Auth0 Breached Password Emails Not Received From Custom Email Provider

Overview

The Auth0 Breached Password Detection feature triggers two distinct email notification flows that route through different delivery systems. User-facing emails route through the configured custom email provider, while administrative notifications route through the Auth0 system servers. Administrators must verify sender safelisting and check spam folders to ensure delivery of administrative alerts.

Applies To

  • Auth0
  • Breached Password Detection
  • Custom Email Providers
  • Admin Notifications
  • User Notifications

Cause

The Breached Password Detection feature can trigger two distinct email notification flows, which route through different delivery systems:

  • Notifications to Affected Users: These are user-facing emails configured under the Send notifications to users with compromised credentials setting. These emails are successfully routed and delivered via the configured custom email provider, such as SendGrid or AWS SES.
  • Notifications to Tenant Administrators: These are platform-level administrative alerts. These security alerts are sent directly by Auth0's system servers, typically originating from the address no-reply@auth0user.net.

Because Auth0 delivers administrative notifications via standard system servers rather than the configured custom email provider, they will not appear in the custom provider's outboxes or activity logs. Additionally, they may occasionally be filtered by some corporate firewalls or spam filters that do not have auth0user.net safelisted.

Solution

How are missing administrative alerts resolved?

If tenant administrators do not receive these alerts, perform the following troubleshooting steps to ensure delivery.

  1. Verify Sender Safelisting: Ensure the internal mail server or email client does not block, spam-filter, or rate-limit emails from no-reply@auth0user.net.
  2. Check Spam/Junk Folders: Check the spam or quarantine folder for emails sent from the auth0user.net domain.

NOTE: To request the capability to route administrative security alerts through custom email providers in a future Auth0 release, submit a feature request following the steps mentioned in the How to Submit Product Feedback or Feature Requests documentation.

Recommended content

No recommended content found...