Docs / n8n

Send email in n8n over SMTP or the REST API

n8n can send through Postwing two ways. The Send Email node speaks SMTP and needs nothing but a credential. The HTTP Request node calls the REST API instead, which adds saved templates, safe retries and a message id to track. Both authenticate with the same domain token.

✓
You can get them on the token management page. For security reasons, a token is shown only once — at the moment it is created.

SMTP connection settings

SettingValue
SMTP hostsmtp.postwing.app
Port587
EncryptionSTARTTLS (the connection is upgraded to TLS before login)
UsernameThe login of an SMTP token for your domain
PasswordThe password of that token — shown once, when the token is created
ℹ
Every mode is also available on a high port: 8465 (SSL/TLS), 8587 (STARTTLS) and 8025 (plain). Many hosting providers and clouds block outbound 25, 465 and 587 — if the connection times out, switch to the matching high port.

Create the SMTP credential

Add a Send Email node, open Credential to connect with and create a new SMTP credential:

FieldValue
UserThe login of an SMTP token for your domain
PasswordThat token's password
Hostsmtp.postwing.app
Port587
SSL/TLSOff
Disable STARTTLSOff
Client Host NameLeave empty
⚠
Turn it on only with port 465. On port 587 leave it off: n8n upgrades the connection with STARTTLS by itself, and that upgrade is what protects the password. Turning on Disable STARTTLS as well would send the token's password across the network in clear text.

Configure the Send Email node

ParameterValue
OperationSend
From EmailAcme <noreply@your-domain.com> — on your verified domain
To EmailAn expression such as {{ $json.email }}; several addresses are comma-separated
SubjectText or an expression
Email FormatBoth — an HTML part and a plain-text one
OptionsReply To for replies, and Append n8n Attribution switched off

The From address is what DKIM, SPF and DMARC are checked against. Put a customer's address there — say, from a form submission — and the message is refused; use Reply To for it instead.

Send a test email

Put your own address in To Email and execute the node on its own. A failure shows the SMTP server's reply in the node's output, which tells you whether the port, the encryption or the credentials are wrong.

Or: the HTTP Request node

Configure an HTTP Request node with Method POST, URLhttps://api.postwing.app/external/send_email_simple/, Authentication None, Send Body on, Body Content Type JSON and Specify Body Using JSON. Switch the JSON field to an expression and paste:

JSON
{
  "to": [{{ JSON.stringify($json.email) }}],
  "subject": {{ JSON.stringify($json.subject) }},
  "body": {{ JSON.stringify($json.html) }},
  "sender": "Acme <noreply@your-domain.com>",
  "idempotency_key": {{ JSON.stringify("order-" + $json.orderId) }},
  "auth": {
    "username": "token-login@your-domain.com",
    "password": "your-token-password"
  }
}

JSON.stringify quotes and escapes each value, so HTML full of quotes and line breaks cannot break the body. The token travels in the body because that is how the send API authenticates — n8n's credential store has no slot for it here, so anyone who can edit or export the workflow can read it. The idempotency_key makes a repeated request return the first result instead of sending again. The rest of the fields are in the API reference.

The node also has Import cURL. Pasting this fills in the method, URL, header and body in one go:

bash
curl -X POST https://api.postwing.app/external/send_email_simple/ \
  -H "Content-Type: application/json" \
  -d '{"to": ["you@your-domain.com"], "subject": "Test", "body": "<p>It works.</p>",
       "sender": "Acme <noreply@your-domain.com>",
       "auth": {"username": "token-login@your-domain.com", "password": "your-token-password"}}'

Troubleshooting

ErrorCause and fix
Timeout or Greeting never received SSL/TLS is off with port 465, or the port is blocked on a self-hosted instance — use 8587 or 8465.
wrong version numberSSL/TLS is on with port 587. Turn it off.
535 authentication failedWrong token login or password.
550 from must be equal to …From Email is not on your verified domain.
HTTP 400 Invalid username or passwordWrong token in the HTTP Request body's auth.
HTTP 400 JSON parse error A value was inserted without JSON.stringify, or the field is not in expression mode.
Mail goes to spamA new domain with no sending history yet — see domain reputation.

Frequently asked questions

Should SSL/TLS be on or off in the n8n SMTP credential?

Off for port 587: the connection starts in plain text and is upgraded with STARTTLS, which n8n does on its own unless Disable STARTTLS is on. On for port 465, where TLS starts with the first byte. Getting this backwards is the usual cause of a handshake error or a timeout.

Why does n8n say 'Invalid login: 535 Authentication failed'?

The User or Password in the credential is wrong. The user is the login of an SMTP token for your domain, not your account email, and the password is that token's password — shown once, when the token is created.

Can I put a display name in the From Email field?

Yes. The Send Email node accepts Name <address> in From Email. The address must be on the domain you verified, or the message is refused.

SMTP or HTTP Request — which should I use?

The Send Email node is simpler and keeps the token encrypted in n8n's credential store. The HTTP Request node gets you saved templates, an idempotency key that makes retries safe, and a structured response with the message id every delivery webhook reports.

How do I stop n8n adding its own line to my emails?

In the Send Email node, add the Append n8n Attribution option and switch it off.

How do I retry a failed send?

In the node's Settings, turn on Retry On Fail and set Max Tries and Wait Between Tries. With the HTTP Request node, send an idempotency_key so a retry after a timeout never delivers the message twice.

Next steps