Skip to content
Authentication & Security InfrastructureAccepted and Queued on the Call

Deliver password reset emails in under 200 milliseconds

When users request a password reset, every second of delay increases drop-off and frustration. Deliver mission-critical auth tokens instantly to the primary inbox.

3,000 emails/month freeZero credit card requiredSub-20ms edge latency
202 Accepted
Dispatch Latency
Queued durably before any provider call
SPF · DKIM · DMARC
Authentication
Aligned on every send
6,000 / mo
Free Monthly Sends
Permanent developer tier
Developer Ergonomics

Drop into your application in under 60 seconds

Native typed interfaces with zero unnecessary dependencies. Built for standard fetch and modern edge runtimes.

$bun add sadasend
password-reset.ts
typescript
TYPESCRIPT
import { SadaSend } from 'sadasend';

const sadasend = new SadaSend({ apiKey: process.env.SADASEND_API_KEY });

export async function sendPasswordReset(email: string, resetToken: string) {
  const resetUrl = `https://yourapp.com/reset-password?token=${resetToken}`;

  const { data, error } = await sadasend.emails.send({
    from: 'Security <auth@yourapp.com>',
    to: email,
    subject: 'Reset your password',
    html: `
      <div style="font-family: sans-serif; max-width: 480px; margin: 0 auto;">
        <h2>Password Reset Request</h2>
        <p>We received a request to reset your password. Click the button below:</p>
        <p style="margin: 24px 0;">
          <a href="${resetUrl}" style="background: #111; color: #fff; padding: 12px 24px; text-decoration: none; border-radius: 6px; font-weight: 600;">Reset Password</a>
        </p>
        <p style="color: #666; font-size: 13px;">This link expires in 15 minutes. If you did not make this request, you can safely ignore this email.</p>
      </div>
    `,
    headers: {
      'X-Entity-Ref-ID': resetToken.slice(0, 8),
    },
    tags: ['auth', 'password-reset']
  });

  if (error) throw new Error(`Reset delivery failed: ${error.message}`);
  return data;
}

High-deliverability password reset dispatch with short token expiration warnings, security headers, and structured delivery tags.

Core Infrastructure

Engineered for high deliverability and zero incident risk

Every layer from edge connection pooling to per-key rate limits is designed to keep critical transactional dispatches fast, reliable, and contained.

Ultra-Low Delivery Latency

fast API dispatch and optimized ISP routing deliver reset tokens to the user within seconds of clicking.

Isolated Auth IP Reputation

Critical authentication emails are processed through dedicated high-reputation pools separate from bulk marketing traffic.

Strict SPF, DKIM & DMARC Alignment

Full cryptographic validation guarantees your auth emails bypass spam filters and display authentic sender checkmarks.

Tamper-Proof Audit Headers

Inject cryptographically signed custom headers and tracking IDs to trace password reset requests across audit logs.

Automated Rate Limiting Defense

Prevent malicious account takeover abuse and credential stuffing by enforcing strict per-IP and per-recipient rate limits.

Real-Time Delivery Webhooks

Catch bounce and drop events instantly so your frontend can inform users if their corporate email blocked the message.

Architectural Comparison

SadaSend vs Shared Bulk Email Providers

Why security teams separate password reset emails from shared marketing email queues.

Feature & CapabilitySadaSendShared Bulk Email Providers
IP Pool Separation from MarketingShared with marketing blasts
Average Inbox Arrival Time< 2 seconds15 - 180 seconds during spikes
Spam Folder Quarantine Rate< 0.2%3.5 - 7.0%
Idempotency Key DeduplicationOptional / unsupported
Detailed Webhook Delivery Signals
Free Tier Volume6,000 sends foreverTrial only
Forever Free Tier
Transparent Economics

Start with 3,000 emails every month at zero cost

No artificial paywalls on security. Unlike legacy providers that reserve recipient allowlists or dedicated IP pools for high enterprise tiers, every SadaSend account receives full safety controls from day one.

3,000 dispatches monthly forever with zero credit card
All safety gates, allowlists, and velocity limits included
Scale seamlessly: Starter ($12/mo for 10k), Pro ($19/mo for 50k), Scale ($79/mo for 250k)
Free Developer Plan
$0 / mo

No credit card required

Create Free AccountCompare all paid plan tiers
Frequently Asked Questions

Everything you need to know about password reset email API

Clear, transparent answers on deliverability, API authentication, and rate limits.

Password reset emails land in spam when sent through shared IP pools tarnished by marketing senders, or when DNS records (SPF, DKIM, DMARC) are not strictly aligned with the sending domain.
Technical Deep Dives

Related developer guides and architectural tutorials

Explore step-by-step production implementation blueprints, benchmarks, and protocols.

Documentation

REST API Reference & Endpoints

Complete REST API reference for sending emails, managing API keys, tracking delivery events, and configuring recipient allowlists with low latency.

Read guide
Documentation

Official Client SDKs (TypeScript & Python)

Official zero-dependency client SDKs for SadaSend. TypeScript and Python packages are live on npm and PyPI with typed results and auto-idempotency.

Read guide
Documentation

API Error Codes & Troubleshooting

HTTP status codes, machine-readable error reasons, and step-by-step remediation guides for API key rate limits, circuit breakers, and bounce handling.

Read guide
Deep Dive3 min read

Why your transactional email goes to spam

People assume transactional mail is exempt from filtering because it was requested. Mailbox providers do not know that, and mostly do not care.

Read tutorial
Deep Dive3 min read

The Complete Guide to SPF, DKIM, and DMARC Alignment in 2026

Everything you need to know about SPF, DKIM, and DMARC in 2026: syntax rules, the 10-lookup SPF limit, strict vs relaxed alignment, and debugging with dig.

Read tutorial
Deep Dive3 min read

Gmail, Yahoo and Microsoft now reject non-compliant mail. The 2026 checklist

The consequence changed. Non-compliant mail used to land in spam, where you might eventually notice. It is now refused at the door.

Read tutorial
Deep Dive2 min read

Email Threat Modeling for SaaS: Preventing Compromised API Key Abuse

What happens when an engineer accidentally commits an email API key to a public GitHub repo? Here is the threat model and defense blueprint.

Read tutorial
Deep Dive3 min read

Sending Transactional Email in Next.js 15 (App Router & React Email)

Render responsive React components to clean HTML strings and dispatch them via Next.js 15 Server Actions with zero external SMTP dependencies.

Read tutorial