Skip to content
Passwordless Authentication InfrastructureZero-Latency Token Delivery

Instant, spam-proof passwordless magic link email delivery

Deliver passwordless sign-in tokens in seconds. Protect links from aggressive corporate spam filter scanners and guarantee clean one-click authentication.

3,000 emails/month freeZero credit card requiredSub-20ms edge latency
202 Accepted
Delivery Speed
Queued durably before any provider call
100%
Link Accuracy
Zero scanner pre-consumption
6,000 / mo
Free Monthly Sends
Forever free tier
Developer Ergonomics

Drop into your application in under 60 seconds

Native typed interfaces with zero unnecessary dependencies. Built for standard fetch and modern edge runtimes.

$bun add sadasend
magic-link-dispatch.ts
typescript
TYPESCRIPT
import { SadaSend } from 'sadasend';

const sadasend = new SadaSend({ apiKey: process.env.SADASEND_API_KEY });

export async function sendMagicLink(recipientEmail: string, loginToken: string) {
  // Use intermediate landing confirmation to prevent corporate scanner token consumption
  const authUrl = `https://yourapp.com/auth/confirm?token=${loginToken}`;

  const { data, error } = await sadasend.emails.send({
    from: 'Auth <login@yourapp.com>',
    to: recipientEmail,
    subject: 'Sign in to your account',
    html: `
      <div style="font-family: sans-serif; max-width: 460px; margin: 0 auto;">
        <h2>Your Magic Sign-In Link</h2>
        <p>Click below to sign in instantly. No password required.</p>
        <p style="margin: 24px 0;">
          <a href="${authUrl}" style="background: #2563eb; color: #fff; padding: 12px 24px; text-decoration: none; border-radius: 6px; font-weight: 600;">Sign In Securely</a>
        </p>
        <p style="color: #64748b; font-size: 13px;">This link is single-use and expires in 10 minutes.</p>
      </div>
    `,
    headers: {
      'X-Auto-Response-Suppress': 'All', // Suppress Exchange/Outlook auto-responders
    },
    tags: ['auth', 'magic-link']
  });

  if (error) throw new Error(`Magic link failed: ${error.message}`);
  return data;
}

Magic link dispatch with anti-prefetching bot protection headers, strict single-use expiry instructions, and fast dispatch.

Core Infrastructure

Engineered for high deliverability and zero incident risk

Every layer from edge connection pooling to per-key rate limits is designed to keep critical transactional dispatches fast, reliable, and contained.

Anti-Prefetch Protection Guidance

Includes X-Auto-Response-Suppress headers and architecture patterns to prevent corporate virus scanners from consuming one-time login links.

Instant Sub-Second Ingestion

low-latency API response time ensures users never wait looking at an empty screen after requesting their login link.

Dedicated Authentication Routing

High-reputation IP routes protect time-sensitive authentication tokens from delays caused by bulk marketing queues.

Full DKIM Alignment Across Providers

Strict cryptographic signing prevents Gmail, Outlook, and Apple Mail from flagging magic links as phishing attempts.

Idempotency Protection

Prevents duplicate magic links when users rapidly click "Resend link" by honoring standard Idempotency-Key request headers.

Real-Time Webhook Signals

Receive instant notifications when a magic link is opened or delivered, allowing client interfaces to show helpful status hints.

Architectural Comparison

SadaSend vs Generic Email Services

Why modern passwordless apps choose SadaSend for magic link delivery.

Feature & CapabilitySadaSendGeneric Email Services
Anti-Scanner Header CompatibilityOften stripped or unsupported
Delivery Speed GuaranteeAccepted and queued on the callVariable queuing delays
Isolated Authentication IP PoolsShared with marketing queues
Instant Idempotent Resend ControlsDuplicates dispatched
Cryptographic DKIM/SPF Alignment
Developer Free Tier6,000 sends foreverTrial only
Forever Free Tier
Transparent Economics

Start with 3,000 emails every month at zero cost

No artificial paywalls on security. Unlike legacy providers that reserve recipient allowlists or dedicated IP pools for high enterprise tiers, every SadaSend account receives full safety controls from day one.

3,000 dispatches monthly forever with zero credit card
All safety gates, allowlists, and velocity limits included
Scale seamlessly: Starter ($12/mo for 10k), Pro ($19/mo for 50k), Scale ($79/mo for 250k)
Free Developer Plan
$0 / mo

No credit card required

Create Free AccountCompare all paid plan tiers
Frequently Asked Questions

Everything you need to know about magic link email API

Clear, transparent answers on deliverability, API authentication, and rate limits.

Corporate spam filters (like Microsoft Defender Safelinks) often pre-fetch URLs in emails to scan them for malware. If your token endpoint consumes the token on GET, the link becomes invalid before the user clicks it.
Technical Deep Dives

Related developer guides and architectural tutorials

Explore step-by-step production implementation blueprints, benchmarks, and protocols.

Documentation

REST API Reference & Endpoints

Complete REST API reference for sending emails, managing API keys, tracking delivery events, and configuring recipient allowlists with low latency.

Read guide
Documentation

React Email Templates & Integration

How to build, preview, and send transactional emails using React Email and JSX components with zero-bleed preheaders and Outlook MSO support on SadaSend.

Read guide
Documentation

Official Client SDKs (TypeScript & Python)

Official zero-dependency client SDKs for SadaSend. TypeScript and Python packages are live on npm and PyPI with typed results and auto-idempotency.

Read guide
Deep Dive3 min read

Gmail, Yahoo and Microsoft now reject non-compliant mail. The 2026 checklist

The consequence changed. Non-compliant mail used to land in spam, where you might eventually notice. It is now refused at the door.

Read tutorial
Deep Dive3 min read

Why your transactional email goes to spam

People assume transactional mail is exempt from filtering because it was requested. Mailbox providers do not know that, and mostly do not care.

Read tutorial
Deep Dive3 min read

The Complete Guide to SPF, DKIM, and DMARC Alignment in 2026

Everything you need to know about SPF, DKIM, and DMARC in 2026: syntax rules, the 10-lookup SPF limit, strict vs relaxed alignment, and debugging with dig.

Read tutorial
Deep Dive2 min read

Email Threat Modeling for SaaS: Preventing Compromised API Key Abuse

What happens when an engineer accidentally commits an email API key to a public GitHub repo? Here is the threat model and defense blueprint.

Read tutorial
Deep Dive3 min read

Sending Transactional Email in Next.js 15 (App Router & React Email)

Render responsive React components to clean HTML strings and dispatch them via Next.js 15 Server Actions with zero external SMTP dependencies.

Read tutorial