🚀 Introduction
When building login systems with OTP (One-Time Password), many developers initially rely on Gmail SMTP. While this works for testing, it’s not ideal for production.
In this guide, we’ll walk through how to configure a professional domain email (like noreply@yourdomain.com) for sending OTPs — improving deliverability, branding, and reliability.
❌ Why Not Use Gmail for OTP?
Using Gmail SMTP may seem convenient, but it has limitations:
- Emails show as personal Gmail accounts (not professional)
- Sending limits are strict
- Higher chances of being flagged or blocked
- Not scalable for production apps
👉 Example:
✅ What We Will Set Up
By the end of this guide, you’ll have:
- Custom domain email (e.g., noreply@yourdomain.com)
- SMTP configured in your application
- DKIM and DMARC enabled
- OTP emails delivered to inbox (not spam)
🧩 Step 1: Create a Domain Email
Login to your hosting control panel (like cPanel ).
Go to:
👉 Email Accounts → Create New Email
Create:
noreply@yourdomain.com
Set a strong password and save it.
⚙️ Step 2: Get SMTP Configuration
After creating the email:
Go to:
👉 Email Accounts → Connect Devices / Mail Client Setup
You will get:
SMTP Host: smtp.yourdomain.com
Port: 465
Encryption: SSL
Username: noreply@yourdomain.com
Password: (your email password)
(or Same SMTP config get it from your email services provider)
💻 Step 3: Configure SMTP in Your Application (PHP Example)
Update your configuration file:
'mail_from_address' => 'noreply@yourdomain.com',
'mail_from_name' => 'YourApp Security',
'smtp_host' => 'smtp.yourdomain.com',
'smtp_port' => 465,
'smtp_encryption' => 'ssl',
'smtp_auth' => true,
'smtp_username' => 'noreply@yourdomain.com',
'smtp_password' => 'your-email-password',
🔐 Step 4: Enable DKIM (Email Authentication)
Go to:
👉 Domainkeys (DKIM)
Configure:
- Selector:
default - Canonicalization: Relaxed
- Enable DNS Record: ✔
Click Add Signature
👉 This ensures your emails are trusted by providers like Gmail.
🛡️ Step 5: Configure DMARC
Go to:
👉 DMARC Wizard
Set:
- Policy: Quarantine
- Alignment: Relaxed
- Percentage: 100%
Click Add DMARC
👉 This protects your domain from spoofing and improves inbox delivery.
🧪 Step 6: Test Your OTP System
Now test:
- Forgot Password
- Login with OTP
Check:
- Inbox (Primary)
- Spam (first few attempts)
📬 Expected Email Output
Your users will receive:
From: YourApp Security <noreply@yourdomain.com>
Subject: OTP Verification
⚠️ Common Mistakes to Avoid
- Using wrong SMTP host (e.g., using domain instead of smtp.domain.com)
- Incorrect port/encryption mismatch
- Not enabling DKIM (causes spam issues)
- Leaving placeholder password in config
- Sending too many emails at once
📊 Limitations of Hosting SMTP
Hosting SMTP is great for:
✔ OTP systems
✔ Small to medium applications
But not ideal for:
❌ Bulk emails
❌ Marketing campaigns
For scaling, consider:
- SendGrid
- Amazon SES
- Mailgun
🎯 Final Result
After completing all steps:
- Emails are sent from your domain
- OTP delivery is reliable
- Spam issues are minimized
- Your app looks professional
💡 Conclusion
Setting up domain-based email for OTP is a critical step in building production-ready applications.
It improves:
- Trust
- Deliverability
- Branding
If you're building any login system, this setup is highly recommended.
Comments
No comments yet.