Why magic links are easy to break in testing
- They’re single-use. Corporate email security, link previews and some mail apps open links to scan them. If that happens first, your click hits “link already used”.
- Several requests, several links. Request two links and only the newest may work. In a shared inbox it’s hard to tell which is which.
- Device and browser rules. Depending on your setup, the link may need to be opened in the same browser that requested it.
- Redirects. After the sign-in completes, the user is redirected to your app. If that address is wrong, everything looks fine until the last step.
How Proxy Mail QA helps
- Create an address and request a magic link from your app.
- The row shows a Sign in button the moment the email arrives. Nothing has opened the link before you.
- Click it: it opens in a new tab with no referrer, just like a careful user’s mail app.
- If the link, or the page it redirects to after signing in, points at
localhostor another local address, we flag it so you can tell a broken environment from a broken flow.
What to check in a magic-link email
- The link signs you in once, and a second click explains that it has been used.
- Requesting a new link makes the old one stop working, if that’s your policy.
- The expiry is stated in the email and matches what the app enforces.
- Opening the link on another device does what you expect, with a clear message if it can’t complete there.
- After signing in, the user lands on the page they were trying to reach.