A password-reset email is a delivery step inside an account-recovery flow. The email provider should not decide who owns an account, create the reset token or authorise a password change. Those responsibilities belong to the application that manages the account.
Define the recovery contract
Your application should create a secure, expiring, single-use token and store the state needed to validate it. Use an HTTPS URL on a domain you control. Keep the destination fixed by the application's configuration rather than taking it from an arbitrary client-supplied link.
Avoid revealing whether an account exists through a public reset form. Apply request limits and abuse controls. These decisions need to be implemented in the application; choosing an email API does not add them automatically.
Send only what the reader needs
Use a recognisable sender and a direct subject. Explain the requested action and what to do if the reader did not initiate it. The email should not contain the current password, internal account data or operational secrets.
Provide clear link text and a plain-text version. If the token expires, the application should explain that outcome and offer a way to request a fresh message. Avoid putting marketing content into an urgent recovery flow.
Keep retries tied to the intended message
Persist the intended reset event and email attempt together. A network retry should not create a new token or a new message identity by accident. Reuse the same single-email idempotency key and payload for the same send attempt, and inspect uncertain outcomes before retrying.
Be careful with automated URL fetching in previews or link-checking tools. Following an action-bearing link can have side effects. Design the application so a passive link visit is not sufficient to complete a sensitive account change.
Test the complete journey
Test an expired token, a reused token, an invalid token and a reset for an unauthorised account. Check the email on a small screen and verify that the application explains the result without exposing secrets. Sendar can submit the message and provide email records; only an end-to-end application test can establish that account recovery behaves correctly.