Skip to content
ZevSend
All articles DeliverabilityGuides Authors Search
Docs Pricing Get started

The 12 emails every product has to send

Verification, resets, receipts, dunning, invites, security alerts: the twelve transactional emails no product escapes, what belongs in each one, and the production failure each one is known for.

DAN 4 min read

Strip any product down to the messages it cannot skip and you find the same twelve emails, every time. Each one has a job, a deadline, and a way of failing that only shows up in production. This is the reference list: what triggers each email, what belongs in it, and the mistake teams make with it.

Identity emails

1. Verify your address

Sent the moment someone signs up with an email address. One link or one code, an expiry, and nothing else competing for attention. The classic failure is burying the link under a welcome pitch: the reader came to click one thing, so give them one thing.

2. Welcome

Sent after verification, not instead of it. This is the only email on the list that is allowed to sell, and even here the best ones teach instead: the first three steps, one link each. If your welcome email and your verification email are the same message, split them.

3. Password reset

The email with the strictest deadline on the list. A reset link that takes two minutes to arrive reads as a broken product, and the user who requested it is already sitting on the login page. Single-use link, short expiry, and a plain sentence for the person who did not request it. Never confirm or deny whether the address has an account in the email subject; that leaks membership to anyone who can type an address.

A password reset that happens every session, which means every property of the reset email matters more: speed, single use, short expiry. The failure mode unique to magic links is the corporate link scanner that clicks the link before the human does, burning a single-use token. Either allow a second use within a short window or make the landing page confirm with a button press.

5. One-time code

The code beats the link when the user is on a different device from their inbox. Put the code first, in the subject if you can: 483920 is your ZevSend code lets the OS surface it without the app being opened. Expire it fast and say the expiry in the message. A code that arrives after it expires is worse than no code, so this email deserves your fastest sending path.

Money emails

6. Receipt

Sent immediately after any charge. Amount, what it was for, the last four digits of the method, and where to get help. Receipts get forwarded to accountants and pasted into expense tools, so they should render as plain readable text without images. This is also the email people search their inbox for months later; put the product name and the amount in the subject.

7. Invoice

The receipt’s formal sibling: numbered, dated, addressed to a legal entity, and attached or linked as a PDF that survives printing. If your customers are businesses, the invoice email is a compliance artifact, not a courtesy.

8. Renewal reminder

Sent far enough before the charge that cancelling is realistic. The teams that skip it save a support ticket this month and buy a chargeback next month. State the amount, the date, and the cancel path in one screen of text.

9. Payment failed

The one email on this list that directly protects revenue. Say what failed, what happens next, and give one link to fix the payment method. Send it on a schedule, not once: the first attempt catches typos, the third catches expired cards. Keep the tone factual; the reader has not done anything wrong.

Team and safety emails

10. Invite

Someone added a teammate; the teammate got an email from a product they have never heard of. Name the person who invited them and the workspace they are joining above everything else, because this email has to survive the "is this phishing" glance. Expire invites and show who has not accepted.

11. Security alert

New device, new location, password changed, recovery email changed. The rule: notify the OLD address about changes to the address, and never include a login link in a security alert, because that trains your users to click login links in security-shaped emails, which is exactly what phishing is.

12. Account deletion

Confirm the request, state what will be deleted and when, and give a recovery window. This is the last email you will ever send this person; a graceless one is a review, a graceful one is sometimes a return.

The rules that cut across all twelve

  • These are transactional emails. Keep them off the domain or subdomain you use for marketing, so a newsletter complaint never drags a password reset into spam with it.

  • Every one of them needs a reply path a human reads. A no-reply@ address on a payment-failed email is a support ticket you refused to receive.

  • Retries must be idempotent. The user who clicks "resend code" three times should get the newest code, not three racing ones.

  • Test rendering in Gmail and Outlook both. The twelve above are exactly the emails where a collapsed layout costs money or access, not clicks.

Keep reading

More in Guides

Ship email that actually arrives

ZevSend is a developer API for transactional email, SMS, WhatsApp, and verification codes. Free plan, sandbox mode, and DNS records we generate for you.