What this covers
PocketBase sends password-reset (and verification) emails through an SMTP server, and it needs to know your app's public URL so the reset link points at the right place. A fresh install has SMTP disabled and its App URL set to localhost, so no mail is ever sent. Enabling password-reset email configures both: a working SMTP sender and your real App URL — so 'forgot password' starts working for your users.
Before you start
Open your PocketBase service in the portal (Services → your app) and use the 'Password-reset email' card. If your app's domain has email hosted with CM Cloud, no details are needed — we provision a mailer mailbox and send from a noreply@ address on your domain. If your email is hosted elsewhere, have your SMTP host, port, username, password, and a From address ready (for example a Gmail app password, or your provider's SMTP).
How to do it
- Go to Services and open your PocketBase app.
- Find the 'Password-reset email' card and click 'Enable password-reset email'.
- If your domain's email is hosted with CM Cloud, you are done — a confirmation appears and your users can reset their passwords by email.
- If your email is hosted elsewhere, a short form appears: enter your SMTP host, port, username, password and From address, then click Save & enable.
- Test it: open your PocketBase login, choose 'forgot password', and confirm the email arrives.
- If your users sign in through your own app rather than PocketBase's page, note where the link goes: PocketBase builds it from its appURL, which is this backend's domain, so the reset finishes on PocketBase's page. To finish it inside your app instead, edit the template under Settings → Mail in /_/ to point at your app's route and submit the token with confirmPasswordReset.
What our team checks
Support can confirm the setting was applied and that a test email is delivered. If a message does not arrive, we check that the From address is allowed to send and that the SMTP credentials are valid.
Next step
Open your PocketBase service page and click 'Enable password-reset email'. If your email is hosted elsewhere, enter your SMTP details when prompted.