Password reset emails

Password reset emails that arrive in seconds.

A password reset email contains a one-time link that lets someone choose a new password. Your app creates the secure token; Mailumi delivers the email from your verified domain as soon as you call the API and shows its delivery status, so users can always get back in.

Free plan with 3,000 emails a month. No credit card required.

How a secure reset works.

  1. The user enters their email address on your Forgot password page.
  2. Your backend creates a random, single-use token that expires within an hour, and stores only its hash.
  3. Your backend calls Mailumi with the reset link.
  4. The user opens the link, chooses a new password and your app signs out their other sessions.

Always show the same message, such as “If an account exists, we sent a link”, whether or not the address is registered. That stops attackers from finding out who has an account.

A reset email people trust.

Keep it short: who it is from, why they got it, one clear button and what to do if they did not ask for it. Leave out passwords, promotions and tracking links.

Save it as a template with variables like {{reset_url}} and {{expires_in}}, and send it from an address users recognise, such as security@yourbrand.com.

Fast, and easy to check.

Reset emails are sent the moment your app calls the API. If a user says the email never arrived, look it up in Email activity: you will see whether it was delivered or bounced, and to which address.

If your request times out, retry with the same Idempotency-Key so the user does not get two links. A new reset request should create a new token and a new key.

Reset link checklist

Do thisWhy
Use at least 32 random bytesTokens cannot be guessed
Expire within 1 hourOld emails stop working
Allow one useA forwarded link cannot be reused
Store only a hashA database leak does not expose tokens
Rate-limit requestsStops abuse of the form

Password reset emails: common questions

Does Mailumi create the reset token?
No. Your authentication system creates and checks the token, which keeps account security in your hands. Mailumi delivers the email containing the link.
How fast does a password reset email arrive?
Mailumi starts delivery as soon as your app makes the request, and most messages reach the recipient’s mail server within seconds.
What if the user does not receive it?
Look up the message in Email activity. If it bounced, the address is wrong. If it was delivered, ask the user to check their spam folder, and make sure your domain has DKIM and DMARC.
Can I send reset emails from a frontend-only app?
Not directly, because your API key must stay secret. Use a serverless function or your backend to create the token and call Mailumi.

Sources

Sources checked . Third-party features and prices may change.

Send your first reset email.

Create a free accountTalk to us

3,000 free emails every month. No credit card required.