Publish SPF, DKIM and DMARC for the sending domain
Add the SPF and DKIM records your email provider gives you, then a DMARC TXT record at _dmarc on the same domain. Google recommends starting with p=none and a dedicated mailbox for reports. Tighten the policy once the reports show your mail passing.
_dmarc.example.com TXT "v=DMARC1; p=none; rua=mailto:[email protected]"
Leave the sandbox and the default sender before launch
On SES, request production access; AWS gives an initial response within 24 hours. On Supabase, configure custom SMTP, then raise the email rate limit on the Rate Limits page to match the sign-ups you expect.
aws sesv2 put-account-details \
--production-access-enabled \
--mail-type TRANSACTIONAL \
--website-url https://example.com \
--contact-language EN
Send over the provider's HTTPS API instead of SMTP
If your host blocks or throttles SMTP ports, call your email provider's HTTPS send endpoint from the server. Railway recommends HTTPS email APIs on every plan, including plans where SMTP is allowed.
Fix the new-user trigger
Check the Auth logs for the exact database error. Make sure the table the trigger writes to exists. Run the function as security definer with an empty search_path so the auth role can write outside the auth schema.
create or replace function public.handle_new_user()
returns trigger
language plpgsql
security definer set search_path = ''
as $$
begin
insert into public.profiles (id) values (new.id);
return new;
end;
$$;
Handle bounces and complaints, and send sign-in mail separately
Subscribe to your provider's bounce and complaint events, and stop sending to addresses that hard-bounce. Send sign-in mail separately from lifecycle and marketing mail, so a complaint about a newsletter can't hurt delivery of sign-in codes.
Add one-click unsubscribe to lifecycle mail
Gmail requires one-click unsubscribe (RFC 8058) on marketing and subscribed mail from senders of more than 5,000 messages a day. The DKIM signature must cover both headers, and the URL must accept a POST.
List-Unsubscribe: <https://example.com/unsubscribe/opaque-token>
List-Unsubscribe-Post: List-Unsubscribe=One-Click
Alert on send failures and sign-in success rate
Page someone when the email provider returns an auth error, such as a disabled key or a failed SMTP login. Logging it isn't enough. Track the share of started sign-ins that complete, so you see a delivery problem within minutes, before users write to support.