All skills
resend avatar

/email-best-practices

@376d1c3 official
by resendresend/resend-skills193 stars
28

Use when building email features, emails going to spam, high bounce rates, setting up SPF/DKIM/DMARC authentication, implementing email capture, ensuring compliance (CAN-SPAM, GDPR, CASL), handling webhooks, retry logic, making emails accessible (alt text, headings, contrast, screen readers), or deciding transactional vs marketing.

Use this Skill: https://skilld.dev/gh/resend/resend-skills/email-best-practices

This session only. Nothing lands on disk.

referencesemail-capture.md

≈867 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Email Capture Best Practices

Collecting email addresses responsibly with validation, verification, and proper consent.

Email Validation

Client-Side

HTML5:

<input type="email" required>

Best practices:

  • Validate on blur or with short debounce
  • Show clear error messages
  • Don't be too strict (allow unusual but valid formats)
  • Client-side validation ≠ deliverability

Server-Side (Recommended)

Always validate server-side—client-side can be bypassed.

Check:

  • Email format (RFC 5322)
  • Domain exists (DNS lookup)
  • Domain has MX records
  • Optionally: disposable email detection

Recommended tools: https://resend.com/blog/best-email-verification-apis

Double opt-in

Confirms address belongs to user and is deliverable.

Process

  1. User submits email
  2. Send verification email with unique link/token
  3. User clicks link
  4. Mark as verified
  5. Allow access/add to list

Timing: Send immediately, include expiration (24-48 hours), allow resend after 60 seconds, limit resend attempts (3/hour).

Single vs Double Opt-In

Single Opt-In Double Opt-In
Process Add to list immediately Require email confirmation first
Pros Lower friction, faster growth Verified addresses, better engagement, meets GDPR/CASL
Cons Higher invalid rate, lower engagement Some users don't confirm
Use for Account creation, transactional Marketing lists, newsletters

Recommendation: Double opt-in for all marketing emails.

Form Design

Email Input

  • Use type="email" for mobile keyboard
  • Include placeholder ("you@example.com")
  • Clear error messages ("Please enter a valid email address" not "Invalid")

Consent Checkboxes (Marketing)

  • Unchecked by default (required)
  • Specific language about what they're signing up for
  • Separate checkboxes for different email types
  • Link to privacy policy
☐ Subscribe to our weekly newsletter with product updates
☐ Send me promotional offers and deals

Don't: Pre-check boxes, use vague language, hide in terms.

Form Layout

  • Keep simple and focused
  • One primary action
  • Clear value proposition
  • Mobile-friendly
  • Accessible (labels, ARIA)

Error Handling

Invalid Email

  • Show clear error message
  • Suggest corrections for common typos (@gmial.com → @gmail.com)
  • Allow user to fix and resubmit

Already Registered

  • Accounts: "This email is already registered. [Sign in]"
  • Marketing: "You're already subscribed! [Manage preferences]"
  • Don't reveal if account exists (security)

Rate Limiting

  • Limit verification emails (3/hour per email)
  • Rate limit form submissions
  • Use CAPTCHA sparingly if needed
  • Monitor for abuse patterns

Verification Emails

Content:

  • Clear purpose ("Verify your email address")
  • Prominent verification button
  • Expiration time
  • Resend option
  • "I didn't request this" notice
  • Don't include OTP/2FA codes in subject line or preview text as it discourages opens

Design:

  • Mobile-friendly
  • Large, tappable button
  • Clear call-to-action

See Transactional Emails for detailed email design guidance.

Related

Source: SKILL.md on GitHub

No alerts16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is a comprehensive knowledge base for email best practices, including deliverability, accessibility, compliance, and reliability. It contains educational content and code examples for developers. No malicious patterns or security risks were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 376d1c3. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 4 months ago
Other metadata
metadata
{
  "author": "Resend",
  "version": "1.0.2",
  "homepage": "https://resend.com/agent-skills",
  "source": "https://github.com/resend/email-best-practices",
  "openclaw": {
    "links": {
      "repository": "https://github.com/resend/email-best-practices",
      "documentation": "https://resend.com/docs/email-best-practices-skill"
    }
  }
}
  • email
  • transactional
  • marketing
  • deliverability
  • spf-dkim-dmarc
  • compliance
  • webhooks
  • accessibility
  • list-management
  • resend

README badge

README badge for resend/resend-skills/email-best-practices

Provides decision trees and reference guides for deliverability (SPF/DKIM/DMARC), compliance (CAN-SPAM/GDPR/CASL), transactional vs marketing email classification, webhook handling, list management, and accessibility (alt text, headings, contrast). Targets teams building email features with Resend or similar transactional email APIs.

Generated from the current SKILL.md.

Does this skill cover setting up SPF, DKIM, and DMARC?
Yes. The Deliverability section covers authentication setup and is the first step recommended for fixing spam issues, as unauthenticated emails are commonly rejected by Gmail and Yahoo.
What compliance standards does this skill address?
It covers CAN-SPAM, GDPR, and CASL requirements, with a dedicated Compliance section for legal obligations around email capture and marketing sends.
Does this skill include guidance on making emails accessible?
Yes. The Accessibility section covers screen reader support, alt text, headings, contrast requirements, and proper HTML structure for inclusive email design.
How does this skill handle bounces and list hygiene?
The List Management section covers bounce handling, suppression list updates, and list hygiene jobs. Webhooks & Events section covers processing delivery events to track bounces and complaints.
Does this skill cover retry logic and idempotent sending?
Yes. The Sending Reliability section covers retry strategy, idempotency, and error handling for production-ready email sending.

Generated from the current SKILL.md. These answers refresh after source changes.