Make gives you two ways to send through Postwing: the Email app's Send an Email module over SMTP, or the HTTP app's Make a request module calling the REST API. Both use the same domain token. Start with SMTP; switch to HTTP when you need templates or safe retries.
| Setting | Value |
|---|---|
| SMTP host | smtp.postwing.app |
| Port | 587 |
| Encryption | STARTTLS (the connection is upgraded to TLS before login) |
| Username | The login of an SMTP token for your domain |
| Password | The password of that token — shown once, when the token is created |
Add an Email → Send an Email module to the scenario and click Create a connection. Pick the SMTP connection for other providers — not Google Restricted or Microsoft SMTP/IMAP OAuth — choose Other as the email provider and fill in:
| Field | Value |
|---|---|
| SMTP server | smtp.postwing.app |
| Port | 587 |
| Secure connection (TLS) | On, with explicit TLS — that is STARTTLS |
| User name | The login of an SMTP token for your domain |
| Password | That token's password |
| Default sender, if the form asks | noreply@your-domain.com — on your verified domain |
587. A secure connection without explicit TLS is TLS from the first byte and goes with port 465. Any other combination fails the handshake, and Make refuses to save the connection. Map To, Subject and the content from earlier modules, and set the content type to HTML if you send markup. The From address has to be on your verified domain: that is the domain DKIM signs for and SPF and DMARC are checked against. A customer's address from a form goes in Reply-To, never in From.
Put your own address in To and click Run once. If the module fails, open it in the run's output: the SMTP server's own reply tells you whether the port, the encryption or the credentials are wrong.
Call the send API with the HTTP app:
| Field | Value |
|---|---|
| Authentication type | No authentication — the token goes in the body |
| URL | https://api.postwing.app/external/send_email_simple/ |
| Method | POST |
| Body content type | application/json |
| Body input method | Data structure |
| Parse response | Yes |
| Return error if HTTP request fails | Yes (advanced settings) |
The data structure mirrors this body, with to as an array of text and auth as a collection holding username and password:
{
"to": ["{{1.email}}"],
"subject": "Order {{1.order_id}} confirmed",
"body": "<p>Thanks! Your order ships tomorrow.</p>",
"sender": "Acme <noreply@your-domain.com>",
"idempotency_key": "order-{{1.order_id}}",
"auth": {
"username": "token-login@your-domain.com",
"password": "your-token-password"
}
}Why Data structure and not JSON string: Make escapes values mapped into a data structure, so an HTML body full of quotes and line breaks stays valid JSON. Pasted as a JSON string, the same mapping breaks the request the first time a value contains a quote. idempotency_key makes a repeated request return the first result rather than sending again, which is what makes Make's retries safe. The token's password is part of the module's settings, so anyone who can edit the scenario can read it.
A successful call returns the message id that every delivery webhook reports:
{
"ok": true,
"emails": [
{
"ok": true,
"message_id": "<uuid@your-domain.com>",
"uuid": "uuid",
"recipient": "customer@example.com",
"kind": "to",
"idempotency_key": "order-4417",
"replayed": false
}
]
}| Error | Cause and fix |
|---|---|
| Connection cannot be saved, handshake error | TLS mode does not match the port — explicit TLS for 587, implicit for 465. |
535 authentication failed | Wrong token login or password. |
550 from must be equal to … | The From address is not on your verified domain. |
HTTP 400 Invalid username or password | Wrong token in the request body's auth. |
HTTP 400 Invalid sender, must end with @… | sender is on a different domain than the token. |
HTTP 400 JSON parse error | A mapped value broke the JSON string — use Data structure. |
HTTP 400 Hourly limit exceeded | Your plan's volume. It clears on its own; retry later. |
Yes. The Email app's Send an Email module takes an SMTP connection for providers other than Google and Microsoft. Choose Other as the email provider and enter the server, port and the token's login and password.
587 with STARTTLS, which Make's connection form calls explicit TLS. If you would rather have TLS from the first byte, use 465 with the secure connection on and explicit TLS off. Mixing the two is what makes the connection fail on save.
The From address is what DKIM, SPF and DMARC are checked against, and your records only cover your own domain. The relay refuses a From on any other domain. Put the customer's address in Reply-To.
The Email module is the quickest to set up. The HTTP module calling the REST API gets you saved templates, an idempotency key that makes retries safe, and a response with the message id that every delivery webhook reports.
With the JSON string input method, mapped values are inserted as they are, so a quote or a line break in them breaks the JSON. Use the Data structure input method, which escapes mapped values for you.
In the scenario's run history: open the failed operation and read the module's output. For the HTTP module, turn on Return error if HTTP request fails so a refusal stops the run instead of passing quietly.