Connect Brevo SMTP to Supabase: send your auth emails

Configure Brevo as the custom SMTP provider for Supabase Auth so sign-up confirmations, magic links, password resets, and invites send from your own domain instead of Supabase’s shared test server.

View as Markdown

Overview

Supabase Auth ships with a built-in SMTP server so you can explore Auth and test email templates. That default server sends only to addresses already on your project’s team and is capped at 2 messages per hour — it isn’t meant for production. To send authentication emails to real users, connect a custom SMTP provider. This guide uses Brevo, which Supabase lists as a supported SMTP provider, as the sending service.

Custom SMTP also unlocks something else: without it, Supabase’s Templates tab won’t let you edit the subject or body of auth emails — it shows a banner asking you to set up custom SMTP first.

Prerequisites

  • A Brevo account
  • A sending domain you can add DNS records to (for SPF/DKIM authentication)
  • A Supabase project on the Auth product
  • Project owner or admin access in both Brevo and Supabase

Connect Brevo to Supabase Auth

1

Authenticate your sending domain in Brevo

  1. In Brevo, go to Senders, Domains & Dedicated IPs.
  2. Add and verify the domain you want auth emails to come from (for example mail.yourapp.com), adding the SPF and DKIM DNS records Brevo provides.
  3. Create a sender email on that domain, for example no-reply@mail.yourapp.com.

Domain authentication is required for reliable deliverability — unauthenticated senders are far more likely to land in spam or get blocked.

2

Generate a Brevo SMTP key

  1. In Brevo, click Settings (gear icon) in the left sidebar, then open SMTP & API (direct link: app.brevo.com/settings/keys/smtp).
  2. Under the SMTP tab, copy your existing SMTP credentials, or click + Generate SMTP key to create a new one.

Use an SMTP key, not a Brevo API key — they’re different credentials, and the SMTP relay only accepts SMTP keys.

The SMTP tab also shows an Activate for SMTP keys option, next to a banner warning that unauthorized IP addresses aren’t blocked by default. Turning this on restricts your SMTP key to a list of authorized IPs (add them first under Security > Authorized IPs) — worth enabling once you know your sending server’s IP is stable.

3

Enable custom SMTP in Supabase

In your Supabase project, go to Authentication > Emails > SMTP Settings (/project/_/auth/smtp) and turn on Enable custom SMTP.

Under Sender details, fill in:

FieldValue
Sender email addressYour verified Brevo sender, e.g. no-reply@mail.yourapp.com
Sender nameYour app or company name

Under SMTP provider settings, fill in:

FieldValue
Hostsmtp-relay.brevo.com
Port number587 (STARTTLS) or 465 (SSL/TLS)
Minimum interval per userLeave the default (60 seconds) unless you have a reason to change it — this caps how often the same user can receive an auth email, separate from the account-wide rate limit in the next step
UsernameYour Brevo account login email
PasswordThe SMTP key from the previous step

Click Save changes. A note on this screen confirms the rate limit is raised once custom SMTP is on. You can also set these fields through the Supabase Management API (smtp_host, smtp_port, smtp_user, smtp_pass, smtp_sender_name).

4

Raise your Auth rate limits

Once custom SMTP is enabled, Supabase lifts the 2-messages-per-hour test limit and raises it to 30 emails per hour by default (Supabase’s own SMTP Settings screen confirms this exact number). Adjust this further on the Rate Limits configuration page to a value that matches your expected signup volume — and coordinate with Brevo’s own sending limits for your plan.

5

Test it

  1. Trigger a real Auth email (sign up a test user, or request a password reset).
  2. Confirm the message arrives from your Brevo-authenticated address.
  3. Check delivery in Brevo > Transactional > Email logs if it doesn’t arrive within a few minutes.

Troubleshooting

  • “Email address not authorized”: custom SMTP isn’t enabled yet, or the address isn’t part of your Supabase organization’s team — enable custom SMTP first.
  • Emails land in spam: double-check SPF/DKIM records in Brevo’s domain settings; authentication can take up to 24-48 hours to propagate.
  • Auth error / mail not sent: confirm you used the SMTP key (not the API key) and that the sender email exactly matches an authenticated Brevo sender.