Resend
Transactional email with React-based templates and delivery webhooks.
The rule
This is the whole text, exactly as your agent receives it. Nothing is held back for the paid tier.
Where it runs
- Server-side only. The API key sends mail as your domain to any recipient. Never in the app, never in an
{{envPrefix}}*variable.
Sending
- Check the returned
error— the SDK returns{ data, error }and does not throw. An unchecked error is indistinguishable from success. - Idempotency on any retryable path. A webhook or queue consumer without a guard emails the user once per retry, and sending cannot be undone.
- Every template needs a plain-text alternative.
Deliverability
- Send from a dedicated transactional subdomain, never the primary domain.
- Handle
email.bouncedandemail.complained, and suppress those addresses. Continuing to send to bounces destroys sender reputation. - Verify webhook signatures — the endpoint is public.
Templates
- Mail clients support a fraction of modern CSS; Outlook renders with Word. Tables and inline styles.
- Never put a token, password or session id in an email body. Send a short-lived, single-use link instead.
Never
- Never log full recipient lists or message bodies.
- Never send bulk or marketing mail through a transactional flow without unsubscribe handling.
6 formats, one per tool
Each tab is the file that tool actually reads, at the path it actually looks in. Knowing where each one looks is most of the work of supporting it.
---
description: Resend transactional email conventions
globs: ["server/**", "api/**", "emails/**", "src/services/email/**"]
alwaysApply: false
---
# Resend
## Where it runs
- **Server-side only.** The API key sends mail as your domain to any recipient.
Never in the app, never in an `{{envPrefix}}*` variable.
## Sending
- Check the returned `error` — the SDK returns `{ data, error }` and does not
throw. An unchecked error is indistinguishable from success.
- **Idempotency on any retryable path.** A webhook or queue consumer without a
guard emails the user once per retry, and sending cannot be undone.
- Every template needs a plain-text alternative.
## Deliverability
- Send from a dedicated transactional subdomain, never the primary domain.
- Handle `email.bounced` and `email.complained`, and suppress those addresses.
Continuing to send to bounces destroys sender reputation.
- Verify webhook signatures — the endpoint is public.
## Templates
- Mail clients support a fraction of modern CSS; Outlook renders with Word.
Tables and inline styles.
- Never put a token, password or session id in an email body. Send a
short-lived, single-use link instead.
## Never
- Never log full recipient lists or message bodies.
- Never send bulk or marketing mail through a transactional flow without
unsubscribe handling.
Hand-written by the module author, frontmatter and all. It is the source the four derived formats are rendered from, so a correction lands here first.
What else this module writes
The rule is one file of several. Selecting Resend contributes all of this too — merged with every other module you pick, with conflicts resolved rather than duplicated.
RESEND_API_KEYrequiredSends email. Never ship in the app.RESEND_FROM_EMAILrequiredVerified sender. Use a dedicated transactional subdomain.RESEND_WEBHOOK_SECREToptionalVerifies bounce and complaint webhooks. The endpoint is public.Advisory history
Every time this rule turned out to be wrong, and what we did about it.
This rule has been accurate since it was published. That is a fact about the rule, not a promise about the future — which is the whole reason this section exists.
Pro tells you the day a correction lands that affects a repo you actually have.
See what Pro adds →Rules people add alongside this one
The wizard picks the rest of the stack with you, writes all 6 formats, and leaves a manifest so check can tell you when any of it drifts.