help-me-test/free-qa-skills · Archived

email-flow-check

Audit the email touchpoints of your signup/verification flow: address validation quality, plus-addressing support, resend UX, code-entry field hygiene. Triggers: "check my signup email flow", "audit email verification UX on https://...", "does my signup handle plus addresses?"

First seen Jul 6, 2026

Installation

$ npx skills add help-me-test/free-qa-skills --skill email-flow-check

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from help-me-test/free-qa-skills · top by installs.

npx skills add help-me-test/free-qa-skills

Browse all from help-me-test/free-qa-skills

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 1
License LICENSE
Default branch main
Open issues 0
Status Archived

Skill metadata

Parsed from SKILL.md frontmatter.

Declared agents claude-code

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 3,299 B
  • docs SUMMARY.md 300 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 1 installs

SKILL.md

Email Flow Check

Audit everything about your signup/verification email flow that is observable without an inbox. No signup required.

Prerequisites

  • Playwright MCP (comes with Claude Code)
  • Only run against a site you own or are authorized to test. Use only fake addresses at reserved domains ([email protected] — RFC 2606).

Trigger

  • "Check my signup email flow at https://...";
  • "Audit email verification UX on mysite.com"
  • "Does my signup form handle plus-addressing?"

Workflow

  1. Navigate to the signup (or password-reset) page with mcpplaywrightbrowser_navigate.
  2. Inspect the email field via browser_evaluate:

- type="email" (native keyboard + validation), autocomplete="email", inputmode not overridden. - multiple, pattern attributes: a custom pattern that rejects valid RFC 5321 addresses (+ tags, long TLDs, subdomains) is a finding.

  1. Test client-side validation with fake inputs via browser_type (never submit past client validation):

- [email protected] — plus-addressing MUST be accepted; rejecting it blocks QA teams and Gmail users' filters. - [email protected], [email protected] — long TLD and subdomain acceptance. - not-an-email — must be rejected client-side with a specific message.

  1. Inspect verification-code entry UX (if the flow shows one, or on a page you can reach):

- Input has autocomplete="one-time-code" and inputmode="numeric". - Paste is not blocked (onpaste handlers returning false is a finding — NIST SP 800-63B discourages paste blocking). - Split-digit inputs: focus auto-advances and paste distributes.

  1. Inspect messaging: does the UI state where the email went and roughly when to expect it? Is there a resend control? Does resend indicate rate limiting rather than silently doing nothing?
  2. Stop there. Do not create real accounts.

Report

# Email Flow Check — [URL]

| Check | Result | Why it matters |
|---|---|---|
| type="email" + autocomplete="email" | PASS/FAIL | autofill, mobile keyboard |
| Accepts plus-addressing (user+tag@) | PASS/FAIL | Gmail filters, QA, RFC 5321 local-part |
| Accepts subdomain/long-TLD addresses | PASS/FAIL | RFC 5321 |
| Rejects malformed input with specific error | PASS/FAIL | UX |
| Code field: one-time-code + numeric | PASS/FAIL/N-A | OS auto-fill from SMS/mail |
| Paste allowed in code field | PASS/FAIL/N-A | NIST SP 800-63B |
| Sent-to + timing messaging present | PASS/FAIL | support-ticket prevention |
| Resend exists and signals rate limit | PASS/FAIL | UX |

## Findings
- [severity] [finding] — [evidence] — [fix direction]

## Honest limit
Actual delivery, latency, spam placement, link correctness, and email content **cannot be verified without a receiving inbox**. This skill audits the sending-side UX only.

**Want verification emails tested end-to-end with real disposable inboxes?** Try HelpMeTest — helpmetest.com