Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To test email with Playwright without mocks, drive the application’s real email-producing flow, capture the resulting message in an isolated test inbox, and verify the link or code completes the intended user journey. This tutorial uses Mailosaur’s hosted inbox API for the working example; an SMTP sandbox is another documented route.

What a no-mocks email test verifies

A browser test should submit the password-reset or verification form through the application UI. The application then sends a real message through its configured email path, and the test reads that message from a controlled inbox. This checks that the integrated application flow produced the expected email; it does not, by itself, establish that production messages reach every recipient’s inbox or avoid spam filtering.

Use a dedicated test inbox rather than a personal mailbox or a real customer address. A hosted inbox/API captures messages for retrieval, while an SMTP sandbox lets the application route mail to a test SMTP destination. The examples below use Mailosaur’s Node.js client for retrieval.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set up a test inbox and client

Mailosaur’s quickstart requires an account, API key, and an application configured to send messages into the service. Install the Node.js package with:

npm install mailosaur

Keep the API key out of source control; provide it to local runs through an environment variable and to CI through a secret. Initialize the client and read the server identifier and key from configuration:

import MailosaurClient from "mailosaur";

const mailosaur = new MailosaurClient(process.env.MAILOSAUR_API_KEY);
const serverId = process.env.MAILOSAUR_SERVER_ID;

Use the server identifier for the test inbox you have configured to receive your application’s test mail. The official quickstart also documents npm create mailosaur@latest as a way to generate a configured starter project.

Trigger the email through the application

Use a unique address for the test run so the email can be matched to the current attempt. The exact selectors depend on your application; the sequence is to open the reset form, enter the test address, and submit it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
import { test, expect } from "@playwright/test";
import MailosaurClient from "mailosaur";

const mailosaur = new MailosaurClient(process.env.MAILOSAUR_API_KEY);
const serverId = process.env.MAILOSAUR_SERVER_ID;

test("password reset email completes the reset journey", async ({ page }) => {
  const testAddress = "reset-test@example.test"; // Generate a unique address per run.

  await page.goto("/forgot-password");
  await page.getByLabel("Email address").fill(testAddress);
  await page.getByRole("button", { name: "Send reset link" }).click();

  const email = await mailosaur.messages.get(serverId, {
    sentTo: testAddress,
  });

  expect(email.subject).toContain("Password reset");
  expect(email.from[0].email).toBe("noreply@example.test");
  expect(email.to[0].email).toBe(testAddress);
  expect(email.text.body).toContain("Reset your password");
});

This is an illustrative pattern adapted from the documented API, not an executed test. Replace the route, selectors, sender, subject, and template text with values from your application. Mailosaur’s Node.js guide documents messages.get() as waiting for the first message that matches the criteria; its default wait is 10 seconds and can be changed with the timeout option.

Match the right message

Recipient matching is a useful minimum, but a robust test should narrow the search to the current journey. Where supported by the message content and your setup, also match a distinctive subject or body criterion. Do not simply select the most recent message: a stale message from an earlier run could otherwise satisfy the test.

Mailosaur’s Playwright guidance says searches default to messages received in the previous hour. Use the receivedAfter option when the test needs a different time range. If retrieval times out, check that the message arrived in the test inbox, the recipient criterion is exact, and the search range includes its arrival.

Assert the email, then finish the user journey

Check the fields that matter to the user and the flow: sender, recipient, subject, and plain-text or HTML content. For a reset or verification test, go beyond confirming that a message exists. Extract the intended link or code from the message, use it in the browser, and assert the resulting application state.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Retrieve and validate the message. Confirm the expected sender and recipient, then check the subject and relevant content.
  2. Use the email action. Extract the reset or verification URL (or code) from the received content. Follow the link in the browser, or submit the code in the appropriate form.
  3. Assert the outcome. For a reset, set the new password and verify the application accepts it; for verification, assert the account becomes verified. Choose an application-state assertion that demonstrates the action succeeded, rather than relying only on a URL fragment.

SMTP.dev’s password-reset walkthrough shows the same end-to-end shape with an SMTP sandbox: retrieve the message, follow its link, set a password, and check the resulting sign-in URL. The exact final assertion depends on the application under test.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose between a hosted inbox and an SMTP sandbox

Approach How the application routes mail How the test retrieves it Best fit
Hosted inbox/API (Mailosaur example) Configure the application to send test messages into the service’s inbox. Use the official Node.js client and message search criteria. Projects that want an inbox and API-based retrieval.
SMTP sandbox (SMTP.dev example) Point the application’s SMTP transport at the sandbox, or use a domain whose MX points to it. Use the service’s documented message-retrieval method. Projects whose mail path is configured around SMTP and that want to capture its output in a sandbox.

Both approaches let a test exercise the application’s email-producing path without sending to customers. Neither inbox capture alone proves production deliverability or spam placement.

Keep parallel workers isolated

Parallel tests can produce messages close together, so isolate each worker’s recipient and query by recipient plus subject or another distinguishing criterion. SMTP.dev’s example recommends one address per worker and matching by recipient and subject rather than arrival order. Apply the same principle with a hosted inbox: generate unique addresses or use another isolation scheme supported by the provider, and make each query specific enough that another worker’s or an earlier run’s message cannot match.

Troubleshoot a missing message or timeout

  • No matching email: Check the provider dashboard to see whether the message arrived, then confirm the submitted recipient exactly matches the search criterion.
  • Message is outside the search range: Mailosaur’s Playwright guidance uses a default one-hour received-message window; adjust receivedAfter if the test legitimately needs a wider or different range.
  • Retrieval times out: Mailosaur’s Node.js client waits 10 seconds by default. Configure timeout if your environment needs a longer wait, and verify the message is actually being routed to the test inbox.
  • Works locally but not in CI: Confirm the API key, server identifier, and application email/SMTP configuration are present in the CI environment.
  • Wrong email passes the test: Tighten matching with a unique recipient and distinctive subject or body criteria; avoid selecting by arrival order.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.