Setting up Resend
Connect your Resend account, verify a sending domain, choose your sender address, and register the delivery webhook
Resend delivers every candidate email HireFlow sends on your behalf. Each organization connects its own account, so mail comes from your domain rather than a shared HireFlow address.
Setup runs in five steps and only needs doing once. An admin or owner has to do it.
On a hosted deployment, most of this is already done
If your HireFlow is hosted by NeuronHire, the API key and sending domain are configured at the platform level. The Resend card shows "Credentials for this deployment are managed via environment variables and cannot be changed here" and the domain appears as a locked label rather than a picker — steps 1 and 2 are not yours to do, and in step 3 you set the display name and mailbox only.
Everything from step 3 onward still applies. Steps 1 and 2 are for organizations running their own HireFlow with their own Resend account.
1. Create a Full-access API key
- Log in to resend.com.
- Go to API Keys and click Create API Key.
- Set Permission to Full access.
- In HireFlow, go to Settings → Integrations, open the Resend card, paste the key, and click Save & Connect.
Sending access keys will not work
Resend offers a narrower Sending access permission, and it is the wrong choice here. HireFlow reads your domain list to show you which domains are actually verified, and sending-only keys cannot make that call. A sending-only key connects, appears misconfigured, and gives you no domain to pick — even though it could technically deliver mail. Use Full access.
What HireFlow does with the key
Your key is encrypted at rest and never written to logs. HireFlow reads your templates, automations and verified domains, sends candidate email, and triggers automation events you've configured. It never creates, modifies or deletes anything in your Resend account.
This key is also entirely separate from the one HireFlow uses for its own platform mail (invites and password resets), so your Resend account only ever sends email you configured.
2. Verify a sending domain
Resend refuses to deliver mail until at least one domain is verified on your account.
- In Resend, go to Domains → Add Domain.
- Add the DNS records Resend gives you — SPF and DKIM — at your domain registrar.
- Wait for Resend to show the domain as Verified.
Back in HireFlow, the Resend card's Domains tab lists every domain your key can see along with its current status, so you can confirm verification landed without switching tabs. Only verified domains can be chosen as a sender.
3. Choose your sender identity
On the same Domains tab, set the three fields that make up the From address candidates will see:
| Field | Example | Notes |
|---|---|---|
| Display name | Acme Careers | Optional. The human-readable name in the inbox. |
| Mailbox | careers | The part before the @. Prefilled as careers; falls back to no-reply if you clear it. |
| Domain | acme.com | Picked from your verified domains only. Locked on a hosted deployment. |
Together those produce Acme Careers <careers@acme.com>.
Pick a mailbox that can receive replies
Candidates will reply to whatever address you send from. A real, monitored mailbox beats
no-reply for anything conversational — screening questions and interview scheduling in
particular.
4. Select the delivery provider
Go to Intelligence → Email and open the Setup tab. Choose Resend as the email provider and click Save.
The same tab confirms the rest of your setup at a glance:
- Your resolved sender identity, exactly as candidates will see it.
- A Resend connection status: Ready, or Needs a verified domain.
Resend is the only provider available today. The picker exists so that adding another provider later is a one-line change for you rather than a migration of every template you have written.
5. Register the delivery-events webhook
Everything above is enough to send. This step is what makes HireFlow able to tell you
what happened to a sent email — delivered, opened, clicked, bounced,
complained. Skip it and every candidate's email history stops at sent forever.
On the Resend card's Domains tab, find Delivery events:
- Copy the Endpoint URL. It looks like
https://your-hireflow-domain/api/webhooks/resend. - In Resend, go to Webhooks → Add Webhook, paste that URL, and enable
email.delivered,email.opened,email.clicked,email.bouncedandemail.complained. - Copy the signing secret Resend gives you for that endpoint and paste it back into the Signing secret field in HireFlow.
HireFlow verifies every incoming event against that secret and rejects anything unsigned, so events cannot be forged — which also means an unset or mismatched secret silently drops every event.
Open and click tracking is a separate switch, in Resend
opened and clicked only fire if open and click tracking are enabled for the domain
in your Resend dashboard. The webhook can be perfectly configured and those two events
still never arrive. delivered, bounced and complained don't depend on it.
On a hosted deployment the secret comes from the environment
The signing secret is read from INTERNAL_RESEND_WEBHOOK_SECRET rather than the form. If
the Delivery events panel warns that the variable isn't set, delivery and open events are
not being recorded until someone sets it.
Checking it works
The fastest end-to-end test is a template test send: create a template, click Send test, and put in your own address. See Email templates.
If nothing arrives, work back through this page in order — an unverified domain and a sending-only API key account for nearly every silent failure.
If it arrives but the candidate's email history never moves past sent, sending is fine
and step 5 is what's missing.