What’s happening
Every verification, magic-link, invite and reset email contains a link back to your app. Your auth provider or framework builds that link from a setting: the site URL, a redirect URL, or the host your mailer is configured with. When that setting still says http://localhost:3000, every email points at the developer’s own computer.
Sometimes the link itself is hosted, for example https://yourproject.supabase.co/auth/v1/verify?..., and only the page it redirects to afterwards is local. The verification succeeds, then the browser is sent to localhost:3000 and fails. That version is easy to miss, because the email looks fine.
Fix it in Supabase (including Lovable apps on your own Supabase project)
- In the Supabase dashboard, open Authentication → URL Configuration.
- Set Site URL to your live address, such as
https://your-app.lovable.appor your own domain. A new Supabase project starts withhttp://localhost:3000here. - Add every other environment you use (staging, preview domains, localhost for development) to Redirect URLs. Wildcards are supported for preview deployments.
- If your code passes
emailRedirectToorredirectTowhen calling sign-up or sign-in, build it from the current site, for examplewindow.location.origin, or an environment variable. A redirect that isn’t on the allow list falls back to the Site URL. - If you’ve customised the email templates, check they use the template’s confirmation URL or site URL variables rather than a hard-coded address.
Fix it in Firebase Authentication
- Check the continue URL your code passes in its action code settings when sending verification or sign-in links. It should come from the environment, not a hard-coded
http://localhost. - Add your live domain under Authentication → Settings → Authorized domains.
Fix it in other stacks
- Auth.js / NextAuth: set the deployment URL (
AUTH_URL, orNEXTAUTH_URLon older versions) where your host doesn’t infer it. - Ruby on Rails: set
config.action_mailer.default_url_optionswith the righthostin each environment’s config. - Django: build links from the request or the Sites framework, and make sure the site’s domain isn’t still
example.comorlocalhost. - Laravel: set
APP_URLfor each environment. - Anything else: search the code for
localhost:3000and move it into an environment variable.
How Proxy Mail QA flags it
When a link in a test email points at a local address, or redirects to one after verifying, Proxy Mail QA marks it on the Accounts row (“Redirects to localhost:3000”) and explains it in the inbox. You can tell at a glance that the environment is misconfigured, before anyone files it as “verification is broken”.
If you’re testing a local build on purpose, choose This is my dev environment. Links to that host stop being flagged in that project. You can remove it again from the project’s settings.