Skip to main content

Mailgun

Mailgun is a sending service you reach with an API key and a sending domain. It works on Node, Docker and Cloudflare Workers. Use this page if you chose EMAIL_PROVIDER=mailgun.

Settings​

VariableDefaultWhat it does
EMAIL_PROVIDERlogSet to mailgun.
EMAIL_FROMnoneThe sender, as Harmony Community Choir <noreply@mg.example.org>. It should be on the domain you gave to Mailgun.
MAILGUN_API_KEYnoneRequired. Your Mailgun API key.
MAILGUN_DOMAINnoneRequired. The sending domain as it is set up in Mailgun, for example mg.example.org.
MAILGUN_REGIONusus or eu. Use eu if your Mailgun domain was created in the EU region. Anything other than a lower-case eu (including EU) is treated as us.

If either required value is missing the server refuses to start with "EMAIL_PROVIDER=mailgun needs MAILGUN_API_KEY and MAILGUN_DOMAIN".

The region decides the address the site talks to: https://api.mailgun.net for us, https://api.eu.mailgun.net for eu. A domain that lives in one region cannot be reached through the other, so a wrong region shows up as a rejection from Mailgun.

Set up Mailgun first​

Add your sending domain in Mailgun, add the DNS records it lists, and wait until it shows as verified.

Working examples​

United States region:

EMAIL_PROVIDER=mailgun
EMAIL_FROM="Harmony Community Choir <noreply@mg.example.org>"
MAILGUN_API_KEY=replace-with-your-key
MAILGUN_DOMAIN=mg.example.org
MAILGUN_REGION=us

EU region:

EMAIL_PROVIDER=mailgun
EMAIL_FROM="Harmony Community Choir <noreply@mg.example.org>"
MAILGUN_API_KEY=replace-with-your-key
MAILGUN_DOMAIN=mg.example.org
MAILGUN_REGION=eu

On Cloudflare, keep the non-secret values under [vars] in wrangler.toml and set the key with wrangler secret put MAILGUN_API_KEY.

If something goes wrong​

When Mailgun refuses a message, the server log has its status and reason, and the message counts as not sent:

Mailgun rejected the email: 401 Unauthorized: Forbidden

A 401 or 403 is usually the wrong key or the wrong region; a 404 can mean the domain is not in that region. See Troubleshooting: nobody can log in, or emails do not arrive.