Hey r/Supabase,
We run several web applications natively on Supabase (in audio tech and hardware diagnostics).
Like many teams here, we quickly ran into the classic transactional email dilemma:
Default Supabase Mailer: Easily hits built-in rate limits (HTTP 429 Too Many Requests) during user testing or sudden signup surges.
Switching to Custom SMTP (Resend/SendGrid/SES): Solves the rate limit, but opens up a dangerous new problem: if an attacker exploits a password-reset or invite form, your bounce rate can easily spike past 5%, causing providers to instantly suspend your production domain with zero warning.
To solve both problems, we designed a lightweight pre-flight outbound circuit breaker built directly on top of our Supabase PostgreSQL database.
The Architecture:
Before any email touches our delivery provider, the payload is inspected:
Blocks batch password/credential resets in real time (HTTP 403).
Catches internal domain spoofing attempts.
Every attempt (blocked or delivered) logs an audit entry to Supabase with email bodies automatically redacted and an immutable SHA-256 compliance hash:
codeSQL
CREATE TABLE security_audit_logs ( id UUID DEFAULT gen_random_uuid() PRIMARY KEY, event_type TEXT NOT NULL, details JSONB, compliance_hash TEXT, payload_snapshot JSONB, created_at TIMESTAMPTZ DEFAULT NOW() );
When an attack is blocked, the signature is saved to a global_threat_signatures table in Supabase so our other applications are preemptively shielded from the same domain.
Only verified payloads are handed to Resend/SES for physical delivery, ensuring our domain maintains a sub-1% bounce rate.
We packaged this into an open gateway and live dashboard (SentriSend) with an official TypeScript SDK
Curious how other Supabase builders handle this: How do you currently safeguard your custom SMTP domains from being blacklisted by unexpected user surges or bot abuse?
The user shares a solution for handling Supabase Auth email rate limits and domain suspension risks. They describe a pre-flight circuit breaker system built on Supabase PostgreSQL to prevent email rate limit issues and domain suspension due to high bounce rates. The solution includes anomaly detection, audit logging, and a threat graph to protect against attacks. They seek feedback from other Supabase users on safeguarding SMTP domains.
[ Removed by Reddit ]
(Happy to share our live dashboard and SDK link in the comments if anyone wants to check out the setup!)