> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developers.brevo.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developers.brevo.com/_mcp/server.

# Connect Brevo SMTP to Supabase: send your auth emails

## Overview

Supabase Auth ships with a built-in SMTP server so you can explore Auth and test email templates. That default server sends only to addresses already on your project's team and is capped at **2 messages per hour** — it isn't meant for production. To send authentication emails to real users, connect a custom SMTP provider. This guide uses [Brevo](https://www.brevo.com/), which Supabase lists as a supported SMTP provider, as the sending service.

Custom SMTP also unlocks something else: without it, Supabase's **Templates** tab won't let you edit the subject or body of auth emails — it shows a banner asking you to set up custom SMTP first.

## Prerequisites

* A Brevo account
* A sending domain you can add DNS records to (for SPF/DKIM authentication)
* A Supabase project on the Auth product
* Project owner or admin access in both Brevo and Supabase

## Connect Brevo to Supabase Auth

### Authenticate your sending domain in Brevo

1. In Brevo, go to **Senders, Domains & Dedicated IPs**.
2. Add and verify the domain you want auth emails to come from (for example `mail.yourapp.com`), adding the SPF and DKIM DNS records Brevo provides.
3. Create a sender email on that domain, for example `no-reply@mail.yourapp.com`.

Domain authentication is required for reliable deliverability — unauthenticated senders are far more likely to land in spam or get blocked.

### Generate a Brevo SMTP key

1. In Brevo, click **Settings** (gear icon) in the left sidebar, then open **SMTP & API** (direct link: [app.brevo.com/settings/keys/smtp](https://app.brevo.com/settings/keys/smtp)).
2. Under the **SMTP** tab, copy your existing SMTP credentials, or click **+ Generate SMTP key** to create a new one.

> **Warning**
>
> Use an **SMTP key**, not a Brevo API key — they're different credentials, and the SMTP relay only accepts SMTP keys.

> **Tip**
>
> The SMTP tab also shows an **Activate for SMTP keys** option, next to a banner warning that unauthorized IP addresses aren't blocked by default. Turning this on restricts your SMTP key to a list of authorized IPs (add them first under **Security > Authorized IPs**) — worth enabling once you know your sending server's IP is stable.

### Enable custom SMTP in Supabase

In your Supabase project, go to **Authentication > Emails > SMTP Settings** (`/project/_/auth/smtp`) and turn on **Enable custom SMTP**.

Under **Sender details**, fill in:

| Field                | Value                                                        |
| -------------------- | ------------------------------------------------------------ |
| Sender email address | Your verified Brevo sender, e.g. `no-reply@mail.yourapp.com` |
| Sender name          | Your app or company name                                     |

Under **SMTP provider settings**, fill in:

| Field                     | Value                                                                                                                                                                                              |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Host                      | `smtp-relay.brevo.com`                                                                                                                                                                             |
| Port number               | `587` (STARTTLS) or `465` (SSL/TLS)                                                                                                                                                                |
| Minimum interval per user | Leave the default (`60` seconds) unless you have a reason to change it — this caps how often the *same* user can receive an auth email, separate from the account-wide rate limit in the next step |
| Username                  | Your Brevo account login email                                                                                                                                                                     |
| Password                  | The SMTP key from the previous step                                                                                                                                                                |

Click **Save changes**. A note on this screen confirms the rate limit is raised once custom SMTP is on. You can also set these fields through the [Supabase Management API](https://supabase.com/docs/guides/auth/auth-smtp) (`smtp_host`, `smtp_port`, `smtp_user`, `smtp_pass`, `smtp_sender_name`).

### Raise your Auth rate limits

Once custom SMTP is enabled, Supabase lifts the 2-messages-per-hour test limit and raises it to **30 emails per hour** by default (Supabase's own SMTP Settings screen confirms this exact number). Adjust this further on the **Rate Limits** configuration page to a value that matches your expected signup volume — and coordinate with Brevo's own sending limits for your plan.

### Test it

1. Trigger a real Auth email (sign up a test user, or request a password reset).
2. Confirm the message arrives from your Brevo-authenticated address.
3. Check delivery in **Brevo > Transactional > Email logs** if it doesn't arrive within a few minutes.

## Troubleshooting

* **"Email address not authorized"**: custom SMTP isn't enabled yet, or the address isn't part of your Supabase organization's team — enable custom SMTP first.
* **Emails land in spam**: double-check SPF/DKIM records in Brevo's domain settings; authentication can take up to 24-48 hours to propagate.
* **Auth error / mail not sent**: confirm you used the SMTP key (not the API key) and that the sender email exactly matches an authenticated Brevo sender.

## Related resources

* [Brevo — SMTP relay integration](/docs/smtp-integration)
* [Brevo Help Center — Send transactional emails using Brevo SMTP](https://help.brevo.com/hc/en-us/articles/7924908994450-Send-transactional-emails-using-Brevo-SMTP)
* [Supabase — Send emails with custom SMTP](https://supabase.com/docs/guides/auth/auth-smtp)