You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Django邮箱确认邮件发送正常但链接失效(Allauth/Anymail/Mailgun/HTTPS)

Hey Sam, I’ve run into this exact issue before with Django Cookiecutter and Allauth—let’s get those verification links switching to HTTPS and working properly. Here’s what you need to check and fix:

1. Update Django’s Security Settings to Recognize HTTPS

Most production setups use a reverse proxy (like Nginx, Caddy, or your hosting provider’s load balancer) that handles SSL termination. That means Django receives HTTP requests internally, so it doesn’t know to generate HTTPS links by default. Add these settings to your settings.py (or use environment variables if your Cookiecutter setup prefers that):

# Tell Django we're behind a proxy that handles SSL
SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https')

# Force all HTTP requests to redirect to HTTPS (optional but recommended)
SECURE_SSL_REDIRECT = True

# Ensure cookies are only sent over HTTPS
SESSION_COOKIE_SECURE = True
CSRF_COOKIE_SECURE = True

Double-check your proxy is actually sending the X-Forwarded-Proto header with value https—if not, adjust your proxy config to add it (for Nginx, that’s something like proxy_set_header X-Forwarded-Proto $scheme;).

2. Configure Allauth to Use HTTPS by Default

Allauth has a specific setting to control the protocol used in account-related emails. Add this to your settings.py:

ACCOUNT_DEFAULT_HTTP_PROTOCOL = "https"

This directly tells Allauth to generate HTTPS links for verification emails, password resets, etc.—no more HTTP links in those messages.

3. Verify Your Cookiecutter Environment Variables

Many Django Cookiecutter templates include environment-specific settings (like in config/settings/production.py). Make sure you haven’t missed any SSL-related env vars that might override your settings. For example, some templates use FORCE_SSL or SSL_ENABLED—ensure those are set to True in your production environment.

4. Test the Fix

After updating settings:

  • Restart your Django application server
  • Create a test user to send a new verification email
  • Check the link in the email—it should now start with https://
  • Click the link to confirm it loads the verification page properly (no more blank tabs!)

If you’re still seeing issues, try running this in a Django shell to debug link generation:

from allauth.account.models import EmailConfirmation
from django.contrib.auth.models import User

user = User.objects.get(username="testuser")
confirmation = EmailConfirmation.objects.filter(user=user).last()
print(confirmation.activate_url)

This will print the exact link Allauth is generating—if it’s still HTTP, go back and double-check the settings above.

内容的提问来源于stack exchange,提问作者Sam Piecz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 08:03:15