# Transactional Email Review

Verify the accuracy, security, trigger, timing, context, required action, privacy exposure, support, and failure behavior of a transactional message.

## Usage note

Generate the email only from a verified event and show the minimum sensitive detail needed. Never ask recipients to send passwords, codes, recovery secrets, or payment credentials by reply.

## How to use this template

1. Define the exact event, recipient, message state, timing, retry, and deduplication contract.
2. Draft minimum necessary context, required action, expiry, consequence, and safe support.
3. Review sensitive detail, authentication, links, spoofing risk, privacy, and localization.
4. Test real event states, variables, delay, duplicate, expiry, bounce, and completed action.
5. Approve a versioned event-template pair and monitor delivery, security, and user confusion.

## Blank template

### Event contract

- **Email ID and event:** [Enter]
- **Trigger source and version:** [Enter]
- **State:** [Requested / Pending / Complete / Failed / Alert]
- **Recipient selection:** [Enter]
- **Send delay and timezone:** [Enter]
- **Retry and deduplication:** [Enter]
- **Cancel/suppress condition:** [Enter]
- **Product and engineering owners:** [Enter]

### Message content

- **Sender name and address:** [Enter]
- **Subject and preview:** [Draft]
- **What happened:** [State precisely]
- **Account/object context:** [Minimum necessary]
- **Action required and deadline:** [Enter or None]
- **If no action:** [Consequence]
- **If recipient did not initiate:** [Safe route]
- **Support and reference:** [Enter]

### Security and privacy

- **Authenticated destination:** [Enter]
- **Link expiry/one-time behavior:** [Enter]
- **Sensitive variables omitted:** [List]
- **Shared-screen/inbox concern:** [Enter]
- **Reply handling:** [Enter]
- **Information support must never request:** [List]
- **Security/privacy reviewers:** [Names/date]
- **Sender authentication owner:** [Enter]

### QA and monitoring

- [ ] Variable, fallback, amount, date, currency, and timezone were tested.
- [ ] Delayed, duplicate, bounced, expired, revoked, and completed states were tested.
- [ ] Email and in-product state agree.
- [ ] Mobile, plain text, localization, dark mode, and accessibility were checked.
- [ ] Links and support references use official current destinations.
- **Approved template/event version:** [Enter]
- **Monitoring:** [Delivery/repeat/security/support/completion]
- **Update trigger:** [Event, policy, risk, product]
