Skip to content
Back to skills

Resend Email

ASecurity

Resend transactional email, React Email templates, domain setup and webhooks. Use when sending email with Resend, building an email template, or configuring email delivery.

  • 80 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 3, 2026
ai-agentsgoreactapi

Works with

  • cli
  • api

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned October 5, 2026

npx -y skills add monkilabs/opencastle --skill resend-email --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Resend Email?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Resend Email
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/monkilabs-resend-email/badge)](https://www.skillsdirectory.com/skills/monkilabs-resend-email)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: resend-email
description: "Resend transactional email, React Email templates, domain setup and webhooks. Use when sending email with Resend, building an email template, or configuring email delivery."
---

# Resend Email

Docs: https://resend.com/docs

Env: `RESEND_API_KEY` (resend.com → API Keys), `RESEND_WEBHOOK_SECRET` (resend.com → Webhooks).

## Gotchas

- **Resend webhooks are Svix-signed.** Verification needs all three headers — `svix-id`, `svix-timestamp`, `svix-signature` — passed to `new Webhook(process.env.RESEND_WEBHOOK_SECRET).verify(rawBody, headers)`. Verify against the **raw** `request.text()`; parsing the JSON first invalidates the signature. Return 400 on failure, 200 on success. Events: `email.delivered`, `email.bounced`, `email.complained`.
- `from` must use a verified domain and the `'Name <no-reply@yourdomain.com>'` form. `to` is an array.
- Pass a React Email component via `react:` (not `html:`); the two are mutually exclusive.

## Domain setup

1. Add the domain at resend.com → Domains, then add the SPF, DKIM, and DMARC records. Verification typically completes within an hour.
2. Confirm propagation before blaming the API: `dig TXT yourdomain.com` — SPF/DKIM records must appear.
3. Send one test message and check the received headers show SPF and DKIM **pass**.
4. Smoke-test the webhook endpoint returns 200:
   `curl -X POST -H 'Content-Type: application/json' -d '{"type":"email.delivered"}' https://yourapp.com/api/webhooks/resend`

Failures here are nearly always DNS propagation, a wrong API key scope, or a mismatched webhook secret.

## Templates

`npm install resend @react-email/components`. Build templates from `@react-email/components` primitives (`Html`, `Head`, `Body`, `Container`, `Heading`, `Text`, `Button`) — plain HTML/CSS is unreliable across clients. Preview locally with `npx react-email dev` — the preview server is the `react-email` package, which `@react-email/components` does not install.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…