Email Sending
AgentLane sends email to your clients on your behalf: the invitation to their client portal, their password-reset link, and the notifications they have turned on (new chatbot messages, callback requests, replies). Under Settings → Email sending an agency admin chooses how that email leaves the platform.
Email to your own team — billing, seat and plan notices, team invitations — always comes from AgentLane and is not affected by this setting.
The four options
| Option | What your client sees in From | Who delivers it |
|---|---|---|
| AgentLane (default) | "Your Agency" <no-reply@agentlane.agency> | AgentLane |
| Your verified domain | "Your Agency" <no-reply@mail.your-agency.com> | AgentLane, from the sender domain you verified under Domains |
| Your SMTP server | The From address you configure | Your own mail server or relay |
| Your Resend account | The From address you configure | Your own Resend account, through your API key |
Your verified domain, Your SMTP server and Your Resend account are included from the Professional plan upwards (Scale and Enterprise too, and negotiated invoiced plans). On the Launch plan the choices are shown but locked; the API enforces the same rule, and an account that moves below Professional goes back to the AgentLane sender automatically.
Your SMTP server
Works with any mail server or relay that accepts SMTP with TLS — Google Workspace, Microsoft 365, Mailgun, Postmark, Amazon SES, your own Postfix.
| Field | Notes |
|---|---|
| Host | The server hostname, for example smtp-relay.gmail.com or smtp.office365.com. IP addresses and private hosts are refused. |
| Port | One of 25, 465, 587, 2525. Picking 465 suggests TLS, the others suggest STARTTLS. |
| Security | STARTTLS (plain connection, then a mandatory TLS upgrade — port 587) or TLS (encrypted from the first byte — port 465). There is no unencrypted option. |
| Username / Password | Optional. Leave both empty for a relay that trusts your server by IP address (Google Workspace’s relay allows this). The password is stored encrypted and is never shown again; leave the field blank on later edits to keep it. |
| From address | Must be an address the server is allowed to send for, or the server will reject it (sender_rejected). |
| Sender name, Reply-To | Optional. |
Google Workspace: host smtp-relay.gmail.com, port 587, STARTTLS. In the Admin console (Apps → Google Workspace → Gmail → Routing → SMTP relay service) allow your domain’s addresses, require TLS, and either require SMTP authentication (then use a Workspace account with an app password here) or allowlist AgentLane’s sending IP, which support can give you. The relay accepts up to about 10,000 recipients per user per day.
Microsoft 365: host smtp.office365.com, port 587, STARTTLS, a mailbox with SMTP AUTH enabled and an app password if MFA is on.
Your Resend account
Paste an API key from your own Resend account (a sending-only key is enough). The From address must be on a domain you have verified in your Resend dashboard — AgentLane’s own verified domains do not count here. Only the key’s last four characters are shown after saving; leave the field blank on later edits to keep it.
Send a test email
After saving, enter an address and press Send test. AgentLane connects to the saved transport and sends one real message, with no fallback, and reports exactly what happened:
| Result | Meaning |
|---|---|
auth_failed | The server rejected the username or password. Google Workspace and Microsoft 365 need an app password or a relay allowlist, not your normal login. |
tls_failed | The security setting does not match the port (use TLS for 465, STARTTLS for 587), or the server certificate does not match the hostname. |
connection_refused | Nothing is listening on that port, or a firewall blocks the connection. |
timeout | No answer in time. Check host and port; some providers block unknown IPs. |
dns_failed | The hostname does not resolve. |
host_not_allowed | Only public hostnames on ports 25, 465, 587 or 2525 can be used. |
sender_rejected | The server will not send from that From address. |
rejected | The server refused the message; check your provider’s dashboard. |
Tests are limited to six per hour. Every test and every settings change is recorded in your audit log (never including the secret itself).
If your server fails later
Client email is time-sensitive — a password reset must arrive. If your SMTP server or Resend key rejects a message, AgentLane delivers that message from the AgentLane mailbox under your agency’s display name instead, records the failure on the Email sending card, and notifies your team (at most once per hour). Fix the settings, run a test, and subsequent email uses your transport again.
Resetting
Reset to AgentLane default deletes your saved SMTP password or Resend key and returns client email to the AgentLane sender with your agency as the display name.
Where the data goes
With Your SMTP server or Your Resend account, the message content and your clients’ addresses are handed to infrastructure you chose and contracted. That provider is your processor, not an AgentLane sub-processor; AgentLane’s sub-processor list covers the AgentLane and verified-domain options.
Related
- Partner Dashboard — the Settings page
- Admin Panel — an AgentLane admin can see each agency’s chosen mode (read-only, secrets masked) on the partner page