Why verification emails are awkward to test
Sign-up is the first thing every user does, and the confirmation email is the first message your app ever sends them. It is also one of the hardest flows to test properly:
- Every run needs a new address. Reuse one and you get “this email is already registered”, so testers end up inventing addresses or deleting accounts between runs.
- Shared inboxes mix things up. With a team Gmail, five people’s confirmation emails land in one place. Someone clicks your link, or you use a code meant for someone else.
- Plus-addresses aren’t what real users type. Addresses like
name+test1@gmail.comare rejected or quietly normalised by some sign-up forms, so the flow you test isn’t the one your users hit. - Local mail catchers stop at your laptop. Tools like Mailpit only see mail your local stack sends. They can’t tell you whether staging or production email is really delivered, or what it really links to.
How it works with Proxy Mail QA
- Create an address. One click gives you a random, unguessable address such as
k3f9q2m8x7aa@mailclub.dev. You can also pick a custom name, or create a whole batch, each with a generated name and username for the sign-up form. - Sign up in the app you’re testing. Use the address exactly as a real user would.
- Watch the row update. Within seconds the Accounts view shows who emailed you and the action from the email: a button named Activate account for a link, or the code with a Copy button.
- Check the email itself. Open the inbox to read the full message, with remote images blocked until you allow them, and every code and link that was found in it.
Nothing on our side ever opens or prefetches the links in your emails, so a single-use verification link is still unused when you click it.
What to check in a verification email
A confirmation email can “work” and still be broken. Run through this list on every environment:
- It arrives within a few seconds, from a sender name your users will recognise.
- The link opens the right environment. A link to
localhost:3000from staging is a bug, and we flag it for you. - The link works exactly once. Clicking it again shows a helpful message, not an error page.
- An expired link explains what to do next, and Resend sends a fresh one.
- The subject line and opening sentence make sense in a crowded inbox, and there is a plain-text version.
- After confirming, the user lands somewhere sensible and is signed in (or told to sign in).
Keep track of every test account
Each address keeps its own notes, tags and generated persona, plus the password you signed up with, encrypted and hidden until you reveal it. Weeks later you can still find “the youth account on staging” by searching notes or tags, instead of guessing which Gmail alias it was.