How auth emails work in a Lovable app
Lovable builds your app’s front end and connects it to a Supabase backend, either a Supabase project you connect or Lovable’s own managed backend. When someone signs up, asks for a magic link or resets their password, Supabase Auth sends the email and builds its link from your project’s settings.
Test every auth email in five minutes
- Create an address in Proxy Mail QA, with a generated persona if your form asks for a name.
- Sign up on your published app, not only in the editor preview.
- Use the link or code from the row. A confirmation link becomes an Activate account button; codes get a Copy button.
- Then test the rest: sign out, request a magic link or a password reset, and use those too.
- Save the password on the row so you can sign in as this user again later.
The two settings that break Lovable auth emails
1. Site URL still set to localhost. In your Supabase project, open Authentication → URL Configuration. Set Site URL to your published address, such as https://your-app.lovable.app, or your custom domain, and add other addresses you use under Redirect URLs. Otherwise confirmation links send people to localhost:3000. Proxy Mail QA flags those links, including hosted Supabase links that only redirect to localhost after verifying. Full guide.
2. The default email sender. Supabase’s built-in sender is for development: it sends only a few emails an hour and may refuse addresses outside your team. Before you test with outside addresses or launch, set up custom SMTP in your Supabase project with a provider such as Resend, then send yourself a test sign-up.
Ask Lovable for the fix
Once you’ve seen the problem, a precise prompt works best: “Use the current site’s address as the email redirect for sign-up and password reset, instead of a hard-coded URL.” Then sign up again with a fresh address to confirm.