/sc-resend — Resend (STUB)
Status: boilerplate only.
Scope when implemented
- Domain verification: register a sending domain with Resend, fetch the DKIM/SPF/DMARC records it requires, then create them via
sc-cforlib/hostinger.jsautomatically — no manual DNS copy-paste. - API key rotation per project, scoped to the verified domain.
- Audience creation for broadcast lists (optional).
- Smoke send to a verified recipient to confirm DNS propagation.
Sender identity policy
Sender identity is project configuration, not repository-global policy. Use one explicitly verified Resend domain/account selected by the user and keep the visible project name separate from the sender address:
From: <Project Name> <transactional@example.com>
Reply-To: <optional monitored mailbox>
Do not infer a sender address from the application hostname. A project hosted at
app.example.com may legitimately send from a different verified domain. Keep the
project-local contract explicit:
EMAIL_FROM_ADDRESS=transactional@example.com
EMAIL_PROJECT_NAME=<Project Name>
EMAIL_PROJECT_TAG=<project-slug>
EMAIL_REPLY_TO=
Framework adapters may map these values into native variables, but the selected project configuration remains the source of truth. Never bake another project's domain, sender, or display name into this skill.
Env vars
| Var | Purpose |
|---|---|
RESEND_API_KEY |
re_... server key |
RESEND_FROM_DOMAIN |
The verified sending domain |
Suggested file layout
sc-resend/
├── SKILL.md
└── scripts/
├── verify-domain.js # register + auto-create DNS records via sc-cf / hostinger
├── api-key.js # create/rotate scoped API key
├── audiences.js # CRUD audience (optional)
└── smoke-send.js # send a test email to confirm
Implementation notes
- API base:
https://api.resend.com - Auth:
Authorization: Bearer <RESEND_API_KEY> - Domain verify response gives 3 records
[{ name, type, value }]— feed those into the DNS module viaconfigureDns(). - DMARC: Resend recommends
v=DMARC1; p=none;initially, tighten top=quarantineonce SPF/DKIM are confirmed in DNS for 24h.