Resend (Email Notifications)
Resend is the default email provider for production deployments. The framework uses it for transactional emails — verification, password resets, invitations, etc.
In local development, emails are logged to the console. No Resend account is needed until you deploy to the cloud.
Prerequisites
- A Resend account (free tier available)
- A domain you control (for DNS verification)
- Cloud environment deployed (Infrastructure setup)
Local Development
No setup needed. The framework uses a console provider that logs emails to the terminal:
To test with real emails locally, set EMAIL_PROVIDER to resend in .secrets.user.json (see Local Secrets):
Then regenerate secrets:
Production Setup
1. Create a Resend Account
- Sign up at resend.com
- Get your API key from the API Keys page
2. Verify Your Domain
In the Resend dashboard, add your domain. Resend will show the exact DNS records you need to create (DKIM, SPF, MX, and optionally DMARC). Follow their instructions — the records and values may change over time, so always use what the dashboard shows.
These records are separate from the infrastructure DNS records covered in Domain Setup.
Where to add these records
Where you create the DNS records depends on your cloud provider:
- GCP — Add the records at your domain registrar (Namecheap, Cloudflare, GoDaddy, etc.). GCP does not manage your DNS zone, so all DNS records (infrastructure and Resend) go to the registrar.
- AWS — Add the records in Route 53. Since your nameservers point to Route 53, it is the authoritative DNS for your domain. Go to Route 53 > Hosted zones > your domain > Create record.
- Azure — Add the records in Azure DNS. Since your nameservers point to Azure DNS, it is the authoritative DNS for your domain. Go to Azure Portal > DNS zones > your domain > + Record set.
Set up Resend domain verification alongside your infrastructure DNS records. You'll be adding DNS records for both at the same time, so doing them together avoids waiting for propagation twice.
DNS propagation can take up to 48 hours, but usually completes within minutes.
3. Push Secrets
cloud-secrets:push prompts for Resend credentials automatically:
It will ask for:
To set or update individually:
EMAIL_PROVIDER is automatically set to resend in cloud environments. You don't need to set it manually.
Usage
Import NotificationModule and inject NotificationService:
For the full API reference (email options, custom providers, testing), see NotificationModule in nest-common.
Using a Different Email Provider
Resend is the default, but you can replace it with SendGrid, Mailgun, Postmark, or any other provider by implementing the EmailProvider interface and overriding the EMAIL_PROVIDER injection token.
See Custom Email Provider for a full walkthrough with code examples, secrets setup, and testing patterns.
Secrets Reference
Troubleshooting
Emails Not Sending in Production
- Verify
RESEND_API_KEYis set:npx tsdevstack cloud-secrets:list --env prod - Check that your domain is verified in the Resend dashboard
- Check service logs for error messages
Domain Not Verified
- Confirm DNS records match what Resend shows in its dashboard
- Wait for DNS propagation (up to 48 hours)
- Use Resend's "Verify" button to re-check
Emails Going to Spam
- Ensure DKIM, SPF, and DMARC records are all set
- Use a sender address on your verified domain (not a free email provider)
- Start with low volume to build sender reputation