Proxy Mail QA

Why your verification link goes to localhost:3000, and how to fix it

You sign up on staging, the email arrives, you click the link and get "This site can't be reached" at localhost:3000. The email isn't broken: your app is putting a development address into it.

Updated

What’s happening

Every verification, magic-link, invite and reset email contains a link back to your app. Your auth provider or framework builds that link from a setting: the site URL, a redirect URL, or the host your mailer is configured with. When that setting still says http://localhost:3000, every email points at the developer’s own computer.

Sometimes the link itself is hosted, for example https://yourproject.supabase.co/auth/v1/verify?..., and only the page it redirects to afterwards is local. The verification succeeds, then the browser is sent to localhost:3000 and fails. That version is easy to miss, because the email looks fine.

Fix it in Supabase (including Lovable apps on your own Supabase project)

  1. In the Supabase dashboard, open Authentication → URL Configuration.
  2. Set Site URL to your live address, such as https://your-app.lovable.app or your own domain. A new Supabase project starts with http://localhost:3000 here.
  3. Add every other environment you use (staging, preview domains, localhost for development) to Redirect URLs. Wildcards are supported for preview deployments.
  4. If your code passes emailRedirectTo or redirectTo when calling sign-up or sign-in, build it from the current site, for example window.location.origin, or an environment variable. A redirect that isn’t on the allow list falls back to the Site URL.
  5. If you’ve customised the email templates, check they use the template’s confirmation URL or site URL variables rather than a hard-coded address.

Fix it in Firebase Authentication

Fix it in other stacks

How Proxy Mail QA flags it

When a link in a test email points at a local address, or redirects to one after verifying, Proxy Mail QA marks it on the Accounts row (“Redirects to localhost:3000”) and explains it in the inbox. You can tell at a glance that the environment is misconfigured, before anyone files it as “verification is broken”.

If you’re testing a local build on purpose, choose This is my dev environment. Links to that host stop being flagged in that project. You can remove it again from the project’s settings.

Try it on your next sign-up test

Free plan, no credit card. Create an address and watch the code or link arrive.

Create a free accountOpen the app

Questions

Why does the link work for the developer but not for me?

localhost always means "this computer". On the developer's laptop their dev server is running, so the link opens. On anyone else's machine there is nothing listening, so it fails.

Is a localhost link ever correct?

Yes, when you're testing a local build on purpose and the dev server runs on the same computer you click from. In Proxy Mail QA, mark that host as a dev environment and links to it won't be flagged again in that project.

I fixed the setting. Why do old emails still link to localhost?

The address is written into each email when it's sent. Request a new email after changing the setting; the old ones will keep their old links.

Which links does Proxy Mail QA flag?

Links to localhost, 127.0.0.1, 0.0.0.0, private network addresses such as 192.168.x.x, and names ending in .local, .test or .localhost, plus hosted links that redirect to one of those after verifying, such as Supabase's redirect_to or Firebase's continueUrl.

Built your app with an AI tool? Pick yours →