© 2026 Hedgehog Software, LLC

TwitterGitHubDiscord
More
CommunitiesDocsAboutTermsPrivacy
Search
Star
Setup for Free
SupabaseS
Supabase•4mo ago•
31 replies
Dove

Self Hosted Password Reset Link Expired (Mimecast)

We’ve built an application that uses a self-hosted Supabase instance, and we’ve run into an issue with the default password-reset email.

Because Supabase sends a single-use link for password resets, our users behind Mimecast are finding that the link has already been consumed by the time they open the email. It appears Mimecast is pre-scanning or “clicking” the link to check it for safety, which triggers the one-time token before the user ever sees it.

Has anyone else experienced this behaviour, or found a good workaround for password resets when using Supabase with Mimecast (e.g. multi-use links, custom reset flow, or alternative verification method)?

Thanks in advance for any advice!
Supabase banner
SupabaseJoin
Supabase gives you the tools, documentation, and community that makes managing databases, authentication, and backend infrastructure a lot less overwhelming.
45,816Members
Resources

Similar Threads

Was this page helpful?
Recent Announcements

Similar Threads

Reset password link expired
SupabaseSSupabase / help-and-questions
3w ago
Self-hosted Reset Password Email template doesn't have the correct link
SupabaseSSupabase / help-and-questions
3y ago
Mimecast modifies password reset links making them invalid
SupabaseSSupabase / help-and-questions
4y ago
Password reset link not received
SupabaseSSupabase / help-and-questions
4y ago