Skip to content

Documentation

Email through your own Resend account

If you already send with Resend, Kicklace can use that account rather than asking you to set it all up again. Paste a key, choose a domain you have already verified there — no DNS step, because you did it — and every email leaves on your own domain, reputation and quota, with Kicklace's own key as the fallback. Your audiences can come in as people, and joining a list is a separate question with its own consent.

If you already send email with Resend, Kicklace can use that account rather than asking you to set everything up a second time. You paste an API key, choose one of the domains you have already verified there, and from then on every email Kicklace sends for that workspace goes out through your account: your domain, your reputation, your quota, your logs.

Kicklace's own key stays as the fallback for the day yours is revoked, so a bad key never means silence.

Settings → IntegrationsEmail through your own Resend account is the whole of it.

What it buys you

  • Your domain as the sender, with no DNS step. You verified it at Resend; there is nothing to add and nothing to check.
  • Your account's own sending limits and reputation. The mail leaves from where the rest of your mail leaves from, and it is in your Resend logs beside it.
  • Your audiences as people. The contacts of an audience can come in, with the unsubscribed ones recorded as having left. Whether they join a list is a separate question, below.

1. The key

Make a key at resend.com/api-keys with full access — a sending-only key cannot list your domains, which is how Kicklace checks the key works — and paste it into the form.

Kicklace reads your domains once, to prove the key. If Resend refuses it, nothing is stored: a typo never leaves a workspace connected to an account it cannot reach.

The key is encrypted the moment it is saved and is never shown again. The screen says when it was added and offers a Replace; a second key replaces the first and keeps the webhook address, so rotating a key does not mean going back into Resend to make the webhook again.

The key is typed into a form and nowhere else. It is never an argument to a tool, never in a message, and never in anything the AI sees or writes.

2. The domain to send from

The frame lists the domains that account has verified. Choose one and it becomes the workspace's sending domain immediately, marked Verified at your Resend account.

Settings → Sending then shows that domain with no records table and no Check DNS button. There is nothing there to check: the DNS is your account's business, and Kicklace only reads it.

  • A domain Resend has not verified is refused by name, because sending from one would be turned away and a screen that said it was set up would be lying about where the email went.
  • Remove stops Kicklace sending from it and touches nothing at Resend. Kicklace never deletes a domain you set up yourself.
  • Kicklace never asks Resend to verify one of your domains, either. It reads your account; it does not write to it.

3. The webhook, so you know what landed

These emails leave your account, so what happens to them afterwards is something only your account knows. Kicklace gives the workspace an address of its own — one per workspace, because Resend signs each webhook with its own secret — and you add it in Resend under Webhooks → Add endpoint.

Tick these:

Event What it does in Kicklace
email.delivered The send is marked delivered.
email.opened The first open is recorded.
email.clicked A link was followed.
email.bounced A hard bounce takes the person off every list here, their record says why, and the people who run the workspace are told.
email.complained Marked as spam: the same.
email.received Somebody wrote back. Only needed if you take replies.

Then paste the webhook's signing secret (Resend shows it on the webhook's own page, once the webhook exists). Until it is in, nothing is taken: an unsigned or badly signed post is refused.

Until your account is posting, Settings → Sending says so under How it is landing — a dead address stays on your lists, and nothing can say whether an email arrived.

Replies, and a support inbox

Both keep working. A reply subdomain (see Filing the emails you send and receive) or an inbox on your own domain (see A support inbox on your own domain) is registered in your account when the sending domain is one of yours, and the mail that arrives there posts to the same address as everything else — which is why email.received is on the list above.

Bringing an audience in

An audience at Resend is a list of addresses. It is not, by itself, permission to email those people from Kicklace, so bringing one in is two questions rather than one.

The people. Every contact becomes a person here: matched by address if they are already here, created if not, with their name filling a blank one and never overwriting a name somebody typed. The contacts Resend marks unsubscribed come too — leaving them out would mean the next import quietly added them back.

The list. They join a Kicklace list only if you give one, together with the sentence those people agreed to when they joined the audience at Resend — their words, 10 to 500 characters, stored verbatim on every subscription as the proof. Without it they arrive as people on no list, which is still most of the value: they are on their timelines, in your charts, and findable.

A contact Resend says has unsubscribed lands as somebody who has left that list: a row no send ever reads, so a second import cannot put them back on. Somebody already on the list is left exactly as they are — a source that says "unsubscribed" is about that source, and is not consent to take away consent given here.

Nothing is ever sent to any of them by the import.

A big audience takes more than one go: an import stops before the tool's own deadline and says so. Running it again carries on, because everybody already here is matched by their address and writing them a second time changes nothing.

When the key stops working

If Resend refuses your key on the way out — usually because it was revoked — Kicklace sends that email again straight away through its own key, from the shared Kicklace address with your name in front. The people who run the workspace are told once, not once per email, and Settings → Integrations says what Resend answered. The next send that goes through a working key clears it.

What Kicklace does with your account

It reads your domains, reads your audiences and the contacts in one, and sends email. It registers a reply subdomain there if you ask for one. That is all.

It never deletes a domain, never asks Resend to verify one, never creates or changes an audience, never touches a contact over there, and never reads a message that is not addressed to a workspace that takes mail.

Disconnecting

Disconnect stops Kicklace using the account. Nothing at Resend changes: the key stays valid, the domains stay verified, the audiences stay where they are. The workspace goes back to sending from the shared Kicklace address with its name in front until a domain is set up here again, and everything already on a record stays where it is.

Through Claude, or Ask Kicklace

Three tools read and use the account, and none of them ever takes or prints the key:

  • describe_resend — the domains and the audiences with their counts.
  • use_resend_domain — one of the verified domains becomes the sender.
  • import_audience — an audience comes in, on a list only with consent passed verbatim.

Asked for the key, they name the form instead. See Use Kicklace from Claude.