Docs / Keycloak

Configure Keycloak email over SMTP

Keycloak sends email for address verification, password recovery and required actions an admin triggers for a user. None of it can be delivered until the realm has an SMTP server. There is no extension to install: every realm has its own Email tab in the admin console.

✓
You can get them on the token management page. For security reasons, a token is shown only once — at the moment it is created.

SMTP connection settings

SettingValue
SMTP hostsmtp.postwing.app
Port587
EncryptionSTARTTLS (the connection is upgraded to TLS before login)
UsernameThe login of an SMTP token for your domain
PasswordThe password of that token — shown once, when the token is created
ℹ
Every mode is also available on a high port: 8465 (SSL/TLS), 8587 (STARTTLS) and 8025 (plain). Many hosting providers and clouds block outbound 25, 465 and 587 — if the connection times out, switch to the matching high port.

Configure the realm

Select the realm your users log in to, then open Realm settings → Email:

FieldValue
Fromnoreply@your-domain.com — on your verified domain
From display nameYour product name
Reply toOptional, e.g. support@your-domain.com
Hostsmtp.postwing.app
Port587
EncryptionEnable StartTLS on, Enable SSL off
AuthenticationOn
UsernameThe login of an SMTP token for your domain
Authentication Typepassword (shown in recent versions)
PasswordThat token's password
⚠
Enable StartTLS goes with port 587; Enable SSL goes with port 465. Turning both on, or SSL on 587, fails the TLS handshake.

Turn on the email flows

SMTP alone sends nothing. Open Realm settings → Login and enable the flows that use it:

  • Forgot password — shows the "Forgot Password?" link on the login page.
  • Verify email — requires new users to confirm their address.

Configure it from the command line

The same settings live in the realm's smtpServer map, so kcadm.sh can set them — handy for scripted or repeated environments:

bash
# Log in to the admin CLI once
kcadm.sh config credentials --server https://sso.your-domain.com \
  --realm master --user admin

# Set the realm's SMTP server — every value is a string
kcadm.sh update realms/myrealm \
  -s 'smtpServer.host="smtp.postwing.app"' \
  -s 'smtpServer.port="587"' \
  -s 'smtpServer.starttls="true"' \
  -s 'smtpServer.ssl="false"' \
  -s 'smtpServer.auth="true"' \
  -s 'smtpServer.user="token-login@your-domain.com"' \
  -s 'smtpServer.password="your-token-password"' \
  -s 'smtpServer.from="noreply@your-domain.com"' \
  -s 'smtpServer.fromDisplayName="Acme"'

Send a test email

Press Test connection at the bottom of the Email tab. Keycloak sends a message to the email address of the admin you are logged in as, so give that account an address first. On failure it shows the server's error in a banner.

Troubleshooting

ErrorCause and fix
Test connection is disabledYour admin user has no email address.
Couldn't connect to host / timeout Outbound port blocked — use 8587 with StartTLS or 8465 with SSL.
SSL handshake errorEnable SSL switched on for port 587. Use StartTLS instead.
535 Authentication failedWrong token login or password, or Authentication left off.
Test works, users get no reset email Forgot password is off on the Login tab, or you configured a different realm.
Mail goes to spamFrom is not on your verified domain.

Frequently asked questions

Where are the SMTP settings in Keycloak?

In the admin console, pick the realm, then Realm settings → Email tab. Email is configured per realm: the master realm's settings do not apply to the realm your users log in to, so set up each realm that sends mail.

Should I enable SSL or StartTLS in Keycloak?

For port 587 turn on Enable StartTLS and leave Enable SSL off. For port 465 do the opposite: Enable SSL on, StartTLS off. Enabling SSL on port 587 is the most common reason the connection test fails with a handshake error.

Why is the Test connection button disabled?

The test email goes to the admin user you are logged in as, so that user needs an email address. Keycloak says so above the button; add an address to your admin account in the master realm and try again.

Why does Keycloak not send the verification or password reset email?

Configuring SMTP does not switch those flows on. Go to Realm settings → Login tab and enable Verify email and Forgot password. Without them Keycloak never generates those messages, however the Email tab is set up.

Can I keep the SMTP password out of the Keycloak database?

Yes. The Password field accepts a vault reference such as ${vault.smtp_password} when a vault provider is configured, and Keycloak reads the secret from the vault at send time instead of storing it in the realm.

Why do Keycloak emails go to spam?

Check the From field on the Email tab. It must be an address on the domain you verified, or DKIM and SPF do not align with it. Put a support address in Reply to if users should be able to answer.

Next steps