Design & Architecture

Email & Notifications

Intermediate

Email and other notifications are how we reach customers. They are also where a small mistake becomes a privacy breach (the wrong recipient), a security risk (a message that is easy to phish), or a delivery failure (everything lands in spam). Send with care: the right content, to the right person, clearly from us.

Notifications carry two risks people underestimate. First, content and addressing: an email can leak personal data to the wrong recipient, or include sensitive details it should not. Second, trust and delivery: if our domain is not configured properly (SPF, DKIM, DMARC), attackers can spoof our mail or it gets filtered as spam. And our customers are exactly the people phishers target.

Treat outbound messaging as a small product: a verified sending identity, minimal sensitive content, clear and hard to spoof, and resilient when the messaging provider fails.

Send safely

Send reliably

Self-review checklist

Why it matters: A misaddressed or over-detailed email is a real, common privacy breach. A well-configured sending domain that is hard to spoof protects our customers from phishers pretending to be us. And decoupled, idempotent sending keeps the app fast and avoids spamming people. Notifications are customer-facing and security-sensitive, so send them with care.