Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To test an application’s verification email in GitHub Actions without stubbing the mailer, run the app inside the workflow, let it send its real verification message to a mail catcher or an isolated test inbox, poll until the matching message arrives, extract the link or code, complete verification, and assert the resulting account state. A local catcher such as Mailpit or MailDev shows what your application generated and sent to that catcher. It does not prove that the message went out through your production email provider, so keep those two boundaries separate in your test design.
First, confirm which verification email you mean
This guide covers an application’s own signup or account-verification message, the email your product sends to a new user. It does not cover verifying your GitHub account email address. That is a separate flow. GitHub’s reference on email addresses says disposable email addresses cannot be verified, and it lists creating or using GitHub Actions among the actions restricted when an address is unverified (GitHub email-address reference).
The core workflow
The pattern is the same whichever mail tool you use. The steps below assume the application runs in the same job as the test, with the mail catcher started as a service container or as a process the job controls.
Free tools Windows power users keep installed
One-click scans. No signup required.
- Decide the test boundary. Decide whether the test must check the generated content and the verification behavior, or whether it must also check the outbound provider and external delivery. The answer determines which tool fits (see the comparison table below).
- Start the mail target. For a local catcher, start Mailpit or MailDev as an Actions service container so the test can reach its SMTP port and its HTTP API. For external delivery, provision an isolated hosted inbox and store its credentials as described later in this guide.
- Point the application’s mail transport at that target. In the public GitHub Actions example that sends through Mailpit, the application’s SMTP host and port are
localhostand1025, and captured mail is read through the HTTP API on port8025. Your project’s network and service-container settings may differ, so check the values against your own workflow. - Clear or isolate the mailbox, then trigger the flow. Start from an empty inbox, or from a fresh inbox that belongs only to this run, and then sign up or request a new verification email through the application.
- Poll for the expected message. Filter by recipient and by subject or other expected details, and keep polling until a deadline. Delivery is asynchronous, so a single immediate read can miss the message.
- Assert, extract, and complete. Assert the subject, recipient, and expected body content. Extract the verification link or code, follow it or submit the code, and then assert the verified state of the account in the application.
MailDev’s CI guide describes the same sequence: start the server, clear the inbox, trigger the action, poll its REST API, and assert on message fields or an extracted link. The guide notes that SMTP delivery is asynchronous, so the request that triggered the email usually returns before MailDev has received it (MailDev CI guide).
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Choose the right test boundary
| Approach | What it validates | Main trade-off |
|---|---|---|
| Local SMTP capture (Mailpit or MailDev) | The application’s send path to the configured catcher, the generated message, and the link or code handling | The message stays local. It does not prove external provider delivery or inbox placement. |
| Hosted disposable inbox API | A message received by an externally hosted inbox, which the vendor’s API can expose as a code or link | Adds an external service, plus credentials, a network dependency, and the vendor’s quotas and retention rules. |
| Shared real mailbox | Receipt in a mailbox the test can read | Shared state, stale messages, and collisions between parallel runs. Credential handling needs extra care. |
| Mocked mailer | Application behavior around a mocked send call | Does not test real inbox receipt. Useful only when rendering or internal logic is the target. |
Mailpit provides an SMTP server, a web interface, a REST API for integration tests, Docker images, and message inspection (Mailpit project). MailDev provides SMTP and an HTTP API for assertions (MailDev CI guide). A hosted-inbox vendor’s guide describes fresh inboxes per run and waiting for codes or links (MailSink guide). That guide’s plan limits and prices are vendor statements that change over time, so check the vendor’s current pricing before you rely on them.
Poll with a deadline instead of sleeping
A fixed sleep either wastes time or fails intermittently. Poll the mail target until a matching message appears or a deadline passes. Use a deadline long enough for normal delivery on your runner, and stop as soon as the message arrives. When the deadline passes, the failure message should say which recipient and subject were expected, how many messages were found, and whether any of them matched.
Rank #2
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
- Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
Keep the match narrow. Filter by recipient first, then by subject or a unique token that your test puts into the signup address. A narrow match stops an email from an earlier test run from satisfying the assertion.
Handle secrets and verification tokens carefully
- Hosted inbox keys. Store an API key as an Actions secret and expose it only to the step that needs it. GitHub states that a secret is readable only when a workflow explicitly includes it, and it recommends granting the minimum permissions required (GitHub Actions secrets).
- Redaction limits. Do not rely on secret masking for every transformed value. Avoid printing credentials, and avoid printing verification links or codes in logs.
- Test data only. Use test accounts and a test environment. Never route test messages to real users.
Troubleshoot by stage
A verification test can fail at four different points. Check them in this order so you know which stage broke.
Rank #3
- FIDO2/Passkey Authentication – Secure, passwordless login with supported platforms. Check if your intended service supports hardware keys before purchase. Works with Gmail, Facebook, GitHub, Dropbox, and more.
- Enhanced Multi-Factor Authentication (MFA): Strengthen account security using either FIDO2.0 authentication or TOTP/HOTP codes, providing flexible options for added protection.
- Universal Connectivity: Features USB-A and NFC compatibility, making it easy to use across various devices including PCs, Macs, iPhones, and Android phones for seamless integration.
- Durable & Portable Design: Built with a 360° rotating metal cover for extra durability. Compact and lightweight, it easily attaches to a keychain for on-the-go convenience. No batteries or network required, ensuring dependable use anywhere.
- FIDO Certified & Business-Ready: Certified for FIDO standards and supported by a range of management software suites, ideal for both individual users and enterprise deployment.
- No message captured. Confirm the application’s SMTP host and port match the service container, and confirm the application actually attempted to send. Check the catcher’s own message list before changing the test.
- Wrong message matched. Clear the inbox or use a per-run address, and tighten the recipient and subject filter.
- Extraction fails. The template may have changed. Assert the body content first, then match the link or code pattern against the captured body.
- Verification fails after extraction. Check that the link’s base URL points at the test environment, that the code has not expired, and that the test follows the link in the same environment the app uses.
What a local catcher does not prove
A passing test with Mailpit or MailDev shows that your application generated a correct verification message and that the link or code works. It does not show that your production provider accepted the message, that it reached an inbox, or that spam filters let it through. If those outcomes matter, add a separate test with a hosted inbox, and keep it in a smaller set of runs so it does not become a flaky gate on every commit.
The guidance here reflects official GitHub and project documentation and one vendor guide as of October 2026. Verify release versions, plan details, and hosted-service terms before you build on them.
Quick Recap
Rank #4
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

