Supabase Go-Live Checklist
Before opening your application to public traffic, ensure your Supabase and Mailofly email configuration is hardened for production.1. Domain Verification
- Your domain has a green Verified status in Mailofly.
- Both DKIM and SPF records are active and passing in DNS.
- You have a root DMARC record configured (
v=DMARC1; p=none; ...).
2. Match Sender Domain Exactly
- The Sender Email in Supabase matches your verified Mailofly domain:
- Example: If you verified
auth.myapp.com, useno-reply@auth.myapp.com. - Do not send from unverified addresses or mismatched domains.
- Example: If you verified
3. Customize Email Templates
- Replace Supabase’s default generic email copy with branded templates.
- Ensure all confirmation links point to your production URL (
https://myapp.com/auth/confirm), notlocalhost:3000. - Set token expiration times (default is 1 hour).
4. Rate Limiting and Anti-Abuse
- Configure Supabase auth rate limits to prevent brute-force sign-ups.
- Enable CAPTCHA (hCaptcha or Cloudflare Turnstile) on your registration form to prevent bots from generating fake sign-ups and spam bounces.