-domain DNS

SPF and DKIM should match the service sending the message. DMARC gives receivers a domain-level policy once alignment is working.

## Auth email templates need more than a button.

### Branding

Users should recognize the app sending the auth email before they click.

### Link destination

The primary button should open the production app or the exact auth callback route.

### Variables

Review ConfirmationURL, TokenHash, SiteURL, RedirectTo, Email, and NewEmail for the flow you use.

### Support and expiry

Explain what to do if the link expires, was not requested, or needs to be resent.

## Common questions

### Supabase email questions, answered.

**What does the Supabase Email Checker inspect?**  
It checks the production readiness of Supabase Auth email: sender route, default Supabase sender risk, expected launch volume, Site URL, redirect URLs, auth flows, sender-domain DNS, DMARC posture, and template readiness.

**Does this test my SMTP username and password?**  
If you choose Custom SMTP, you can optionally run the shared SMTP tester from this hub. Credentials are sent only to run the connection, TLS, authentication, and optional controlled-send test; Dreamlit does not store them or show them back.

**Why is the default Supabase sender risky for production?**  
The built-in sender is convenient for development, but production projects should use custom SMTP, a Send Email Hook, or a managed sender route so auth email volume, branding, and domain authentication are under your control.

**Can this help when Supabase magic links are not sending?**  
Yes. It checks the sender and launch risks that stop or delay auth email, then points magic-link-specific redirect and callback issues to the Supabase Magic Link Checker.

**How should I test password reset email before launch?**  
Trigger a reset from the production app, confirm the email arrives, open the reset link on the expected device/browser, complete the password change, and verify the template explains expiry and resend expectations.

**Do I need SPF, DKIM, and DMARC for Supabase Auth email?**  
If you send from a custom domain, SPF and DKIM should be correct for the sender service, and DMARC should at least be monitored. These checks help receivers trust signup, magic link, and password reset email.

## Supabase Auth email references

- [Supabase Auth emails guide](/content/docs/guides/supabase-auth-emails/index.html)
- [Supabase custom sender docs](https://supabase.com/docs/guides/auth/auth-smtp)
- [Supabase Send Email Hook](https://supabase.com/docs/guides/auth/auth-hooks/send-email-hook)
- [Supabase redirect URLs](https://supabase.com/docs/guides/auth/redirect-urls)
- [Supabase Auth rate limits](https://supabase.com/docs/guides/auth/rate-limits)
- [Dreamlit deliverability docs](/content/docs/resources/deliverability/index.html)

## Set up Supabase Auth email workflows without wiring SMTP by hand.

Dreamlit connects to Supabase and helps teams build branded, production-ready auth and lifecycle email workflows from their own data.

[Build Supabase email workflows](https://app.dreamlit.ai/signup)
