Firebase Password Reset from Gmail

Firebase authentication has a useful email/password login option and it’s default behavior includes easy ways to trigger password resets. One annoyance though is that the invoking the password reset will be sent from noreply@(project-id).firebaseapp.com email address. This can easily end up in a customer’s spam folder or blocked by email filters.

Firebase offers two ways to fix this; one by setting up a custom domain and one by integrating with any SMTP server. We’ll focus on the second one for today and specifically hooking it up to Gmail account.

SMTP

The steps are pretty simple:

  1. Toggle enable on
  2. Enter each of the fields (see above for the correct values for Gmail)
  3. Hit save

Some parts to pay closer attention to:

  1. The username should include the full email address with the @host.com extension
  2. The SMTP security mode should be set to STARTTLS and not SSL for Gmail
  3. If this is a GSuite (now called Google Workplaces) account, you’ll have to do a few extra steps
  4. in the Google Admin console, go to Security and ‘Less Secure Apps’, then click the option to ‘Allow users to manage their access to less secure apps’ (see below)

Less Secure Apps

  1. in Gmail, click on your profile to ‘Manage your Google Account’, then head to Security and enable 2-factor authentication
  2. in Gmail, in the same Security tab, there’s also a section for ‘App Passwords’, it’s a good practice to avoid sharing the account password with Firebase, so create a custom one

Gmail Security

If you test now by triggering a password reset for a user on the Firebase authentication tab, you should get a password reset email from that Gmail account! Unfortunately if it doesn’t arrive, then there’s no easy way I’ve found to debug; so carefully check each step.

Bonus Section!

Notice how the email at the top is a noreply@(custom domain) but the email I use as a user is somebodyelse@(custom domain)? Here, we’re using a Google Groups email address and sending emails from our Gmail account under an alias.

To set up the Google Group:

  1. Create your Google Group
  2. For a no-reply group, I ensured that group members do NOT receive any inbound messages
  3. Under ‘Group Settings’, in the ‘Posting policies’ section, ensure that ‘Who can post as group’ is enabled

Google Group Posting Policies

To enable the Gmail account to post on behalf of the group, we’ll just need a few more steps:

  1. Back in your Gmail account, click the settings button in the upper right, then click ‘See All Settings’
  2. Head to the ‘Accounts’ tab and see the ‘Send mail as’ section, then ‘Add another email address’
  3. Go back to the Google Group page and verify that this user should have permission to post

Gmail Accounts

If all goes well, password reset requests will now trigger an email sent from a lovely noreply@host address.

Hooray!


Name:

Comment: