The 2-email-per-hour limit: Why Supabase Auth breaks in production
Supabase is one of the most popular open-source Firebase alternatives, offering PostgreSQL, Row Level Security (RLS), and instant authentication. However, every new Supabase project ships with a critical catch: the default email service is capped at 2 emails per hour.
This built-in limit exists solely for initial local testing. The moment you invite a third team member or launch to early users, your sign-up and magic link flows fail with an HTTP 429 error: email_rate_limit_exceeded: For security purposes, you can only request this once every 60 seconds.
To take any Supabase application to production, configuring a reliable Custom SMTP provider is mandatory.
Step-by-step: Configuring SadaSend Custom SMTP in Supabase
Connecting SadaSend to Supabase Auth takes under two minutes in the Supabase Dashboard:
1. Open your Supabase project and navigate to Project Settings > Authentication.
2. Scroll down to the SMTP Settings section and toggle Enable Custom SMTP to ON.
3. Enter the following connection credentials:
• Sender Email: auth@yourdomain.com (Must match a verified domain in SadaSend)
• Sender Name: Your App Name
• Host: smtp.sadasend.com
• Port: 587 (STARTTLS recommended) or 465 (SSL)
• Minimum TLS Version: 1.2
• Username: sadasend
• Password: Your SadaSend API Key (sk_live_...)
4. Click Save and test with a magic link sign-up. Your emails will now dispatch instantly from your authenticated domain with zero rate-limit errors.
Sending transactional emails from Supabase Edge Functions
While Supabase Auth handles password resets and confirmations via SMTP, you will often need to dispatch transactional notifications (e.g., payment receipts, team invites) from Supabase Edge Functions (Deno).
Using SadaSend's REST API inside Edge Functions eliminates the cold-start overhead of heavy SMTP libraries:
// supabase/functions/send-invite/index.ts
import { serve } from 'https://deno.land/std@0.168.0/http/server.ts';
serve(async (req) => {
const { email, inviteUrl, inviterName } = await req.json();
const res = await fetch('https://api.sadasend.com/v1/emails', {
method: 'POST',
headers: {
'Authorization': `Bearer ${Deno.env.get('SADASEND_API_KEY')}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({
from: 'team@yourdomain.com',
to: email,
subject: `${inviterName} invited you to collaborate`,
html: `<p>Click here to join: <a href="${inviteUrl}">Accept Invitation</a></p>`,
text: `Join the team: ${inviteUrl}`,
}),
});
if (!res.ok) {
return new Response(await res.text(), { status: res.status });
}
const data = await res.json();
return new Response(JSON.stringify({ success: true, id: data.id }), {
headers: { 'Content-Type': 'application/json' },
});
});Ensuring 100% DMARC and SPF alignment
Authentication emails like magic links and password resets are scrutinised heavily by anti-phishing filters at Gmail and Microsoft 365.
By verifying your custom domain in SadaSend, your Supabase auth emails pass both SPF and DKIM with 100% alignment under your own domain name (yourdomain.com). This ensures that your magic links appear in the primary inbox within 2 seconds of the user clicking 'Sign Up'.
Building AI agents that send email?
Join the SadaSend early access waitlist to get scoped API keys, recipient allowlists, and Model Context Protocol (MCP) servers upon launch.