Send email from your domain
Udibo emails your users to verify addresses, reset passwords, and sign them in. Connect your own Resend account so those messages come from your domain, verify that domain, and learn what changes for your users when you do.
Emails your users receive
| Sent when | |
|---|---|
| Email verification | A person needs to confirm their address |
| Password reset | A person asks to reset their password |
| Account unlock | An account is locked after too many failed sign-in attempts |
| Sign-in code or sign-in link | A person asks for an email code or link on the sign-in page |
| Sign-in method connected or removed | A social account is connected to or removed from an account |
| New-device sign-in | An account signs in from an unrecognized device, when enabled |
| Waitlist emails | A person joins or asks to leave; you invite them or open sign-up |
| Organization invitation | Someone is invited to an organization |
Security notices go only to a verified address. New-device notices are off by default and are not a setting you can change for your tenant. Dashboard invitations and usage alerts are about your tenant, not your users; they always come from Udibo and are not affected by your sender.
What your branding changes in email
Waitlist and organization invitation emails use the display name from your branding. The other emails in the table name Udibo in their subject and text today. No email uses your logo or accent color, and email content cannot be customized.
Delivery by Udibo
Until you connect a sender, Udibo delivers these emails from a shared sending address. Each tenant has a daily allowance on it; mail past the allowance is not sent, and the person is not told. These emails count toward "Emails sent by Udibo" on pricing. If you set an email limit on your Billing page, sending stops when it is reached, sign-in and recovery email included.
Connect your own sender
Only Resend is supported. Before you start, add your sending domain to your Resend account and create an API key there. Udibo reads the domain's status and DNS records from Resend; it does not create the domain for you.
Open your tenant in the dashboard, choose Settings, and scroll to Email sender.
Enter your Resend API key. It is required the first time, stored encrypted, and never shown again; leave it blank later to keep it.
Enter the From address, such as
[email protected].Optionally fill in the rest:
From name, up to 100 characters. Your branding display name is not used as the From name.
Sending domain, which defaults to the from address's domain. Changing it discards the last domain check.
Webhook signing secret; see record bounces and complaints.
Choose Save email sender.
The section then shows Configured, the provider, a domain status, and the
exact sender, for example Acme <[email protected]>. Your emails go
through your Resend account from then on, whether or not the domain is verified
yet. Udibo bills nothing for them; your provider's charges apply. You can set a
separate limit and alert for them on your Billing page.
Verify your sending domain
After you save, the page asks Resend for your domain's status and lists the DNS records to publish, each with its own status. Add them at your DNS provider, then choose Verify domain to check again. The page shows when the domain was last checked. A check sends no email and changes no DNS records.
The domain badge shows Resend's answer: Verified, Pending verification, Not started, or Verification failed. Could not verify — check in Resend means Resend did not answer or the key cannot find the domain in that account.
Until the domain is verified, mail from it is likely to be rejected or land in spam. Also publish a DMARC record for the domain.
Record bounces and complaints
In Resend, add a webhook that sends bounce and complaint events to
https://www.udibo.com/api/webhooks/resend/{tenantId}, then paste its signing
secret into Webhook signing secret. Deliveries with an invalid signature are
refused.
A permanent bounce or a spam complaint adds the address to your tenant's suppression list. Udibo then skips security notices, waitlist emails, and organization invitations to it. Emails a person asks for — verification, password reset, sign-in codes and links, and account unlock — are still sent.
Watch sender health
"Your Resend API key cannot be read." Replace the API key. Until you do, your emails go out through Udibo's shared sender under its limits.
"Resend has rejected recent email sends from your domain." At least two sends were refused for invalid credentials in the last 24 hours. Check or replace the key in Resend.
A failed send is recorded in your audit log as
email.delivery_failed.
Remove your sender
Under Settings → Danger zone, choose Remove email sender and type the sender address to confirm. Every email goes out through Udibo's shared sender again, and your API key and webhook secret are deleted rather than kept.
Manage the sender through the API
The management API exposes the same settings at
/api/identity/{tenantId}/email-sender, with a verify operation for the
domain check. It never returns your API key or webhook secret. Today you reach
it through the dashboard; see
choose the right API.
Test before launch
Trigger each email your tenant uses and send it to real inboxes at more than one mail provider.
Check spam folders, and read the message headers to confirm SPF and DKIM pass for your domain.
If a message never arrives, check your provider's logs and your audit log.
Limits today
Resend only. No other email provider can be connected.
Fixed content. Subjects, text, and layout cannot be customized, and most account emails name Udibo.
No sending from your domain through Udibo. Mail comes from your domain only through your own provider.
Next: brand your hosted pages, or set up passwordless sign-in.
Last verified 2026-09-29.

