Provider
StytchIncident detail
Emails not being delivered
We extend our sincerest apologies for this outage. On 17 August 2026, between 02:15 and 05:15 PT (09:15–12:15 UTC), all outbound email from Stytch failed, including email magic links, email OTPs, and password reset emails. Service was restored at 05:15 PT. What happened: This
Timeline window
to
Outage alerts
Get alerted the next time Stytch breaks
Free email alerts for up to 5 providers. No card, live in about a minute. Paid plans add Slack, Teams, Discord, and webhook delivery across your whole stack, plus higher API quotas.
Timeline
Incident updates
Every update Stytch posted, oldest to newest, exactly as it appeared on their official status page.
Investigating
We are currently investigating this incident.
Monitoring
We've mitigated the issue and emails are now being delivered. Currently monitoring.
Resolved
The incident should be resolved; we have put in mitigations and will continue to monitor. A small percentage of users may see some lingering deliverability issues as we catch up. We apologize for the inconvenience.
Resolved
An email spam attack triggered our automatic provider failover, and we experienced sending difficulties with our secondary provider, causing Stytch emails to be unable to be sent. A fix was put in place to mitigate email spam but we were unable to merge this due to an upstream GitHub incident, resulting in delays in mitigating the issue. We will update this postmortem with additional details as soon as possible with planned near-term mitigations to prevent this from occurring again in the future.
Resolved
We extend our sincerest apologies for this outage. On 17 August 2026, between 02:15 and 05:15 PT (09:15–12:15 UTC), all outbound email from Stytch failed, including email magic links, email OTPs, and password reset emails. Service was restored at 05:15 PT. What happened: This outage was triggered by abuse of free-tier email sending, a pattern we defend against continuously. In this case, our abuse controls did not engage in time, and a large volume of spam was sent before we intervened. That volume exhausted our sending quota with our primary email provider, which normally handles the majority of traffic. Automated failover and alerting fired, and our on-call engineer fully failed over to our secondary email provider within 20 minutes. That failover appeared to succeed: The secondary provider accepted our sends and reported them as successful 200s. However, the secondary provider was not delivering those emails due to the previous spam volume. As a result, we believed email had been restored when it had not. We received customer reports beginning at 03:15 PT and confirmed the true state of email sends at 05:01 PT. We restored service at 05:15 PT, banned the malicious accounts, and implemented new safeguards against the abuse seen. Impact: All email sent during the window failed permanently. Any authentication email a user requested between 02:15 and 05:15 PT never arrived, and users would need to request a new one after 05:15 PT. Ongoing impact on deliverability: The spam volume sent from our infrastructure has affected our sender reputation for `login@stytch.com`. For some time, a higher-than-normal share of legitimate emails may land in recipients' spam folders. We are working with our providers on reputation remediation and expect this to improve over the coming days. No action is required. If your users report missing authentication emails, please ask them to check their spam folder. What we're changing: We have already implemented new
Keep exploring
More from Stytch
Neighboring incidents on Stytch's timeline and the rest of their record on OutageDeck.