Email and templates
Set up SMTP, choose the sender, and edit the wording of every message the product sends.
Transactional mail is queued and sent by a scheduled job rather than during the request that caused it. That is why a slow mail server cannot hold up certificate work, and why no queued message is delivered until the email job is running. The SMTP test below is the one deliberate exception because it has to show the server response while the entered settings are still on the page.
Setting up SMTP
Admin. Open Email settings. Enter the host, port, encryption,
user name and password of a mailbox you control. Saved values are held encrypted in the
database and take precedence over the MAIL_* keys in .env.
| Field | Usual value |
|---|---|
| Host | The SMTP host of your provider, for example smtp.example.com. |
| Port and encryption | 587 with tls, or 465 with ssl. |
| User name | Usually the full mailbox address. |
| Password | Write-only. Once saved it is never shown again, and leaving the field blank keeps the current one. |
Before saving, select Send test email. CertiFlow sends one branded message immediately to the signed-in Admin using the values currently in the form, including values that have not been saved. The page shows the exact SMTP success or failure response. The test does not change the stored connection; select Save SMTP settings after a successful test.
Send from your own domain. A sender address on a domain you do not control is rejected or filed as spam by most receiving servers, however correct your SMTP settings are. Set up SPF, and DKIM if your provider offers it, for the domain in the sender address.
The sender address
The sender address and display name are saved separately from the connection, so you can send through one provider while appearing as another address on the same domain. Both are validated when you save them.
Send limits
System Admin. On Email settings, set the maximum batch size, the delay between attempts and the rolling-hour attempt cap. Defaults are 25 messages per run, one second between attempts and 100 attempts per hour. Start with your relay's published limits and raise these values only when your provider permits it.
The cap counts every reserved sending attempt, including failures and retries, across worker restarts. A crash after reservation still consumes that attempt. Jobs run one at a time, wait only between actual attempts and leave messages pending when the cap is reached. Email deliveries shows the hourly-cap reason and next attempt time. Queue limits do not apply to the separately rate-limited SMTP test.
These settings are stored separately from SMTP credentials and sender details. Upgrades preserve existing administrator settings; conservative defaults apply until limits are saved. A database failure stops dispatch rather than bypassing the cap.
Editing the messages
Admin. Open Email templates. Every message the product sends is listed with its subject, body and action label, in both bundled languages, with a preview that uses your branding.
- Edits are stored as overrides, so a later release can add or improve default wording without discarding yours.
- Only the wording is editable. The link a message carries is always generated, so no edit can point a recipient at the wrong certificate.
- The same screen is a view of the translation system, which means a message you edit in one language stays independent of the other.
What gets sent
| Message | When |
|---|---|
| Account activation | An internal or verifier account is created. The link is valid for 24 hours. |
| Password reset | Someone uses the forgotten-password form. |
| Certificate notification | A certificate is issued, or an import is confirmed, with notification requested and an email address present. |
The certificate notification carries a link, never the PDF. A recipient opens the verification page and downloads from there, which keeps a forwarded email from handing the document to someone else.
Resend a certificate notification
On Certificates, Admins and Operators can choose Resend notification for an active, verified certificate whose participant requested notification. Confirm the current recipient before queueing it. A message already waiting in the queue is not duplicated, and an opted-out, revoked, archived or deleted certificate cannot be resent.
Resend failed notifications applies to the whole current filtered list, including its other pages. Only certificates whose latest notification failed qualify. Each retry creates a fresh message with the current email address and template; older delivery rows and audit history remain available. Running the email job sends queued messages separately.
When mail is not arriving
Admin. Open Email deliveries below Email settings. Filter by status and the date the message entered the queue. The paginated list shows the recipient, subject, status, failed-attempt count, next attempt and sent time. A pending message is waiting for the scheduled email job; a failed message has exhausted its retries. The last-error indicator is deliberately generic: message bodies, activation/reset links and raw SMTP replies are never shown in this log.
- Confirm the email job is running. If
cron/process_email_queue.phpis not scheduled, the queue simply grows. - Run it once by hand from the control panel and read the output: it prints how many messages were sent and how many failed.
- Check Email deliveries for failures. Use Send test email on the SMTP settings screen to diagnose the configured connection; its response is credential-redacted.
- Retry counting is per message, up to
EMAIL_MAX_ATTEMPTS. After that the message is marked failed and is not retried. - If nothing is configured at all, the product falls back to the server's own mail function. It works on some hosts and silently fails on many, so treat SMTP as required.