Skip to content

Approvals, logs & sending

Send email over SMTP

Connect Supabase Auth, WordPress, or any app that speaks SMTP to Banger, so its email leaves from your domain and shows up in Logs.

5 min readUpdated
In this guide 8 sections

Banger’s SMTP relay lets any app that can only send over SMTP, such as Supabase Auth, Auth0, WordPress, or your framework’s mailer, send through Banger. Your app logs in with a Banger API key, and every message leaves from your own domain and appears in Logs.

Before you start

You need two things:

  1. A Product lane. The From address must be on a domain or subdomain with a ready Product lane. Open Domains › Add lane, choose Product, and add the DNS records it lists. See Add your domain. A Mail lane (your team’s mailboxes) or a Broadcast lane can’t send app email, so your app’s mail never affects your team’s inbox reputation.
  2. An API key that can send. Open API keys › Create API key, name it after the app (for example “Supabase Auth”), select only mail:send, and choose Create key. Copy it right away: it’s shown once.

You can also reach API keys from Settings › Developers › Manage API keys.

SMTP settings

The SMTP box on the API keys page shows these settings, with a copy button for the host.

SettingValue
Hostsubmit.bangermail.com
Port465 (TLS) or 587 (STARTTLS)
Port, if those are blocked2465 (TLS) or 2587 (STARTTLS)
Usernamebanger (any value works; the key identifies your workspace)
PasswordYour API key
EncryptionTLS 1.2 or newer. Login is only offered after TLS starts.
AuthenticationPLAIN or LOGIN

If your app asks for “SSL” or “TLS”, use port 465. If it asks for “STARTTLS”, use 587.

Connect Supabase Auth

  1. In Supabase, open Authentication › Emails › SMTP Settings and turn on custom SMTP.
  2. Sender email: an address on your Product lane, such as noreply@app.example.com.
  3. Sender name: your product’s name. Banger keeps it as written.
  4. Host submit.bangermail.com, Port 465, Username banger, Password your API key.
  5. Save, then send yourself a magic link from Authentication › Users.

Other apps work the same way: paste the settings above into their SMTP or mail settings. Code examples are in the SMTP developer docs.

Check it worked

Open Logs. Each message your app sends appears with SMTP as its source and its delivery status. Banger also logs every attempt it refused, with what to fix.

Your app gets 250 2.0.0 Queued as … when Banger accepts a message.

What Banger does with each message

  • Sends it as your app wrote it, with your From name, signed with your domain’s DKIM key.
  • Removes Bcc and Return-Path, and adds a Reply-To naming the From address when there is none.
  • Skips suppressed recipients and sends to the rest.
  • Treats a retry of the same message as the same send, so a timeout never sends twice.
  • Counts each message toward your plan, like any other send.

Each message can be up to 10 MiB with up to 50 recipients.

When a message is refused

Every refusal says why and includes a reference, (ref …), that matches the entry in Logs. Codes starting with 4 are temporary; your app can retry later.

ReplyWhat to do
535 5.7.8The password isn’t a working API key. Check it wasn’t revoked and has mail:send.
421 4.7.0Three failed logins on one connection, so it closed. Fix the key before retrying.
454 4.7.0Too many failed logins from your network. Fix the key, then wait up to an hour.
550 5.7.1The From domain has no ready Product lane (the reply names what it lacks), the recipient is suppressed, or sending is paused. See Deliverability and sending pauses.
553 5.1.3A recipient address isn’t valid.
552 5.3.4The message is larger than 10 MiB.
554 5.6.0The message is malformed, such as two From headers or a From with several addresses.
451 4.7.0Your sending allowance or daily limit is used up. It renews next period or day, or now with an upgrade.
451 4.3.0Banger couldn’t take the message right now. Your app should retry.

Keep the key safe

  • Give each app its own key with only mail:send. A leaked SMTP password then can’t read your workspace.
  • To rotate, create a new key, update the app, then Revoke the old one. Apps still using it are refused at their next login.
  • Banger stores only a hash of each key and records refused logins in Logs.

Try it with your AI

Create an API key that can only send mail, check my Product lane is ready, and give me the SMTP settings to paste into Supabase.

Still stuck? Contact support with the screen and the exact error.