How a secure reset works.
- The user enters their email address on your Forgot password page.
- Your backend creates a random, single-use token that expires within an hour, and stores only its hash.
- Your backend calls Mailumi with the reset link.
- The user opens the link, chooses a new password and your app signs out their other sessions.
Always show the same message, such as “If an account exists, we sent a link”, whether or not the address is registered. That stops attackers from finding out who has an account.
A reset email people trust.
Keep it short: who it is from, why they got it, one clear button and what to do if they did not ask for it. Leave out passwords, promotions and tracking links.
Save it as a template with variables like {{reset_url}} and {{expires_in}}, and send it from an address users recognise, such as security@yourbrand.com.
Fast, and easy to check.
Reset emails are sent the moment your app calls the API. If a user says the email never arrived, look it up in Email activity: you will see whether it was delivered or bounced, and to which address.
If your request times out, retry with the same Idempotency-Key so the user does not get two links. A new reset request should create a new token and a new key.
Reset link checklist
| Do this | Why |
|---|---|
| Use at least 32 random bytes | Tokens cannot be guessed |
| Expire within 1 hour | Old emails stop working |
| Allow one use | A forwarded link cannot be reused |
| Store only a hash | A database leak does not expose tokens |
| Rate-limit requests | Stops abuse of the form |
Password reset emails: common questions
- Does Mailumi create the reset token?
- No. Your authentication system creates and checks the token, which keeps account security in your hands. Mailumi delivers the email containing the link.
- How fast does a password reset email arrive?
- Mailumi starts delivery as soon as your app makes the request, and most messages reach the recipient’s mail server within seconds.
- What if the user does not receive it?
- Look up the message in Email activity. If it bounced, the address is wrong. If it was delivered, ask the user to check their spam folder, and make sure your domain has DKIM and DMARC.
- Can I send reset emails from a frontend-only app?
- Not directly, because your API key must stay secret. Use a serverless function or your backend to create the token and call Mailumi.
Sources
Sources checked . Third-party features and prices may change.