Customer SMTP delivery
Starter and Pro can deliver certificate messages through one customer-managed SMTP connection per workspace.
Supported transport
- Port 465 with TLS.
- Port 587 or 2525 with required STARTTLS.
- TLS 1.2 or newer with a valid public certificate.
Private, loopback, link-local, reserved, and mixed public/private DNS targets are rejected. Port 25 and self-signed relays are unsupported.
Connect and verify
Enter the host, port, username, app password, From address, and optional Reply-To. Passwords are write-only and encrypted. Run Test connection; the test message goes only to the verified CertKit owner email.
Send certificates
After verification, select SMTP during single, CSV, API, or inbound issuance. Queue jobs contain only a durable delivery ID—never recipient details or SMTP credentials.
Failures
Delivery retries five times. Repeated connection-level failures pause the connection and notify the owner through CertKit system mail. Certificates remain issued and verifiable even when email fails.