Why Retool's default email fails in production
Retool is the industry-standard platform for building internal tools, customer success dashboards, and operational backends. However, when engineering teams need to trigger emails from Retool (e.g. manual password resets, invitation links, refund confirmations, or account unbans), relying on the default 'Retool Email' resource introduces severe limitations.
Retool's default email sends from a generic retool-email.com address. You cannot align SPF, DKIM, or DMARC with your own domain, causing emails to be rejected by enterprise spam filters or look like phishing attempts to customers.
By connecting SadaSend as a REST API or SMTP resource, your internal Retool applications gain white-label domain deliverability with sub-20ms execution.
Setting up the SadaSend REST API resource in Retool
Configuring SadaSend in Retool takes less than two minutes:
1. In your Retool dashboard, navigate to Resources > Create New > REST API.
2. Set Name to SadaSend API.
3. Set Base URL to https://api.sadasend.com/v1.
4. Under Headers, add:
• Authorization: Bearer {{ secrets.SADASEND_API_KEY }}
• Content-Type: application/json
5. Click Create Resource. Your Retool apps and workflows can now query this resource securely.
Triggering emails from Retool tables and action buttons
In your Retool app canvas, create a new query using your SadaSend API resource:
• Action type: POST
• URL path: /emails
• Raw Body (JSON):
{
"from": "support@yourdomain.com",
"to": "{{ tableUsers.selectedRow.email }}",
"subject": "{{ 'Your account has been updated by ' + current_user.fullName }}",
"html": "<p>Hi {{ tableUsers.selectedRow.firstName }},</p><p>Your account status has been updated to: <strong>{{ selectStatus.value }}</strong>.</p>",
"text": "Hi {{ tableUsers.selectedRow.firstName }}, Your account status has been updated to: {{ selectStatus.value }}.",
"headers": {
"X-Retool-Operator": "{{ current_user.email }}"
}
}Preventing the ultimate disaster: Recipient Allowlists for staging
The single most expensive mistake in internal tooling is when a developer tests a Retool staging app against a cloned production database and accidentally emails thousands of real customers.
SadaSend solves this with hardware-grade Recipient Allowlists. When provisioning a key for Retool staging or development, configure the key's allowlist to @yourcompany.com.
If an internal operator or test query attempts to dispatch to an external customer address, SadaSend intercepts the call and rejects it with an immediate 403 Forbidden error before any mail leaves.
Building AI agents that send email?
Join the SadaSend early access waitlist to get scoped API keys, recipient allowlists, and Model Context Protocol (MCP) servers upon launch.