Deliver password reset emails in under 200 milliseconds
When users request a password reset, every second of delay increases drop-off and frustration. Deliver mission-critical auth tokens instantly to the primary inbox.
Drop into your application in under 60 seconds
Native typed interfaces with zero unnecessary dependencies. Built for standard fetch and modern edge runtimes.
import { SadaSend } from 'sadasend';
const sadasend = new SadaSend({ apiKey: process.env.SADASEND_API_KEY });
export async function sendPasswordReset(email: string, resetToken: string) {
const resetUrl = `https://yourapp.com/reset-password?token=${resetToken}`;
const { data, error } = await sadasend.emails.send({
from: 'Security <auth@yourapp.com>',
to: email,
subject: 'Reset your password',
html: `
<div style="font-family: sans-serif; max-width: 480px; margin: 0 auto;">
<h2>Password Reset Request</h2>
<p>We received a request to reset your password. Click the button below:</p>
<p style="margin: 24px 0;">
<a href="${resetUrl}" style="background: #111; color: #fff; padding: 12px 24px; text-decoration: none; border-radius: 6px; font-weight: 600;">Reset Password</a>
</p>
<p style="color: #666; font-size: 13px;">This link expires in 15 minutes. If you did not make this request, you can safely ignore this email.</p>
</div>
`,
headers: {
'X-Entity-Ref-ID': resetToken.slice(0, 8),
},
tags: ['auth', 'password-reset']
});
if (error) throw new Error(`Reset delivery failed: ${error.message}`);
return data;
}High-deliverability password reset dispatch with short token expiration warnings, security headers, and structured delivery tags.
Engineered for high deliverability and zero incident risk
Every layer from edge connection pooling to per-key rate limits is designed to keep critical transactional dispatches fast, reliable, and contained.
Ultra-Low Delivery Latency
fast API dispatch and optimized ISP routing deliver reset tokens to the user within seconds of clicking.
Isolated Auth IP Reputation
Critical authentication emails are processed through dedicated high-reputation pools separate from bulk marketing traffic.
Strict SPF, DKIM & DMARC Alignment
Full cryptographic validation guarantees your auth emails bypass spam filters and display authentic sender checkmarks.
Tamper-Proof Audit Headers
Inject cryptographically signed custom headers and tracking IDs to trace password reset requests across audit logs.
Automated Rate Limiting Defense
Prevent malicious account takeover abuse and credential stuffing by enforcing strict per-IP and per-recipient rate limits.
Real-Time Delivery Webhooks
Catch bounce and drop events instantly so your frontend can inform users if their corporate email blocked the message.
SadaSend vs Shared Bulk Email Providers
Why security teams separate password reset emails from shared marketing email queues.
| Feature & Capability | SadaSend | Shared Bulk Email Providers |
|---|---|---|
| IP Pool Separation from Marketing | Shared with marketing blasts | |
| Average Inbox Arrival Time | < 2 seconds | 15 - 180 seconds during spikes |
| Spam Folder Quarantine Rate | < 0.2% | 3.5 - 7.0% |
| Idempotency Key Deduplication | Optional / unsupported | |
| Detailed Webhook Delivery Signals | ||
| Free Tier Volume | 6,000 sends forever | Trial only |
Start with 3,000 emails every month at zero cost
No artificial paywalls on security. Unlike legacy providers that reserve recipient allowlists or dedicated IP pools for high enterprise tiers, every SadaSend account receives full safety controls from day one.
Everything you need to know about password reset email API
Clear, transparent answers on deliverability, API authentication, and rate limits.
Related developer guides and architectural tutorials
Explore step-by-step production implementation blueprints, benchmarks, and protocols.
REST API Reference & Endpoints
Complete REST API reference for sending emails, managing API keys, tracking delivery events, and configuring recipient allowlists with low latency.
Official Client SDKs (TypeScript & Python)
Official zero-dependency client SDKs for SadaSend. TypeScript and Python packages are live on npm and PyPI with typed results and auto-idempotency.
API Error Codes & Troubleshooting
HTTP status codes, machine-readable error reasons, and step-by-step remediation guides for API key rate limits, circuit breakers, and bounce handling.
Why your transactional email goes to spam
People assume transactional mail is exempt from filtering because it was requested. Mailbox providers do not know that, and mostly do not care.
The Complete Guide to SPF, DKIM, and DMARC Alignment in 2026
Everything you need to know about SPF, DKIM, and DMARC in 2026: syntax rules, the 10-lookup SPF limit, strict vs relaxed alignment, and debugging with dig.
Gmail, Yahoo and Microsoft now reject non-compliant mail. The 2026 checklist
The consequence changed. Non-compliant mail used to land in spam, where you might eventually notice. It is now refused at the door.
Email Threat Modeling for SaaS: Preventing Compromised API Key Abuse
What happens when an engineer accidentally commits an email API key to a public GitHub repo? Here is the threat model and defense blueprint.
Sending Transactional Email in Next.js 15 (App Router & React Email)
Render responsive React components to clean HTML strings and dispatch them via Next.js 15 Server Actions with zero external SMTP dependencies.