Docs · Bring Your Own Keys

Email with Resend

Setting up transactional email, and the SPF/DKIM/DMARC deliverability warning.

Magic-code sign-in emails and any receipt or notification email you add all go out through Resend in production. Without a Resend key, development uses letter_opener instead, opening every email in your browser rather than sending it anywhere, so nothing about local development requires this setup.

The two variables

  • RESEND_API_KEY, from resend.com.
  • MAIL_FROM, a sender address on a domain you've verified inside Resend.

Deliverability: the step that actually matters

Add Resend's SPF, DKIM, and DMARC DNS records for your sending domain. Skip this, and magic-code emails will land in spam, or fail to deliver at all, which silently breaks signup for anyone affected: they never see an error, they just never get their code. This is the single most common cause of "sign-in doesn't work" reports on a freshly deployed app, and it's invisible from inside the app itself, since the email leaves your server successfully; it just doesn't arrive anywhere useful. Set these DNS records up at the same time you're configuring the rest of your domain; see Edge and DNS Setup.

Next

Turn on real Stripe billing: Stripe Setup. Or continue through the reference: Sign in with Google and Apple.

Common questions

How do I preview emails in development without sending them?

One Shot uses letter_opener in development, so every deliver_later opens the rendered email in a browser tab instead of sending it. No key and no account are needed. That is how you read a sign-in code locally, and it means a seed script cannot accidentally email a real address.

How do I send transactional email from a Rails app in production?

Set RESEND_API_KEY and MAIL_FROM, and ActionMailer delivers through Resend in production while development keeps opening messages in a browser tab. The code side is already wired. The real work is verifying your sending domain and publishing SPF, DKIM and DMARC, without which the mail sends and lands in spam.

What DNS records do I need to send email from my domain?

Three: an SPF record authorizing your sending provider, DKIM keys the provider gives you, and a DMARC policy. Your email provider publishes the exact values; you add them at your DNS host. Missing any of the three is the reason a correctly configured app still has its sign-in emails filtered, and no code change fixes it.