OAuth Sending

Send from your own inbox. No passwords stored.

Connect Google Workspace and Microsoft 365 directly via OAuth. Tokens are encrypted at rest with AES-256-GCM. Sending goes through Gmail API and Microsoft Graph — your infrastructure, your deliverability.

See it in action

Add sending identity
Connect a new mailbox to this workspace.
Google Workspace
Connect Gmail or Google Workspace with OAuth.
Microsoft 365 / Outlook
Connect Outlook or Microsoft 365 with OAuth.
SMTP / Manual
Connect using SMTP credentials and optional IMAP reply sync.
[email protected]AES-256-GCM

How it works

01

OAuth — no passwords

Google and Microsoft accounts connect via the standard OAuth 2.0 flow. No SMTP passwords are requested or stored. The OAuth access token is encrypted at rest using AES-256-GCM before being written to the database. The encryption key is stored separately from the token — a compromised database record alone is not sufficient to access your inbox.

1. Authorise
2. Token received
3. AES-256-GCM encrypted
4. Stored in DB
02

Sends via Gmail API and Microsoft Graph

ForgeSend dispatches email via the Gmail API for Google accounts and Microsoft Graph for Microsoft 365 accounts. Both APIs route through Google's and Microsoft's own delivery infrastructure — not a third-party relay. Your sending reputation is tied to your own domain, not a shared IP pool. Unsubscribes and bounces are handled natively.

Send job
GO
Delivered
no third-party relay
03

SMTP fully supported

For any inbox connected via SMTP instead of OAuth — Outlook/M365, Zoho Mail, cPanel/Fasthosts, or any other custom host — ForgeSend supports full SMTP configuration with an optional IMAP toggle for reply sync. Auto-fill presets for common providers, plus an Other/Custom option for anything else. Test connection before saving. App password support for providers that require it. SMTP inboxes join the rotation pool immediately on connection.

O
Z
C
+
SMTP auto-fill presets
04

Private Deployment credential sovereignty

With Private Deployment, inbox credentials never leave infrastructure you control. OAuth tokens and SMTP app passwords are encrypted and stored in your own database. No third party — including ForgeSend — has access to your credentials. This is not possible with any other cold email platform.

Your infrastructureYour DB (tokens)Gmail API
no ForgeSend server in chain
05

Every inbox at a glance

Connected inboxes show as a card grid, not a plain list. Each card shows the address, provider, connection status, a health chip, and a daily-send progress bar. Click a card to open its detail slide-over — Domain authentication (SPF/DKIM/DMARC), Placement & reputation (30-day inbox placement rate), Sending limits, Signature, Connection settings, and Token status, with disconnect always available at the bottom.

92 · Healthy31/50 sent today
Click card → Domain auth · Placement · Sending · Signature · Token
0
Bit AES-GCM encryption on all stored tokens
0
Inbox types supported — Gmail, Outlook, SMTP
0
Passwords stored in plaintext

Common questions

Does ForgeSend store my Google or Microsoft password?

No. OAuth means you authorise ForgeSend to access your inbox without sharing your password. Only an encrypted access token is stored.

What encryption is used for stored tokens?

AES-256-GCM. The encryption key is stored separately from the encrypted token in the database.

Does OAuth work with Private Deployment?

Yes. You configure your own Google OAuth app and Microsoft Azure app. Tokens are stored encrypted in your own database.

What SMTP providers are supported?

Any SMTP provider. ForgeSend includes auto-fill presets for Outlook/M365, Zoho Mail, and cPanel/Fasthosts, plus an Other/Custom option with an optional IMAP toggle for reply sync. Personal Gmail and Yahoo addresses aren't offered as SMTP presets — connect Google Workspace directly via the OAuth card instead.

Your inbox. Your credentials. Your rules.

Connect Gmail, Outlook, or SMTP — tokens encrypted, infrastructure yours.