Envoi de messages électroniques¶
Django provides wrappers for Python’s email and smtplib modules
to simplify composing and sending email. Django’s email framework also supports
swapping in different delivery mechanisms: you can direct email to the console
or a file during development and an SMTP server or email service provider in
production.
Le code se trouve dans le module django.core.mail.
Exemples rapides¶
Utilisez send_mail() pour l’envoi direct de courriels. Par exemple, pour envoyer un message en texte brut :
from django.core.mail import send_mail
send_mail(
"Subject here",
"Here is the message.",
"from@example.com",
["to@example.com"],
)
When additional email sending functionality is needed, use the
EmailMessage or EmailMultiAlternatives
class. For example, to send a multipart email that includes both HTML and plain
text versions with a specific template and custom headers, you can use the
following approach:
from django.core.mail import EmailMultiAlternatives
from django.template.loader import render_to_string
# First, render the plain text content.
text_content = render_to_string(
"templates/emails/my_email.txt",
context={"my_variable": 42},
)
# Secondly, render the HTML content.
html_content = render_to_string(
"templates/emails/my_email.html",
context={"my_variable": 42},
)
# Then, create a multipart email instance.
msg = EmailMultiAlternatives(
subject="Subject here",
body=text_content,
from_email="from@example.com",
to=["to@example.com"],
headers={"List-Unsubscribe": "<mailto:unsub@example.com>"},
)
# Lastly, attach the HTML content to the email instance and send.
msg.attach_alternative(html_content, "text/html")
msg.send()
Configuring email¶
New Django projects are not configured to send email by default. Instead, email
is printed to the console as a development aid (for projects created with
startproject) or results in a MailerDoesNotExist error (when the
MAILERS setting isn’t defined).
Use the MAILERS setting to tell Django how to send email. For
example, to send through an SMTP server running on the local machine:
MAILERS = {
"default": {
"BACKEND": "django.core.mail.backends.smtp.EmailBackend",
"OPTIONS": {
"host": "localhost",
},
},
}
Django abstracts the email sending process into an « email backend » class. Moteurs de messagerie lists the email backends that come with Django.
The example above uses Django’s SMTP email backend, which sends using the standard SMTP protocol. This backend is useful for many production configurations, including SMTP servers in your own infrastructure and most commercial email service providers (ESPs). There are also third-party email backends available that integrate directly with ESP APIs or add other sending features.
During development or testing you often don’t want to send email at all.
Django’s test runner automatically overrides the
MAILERS configuration to substitute Django’s memory email
backend. This prevents test cases from sending
real email and gives them access to the messages that would have been sent.
Configuration de la messagerie pour le développement discusses some other
approaches.
In earlier releases, Django defaulted to sending email through an SMTP
server running on localhost, using the now-deprecated
EMAIL_BACKEND and related settings.
Obsolète depuis la version 6.1: Until Django 7.0, if the MAILERS setting is not defined then the
earlier behavior still applies: Django will default to using an SMTP server
on localhost (but will issue deprecation warnings). Starting in Django 7.0,
attempts to send email without MAILERS defined will result in a
MailerDoesNotExist error.
Existing projects can opt into the new behavior early by adding
MAILERS to settings.py. See Migrating email to mailers.
Multiple mailers¶
Sometimes different types of email need to be sent in different ways: e.g., internal vs. external email, different SMTP servers for users in different regions, using different services for transactional notifications and bulk marketing email, etc.
The MAILERS setting can define multiple mail configurations. For
example:
import os
MAILERS = {
"default": {
"BACKEND": "django.core.mail.backends.smtp.EmailBackend",
"OPTIONS": {
"host": "smtp.example.net",
"use_tls": True,
"username": os.environ["EMAIL_ACCOUNT_ID"],
"password": os.environ["EMAIL_API_KEY"],
},
},
"notifications": {
"BACKEND": "example.third.party.EmailBackend",
"OPTIONS": {
"api_key": os.environ["THIRD_PARTY_API_KEY"],
"region": "eu",
},
},
"admin": {
"BACKEND": "django.core.mail.backends.smtp.EmailBackend",
"OPTIONS": {
"host": "localhost",
},
},
}
This defines three mailer configurations:
"default"sends through an SMTP server atsmtp.example.netwith a TLS secured connection. It reads an account id and API key from environment variables and uses them as the SMTP authentication username and password. (Many SMTP services use some variation of this authentication scheme.)"notifications"sends through a hypothetical commercial email service, using a third-party EmailBackend that connects directly to their API. (See Moteurs de tierce partie for pointers on locating real, community maintained email backend packages.)"admin"sends through an SMTP server running onlocalhost, with no other options required.
With this configuration, you can provide the using argument to Django’s
email sending functions to specify a particular
mailer configuration:
from django.core.mail import send_mail
send_mail(
"Account activated",
"Congratulations, you're all ready to use our Django app!",
"from@example.com",
["user@example.com"],
using="notifications",
)
If using is not specified, Django uses the mailer defined for the
"default" configuration.
With reusable apps or Django features that send email for you, there may be an
option to use a specific mailer configuration. For example, Django’s logging
AdminEmailHandler allows specifying the mailer
configuration in its using option.
Sending messages¶
django.core.mail provides functions for conveniently sending email, as
well as classes for building and sending more complex email messages with
attachments and multiple content types.
Note
Le jeu de caractères des messages envoyés par django.core.mail est défini par la valeur du réglage DEFAULT_CHARSET.
send_mail()¶
- send_mail(subject, message, from_email, recipient_list, *, fail_silently=False, auth_user=None, auth_password=None, connection=None, html_message=None)[source]¶
django.core.mail.send_mail() sends a single email message.
Les paramètres subject, message, from_email et recipient_list sont obligatoires.
subject: une chaîne de caractères.message: une chaîne de caractères.from_email: une chaîne. SiNone, Django utilise la valeur du réglageDEFAULT_FROM_EMAIL.recipient_list: une liste de chaînes de caractères, chacune étant une adresse électronique. Chaque personne dansrecipient_listverra les autres destinataires dans le champ « To: » du courriel.
Les paramètres suivants sont facultatifs, et s’ils sont indiqués, doivent être des arguments nommés.
fail_silently: A boolean, defaultFalse. If setTrue,send_mail()will suppress some errors during sending. (The exact exceptions ignored depend on the email backend in use.)auth_user: le nom d’utilisateur facultatif utilisé pour s’authentifier auprès du serveur SMTP. Si ce paramètre est absent, c’est la valeur du réglageEMAIL_HOST_USERqui sera utilisée.auth_password: le mot de passe facultatif utilisé pour s’authentifier auprès du serveur SMTP. Si ce paramètre est absent, c’est la valeur du réglageEMAIL_HOST_PASSWORDqui sera utilisée.connection: le moteur de messagerie facultatif utilisé pour envoyer le message. Si ce paramètre est absent, c’est une instance du moteur par défaut qui sera utilisée. Consultez la documentation sur les moteurs de messagerie pour plus de détails.html_message: sihtml_messageest indiqué, le courriel produit sera un courriel multipart/alternative, avecmessagecomme type de contenu text/plain ethtml_messagecomme type de contenu text/html .using: An optionalMAILERSalias to use to send the mail. If unspecified, the default mailer configuration will be used.
fail_silently, auth_user, auth_password, and connection are not
allowed with the using argument.
La valeur renvoyée correspond au nombre de messages livrés avec succès (qui ne peut être que 0 ou 1 puisqu’elle ne peut envoyer qu’un message).
Obsolète depuis la version 6.0: La transmission de fail_silently et des paramètres suivants en tant qu’arguments de position est obsolète.
Obsolète depuis la version 6.1: The fail_silently, auth_user, auth_password, and connection
arguments are deprecated. In most cases they can be replaced by using
with an appropriate MAILERS configuration. See
Replacing fail_silently,
Replacing auth_user and auth_password, and
Replacing get_connection() and connection arguments.
The using argument was added.
Older versions ignored fail_silently=True, auth_user,
and auth_password when a connection was also provided.
This now raises a TypeError.
send_mass_mail()¶
- send_mass_mail(datatuple, *, fail_silently=False, auth_user=None, auth_password=None, connection=None, using=None)[source]¶
django.core.mail.send_mass_mail() est prévu pour envoyer des courriels en masse.
datatuple est un tuple dans lequel chaque élément suit le format suivant :
(subject, message, from_email, recipient_list)
fail_silently, auth_user, auth_password and connection have the
same functions as in send_mail(). They must be given as keyword arguments
if used, and are not allowed with the using argument.
The keyword argument using is an optional MAILERS alias to use
to send the mail. If unspecified, the default mailer configuration will be
used.
Chaque élément de datatuple produit un courriel séparé. Comme dans send_mail(), les destinataires de la même recipient_list verront les autres adresses dans le champ « To: » des courriels.
Par exemple, le code suivant envoie deux messages différents à deux ensembles différents de destinataires ; cependant, une seule connexion est ouverte vers le serveur de messagerie :
message1 = (
"Subject here",
"Here is the message",
"from@example.com",
["first@example.com", "other@example.com"],
)
message2 = (
"Another Subject",
"Here is another message",
"from@example.com",
["second@test.com"],
)
send_mass_mail((message1, message2))
La valeur renvoyée correspond au nombre de messages livrés avec succès.
Obsolète depuis la version 6.0: La transmission de fail_silently et des paramètres suivants en tant qu’arguments de position est obsolète.
Obsolète depuis la version 6.1: The fail_silently, auth_user, auth_password, and connection
arguments are deprecated. In most cases they can be replaced by using
with an appropriate MAILERS configuration. See
Replacing fail_silently,
Replacing auth_user and auth_password, and
Replacing get_connection() and connection arguments.
The using argument was added.
Older versions ignored fail_silently=True, auth_user,
and auth_password when a connection was also provided.
This now raises a TypeError.
send_mass_mail() vs. send_mail()¶
The main difference between send_mass_mail() and repeatedly calling
send_mail() is that send_mail() opens a connection to the mail
server each time it’s executed, while send_mass_mail() uses a single
connection for all of its messages. This makes send_mass_mail() slightly
more efficient.
send_mail() with multiple to addresses sends a single email message,
with john@example.com and jane@example.com both appearing in the « To: »
field:
send_mail(
"Subject",
"Message.",
"from@example.com",
["john@example.com", "jane@example.com"],
)
send_mass_mail() sends a separate message per datatuple element, so
john@example.com and jane@example.com each receive their own email:
datatuple = (
("Subject", "Message.", "from@example.com", ["john@example.com"]),
("Subject", "Message.", "from@example.com", ["jane@example.com"]),
)
send_mass_mail(datatuple)
mail_admins()¶
- mail_admins(subject, message, *, fail_silently=False, connection=None, html_message=None, using=None)[source]¶
django.core.mail.mail_admins() est un raccourci pour envoyer un courriel aux administrateurs du site, tels qu’ils apparaissent dans le réglage ADMINS.
mail_admins() préfixe le sujet avec la valeur du réglage EMAIL_SUBJECT_PREFIX (« [Django] » par défaut).
L’en-tête « From: » du courriel correspond à la valeur du réglage SERVER_EMAIL.
Cette méthode existe par commodité et pour une meilleure lisibilité.
Si html_message est indiqué, le courriel produit sera un courriel multipart/alternative, avec message comme type de contenu text/plain et html_message comme type de contenu text/html .
The keyword argument using is an optional MAILERS alias to use
to send the mail. If unspecified, the default mailer configuration will be
used.
Obsolète depuis la version 6.0: La transmission de fail_silently et des paramètres suivants en tant qu’arguments de position est obsolète.
Obsolète depuis la version 6.1: The fail_silently and connection arguments are deprecated. In most
cases they can be replaced by using with an appropriate
MAILERS configuration. See
Replacing fail_silently and
Replacing get_connection() and connection arguments.
The using argument was added.
Older versions ignored fail_silently=True when a connection
was also provided. This now raises a TypeError.
mail_managers()¶
- mail_managers(subject, message, *, fail_silently=False, connection=None, html_message=None, using=None)[source]¶
django.core.mail.mail_managers() est équivalent à mail_admins(), excepté le fait qu’il envoie un courriel aux gestionnaires du site tels que définis dans le réglage MANAGERS.
The keyword argument using is an optional MAILERS alias to use
to send the mail. If unspecified, the default mailer configuration will be
used.
Obsolète depuis la version 6.0: La transmission de fail_silently et des paramètres suivants en tant qu’arguments de position est obsolète.
Obsolète depuis la version 6.1: The fail_silently and connection arguments are deprecated. In most
cases they can be replaced by using with an appropriate
MAILERS configuration. See
Replacing fail_silently and
Replacing get_connection() and connection arguments.
The using argument was added.
Older versions ignored fail_silently=True when a connection
was also provided. This now raises a TypeError.
La classe EmailMessage¶
Les fonctions send_mail() et send_mass_mail() de Django sont en réalité de légers adaptateurs qui utilisent la classe EmailMessage.
Seule une partie des fonctionnalités de la classe EmailMessage sont exposées par send_mail() et les autres fonctions adaptatrices liées. Si vous voulez utiliser des fonctionnalités avancées, telles que les destinataires en copie cachée, les fichiers joints ou les courriels multi-parties, vous devrez créer directement des instances de EmailMessage.
Note
Cette conception est volontaire. send_mail() et les fonctions liées étaient au départ la seule interface proposée par Django. Cependant, la liste des paramètres acceptés ne cessait de s’accroître avec le temps. Il était donc logique de passer à un concept plus orienté objet pour les courriels et ne conserver les fonctions originales que par rétrocompatibilité.
EmailMessage est responsable de créer le courriel lui-même. Le moteur de messagerie est ensuite responsable d’envoyer le courriel.
Par commodité, EmailMessage propose une méthode send() pour envoyer un courriel unique. Si vous devez envoyer plusieurs messages, l’API du moteur de messagerie offre une alternative.
- class EmailMessage[source]¶
La classe
EmailMessageest initialisée avec les paramètres suivants. Tous les paramètres sont facultatifs et peuvent être définis à tout moment précédant l’appel à la méthodesend().Les quatre premiers paramètres peuvent être transmis en tant qu’arguments positionnels ou nommés, mais ils doivent être transmis dans cet ordre s’ils sont transmis comme paramètres positionnels :
subject: la ligne sujet du courriel.body: le texte du corps. Cela doit être un message texte brut.from_email: The sender’s address. Bothfred@example.comand"Fred" <fred@example.com>forms are supported (see Formatting email addresses). If omitted, theDEFAULT_FROM_EMAILsetting is used.to: une liste ou un tuple d’adresses de destination.
Les paramètres suivants, s’ils sont indiqués, doivent être des arguments nommés :
cc: une liste ou un tuple d’adresses de destination utilisées dans l’en-tête « Cc » lors de l’envoi du courriel.bcc: A list or tuple of addresses used for blind carbon copies when sending the email.reply_to: une liste ou un tuple d’adresses de destination utilisées dans l’en-tête « reply_to » lors de l’envoi du courriel.attachments: une liste de pièces jointes à placer dans le message. Chacune peut être une instance deMIMEPartou deEmailAttachment, ou un tuple avec attributs(nom de fichier, contenu, type mime).Changed in Django 6.0:La prise en charge d’objets
MIMEPartdans la listeattachmentsa été ajoutée.headers: un dictionnaire d’en-têtes à ajouter au message. Les clés sont les noms d’en-têtes, les valeurs sont les valeurs d’en-têtes. C’est à l’appelant de s’assurer que les noms et les valeurs d’en-têtes soient dans un format correct pour les courriels. L’attribut correspondant estextra_headers.connection: An email backend instance. This parameter is ignored when using send_messages().Obsolète depuis la version 6.1: The
connectionargument is deprecated. Instead, define aMAILERSconfiguration with the desired connection options, and then callEmailMessage.send(using="...")with that configuration’s alias. See Migrating email to mailers.
Obsolète depuis la version 6.0: La transmission des paramètres en tant qu’arguments de position est obsolète. à l’exception des quatre premiers.
Par exemple :
from django.core.mail import EmailMessage email = EmailMessage( subject="Hello", body="Body goes here", from_email="from@example.com", to=["to1@example.com", "to2@example.com"], bcc=["bcc@example.com"], reply_to=["another@example.com"], headers={"Message-ID": "foo"}, )
La classe possède les méthodes suivantes :
- send(fail_silently=False, *, using=None)[source]¶
Sends the message. Returns
1if the message was sent successfully, otherwise0. (An empty list of recipients returns0– it will not raise an exception.)The optional
usingkeyword argument specifies aMAILERSalias to use to send the mail. If not given, the default mailer configuration will be used.If a deprecated connection was specified when the email was constructed, that connection will be used. Providing both a connection and
usingwill raise an error.If the deprecated keyword argument
fail_silentlyisTrue, certain backend-dependent exceptions while sending the message will be ignored. Providing bothfail_silentlyandusingwill raise an error.Changed in Django 6.1:The
usingargument was added.Older versions ignored
fail_silently=Truewhen aconnectionwas also provided. This now raises aTypeError.Obsolète depuis la version 6.1: The
fail_silentlyargument is deprecated. See Replacing fail_silently for alternatives.
- message(*, policy=email.policy.default)[source]¶
Construit et renvoie un objet Python
email.message.EmailMessagereprésentant le message à envoyer.The keyword argument
policyallows specifying the set of rules for updating and serializing the representation of the message. It must be anemail.policy.Policyobject. Defaults toemail.policy.default. In certain cases you may want to useSMTP,SMTPUTF8or a custom policy. For example, the SMTP email backend uses theSMTPpolicy to ensure\r\nline endings as required by the SMTP protocol.Si vous aviez un besoin d’étendre un jour la classe
EmailMessagede Django, il est probable que vous surchargiez cette méthode pour placer le contenu souhaité dans l’objet PythonEmailMessage.Changed in Django 6.0:Le paramètre nommé
policya été ajouté et le type renvoyé a été mis à jour pour renvoyer une instance deEmailMessage.
- recipients()[source]¶
Renvoie une liste de tous les destinataires du message, quel que soit le champ où ils se trouvent (
to,ccoubcc). C’est aussi une méthode qu’il peut être utile de surcharger lors de l’écriture d’une sous-classe, car le serveur SMTP doit recevoir la liste complète des destinataires au moment de l’envoi du message. Si vous ajoutez une autre façon d’indiquer les destinataires dans votre classe, ceux-ci doivent aussi être renvoyés par cette méthode.
- attach(filename, content, mimetype)[source]¶
- attach(mimepart)
Crée une nouvelle pièce jointe et l’ajoute au message. Il y a deux façons d’appeler
attach():Il est possible de passer trois paramètres :
filename,contentetmimetype.filenameest le nom de la pièce jointe tel qu’il apparaîtra dans le courriel,contentcontient les données qui formeront la pièce jointe etmimetypeest le type MIME facultatif de la pièce jointe. Si vous omettezmimetype, le type de contenu MIME sera déduit du nom de fichier de la pièce jointe.Par exemple :
message.attach("design.png", img_data, "image/png")
Si vous indiquez message/rfc822 comme
mimetype,contentpeut être une instancedjango.core.mail.EmailMessage, ou une instanceemail.message.EmailMessageouemail.message.Messagede Python.Pour un
mimetypecommençant par text/, le contenu attendu est une chaîne. Les données binaires sont décodées en utilisant UTF-8 et en cas d’échec, le type MIME sera transformé en application/octet-stream et les données seront jointes telles quelles.Ou, pour les pièces jointes demandant des en-têtes ou paramètres supplémentaires, vous pouvez passer à
attach()un seul objet PythonMIMEPart. Il sera directement joint au message résultant. Par exemple, pour joindre une image intégrée avec un Content-ID:import email.utils from email.message import MIMEPart from django.core.mail import EmailMultiAlternatives message = EmailMultiAlternatives(...) image_data_bytes = ... # Load image as bytes # Create a random Content-ID, including angle brackets cid = email.utils.make_msgid() inline_image = email.message.MIMEPart() inline_image.set_content( image_data_bytes, maintype="image", subtype="png", # or "jpeg", etc. depending on the image type disposition="inline", cid=cid, ) message.attach(inline_image) # Refer to Content-ID in HTML without angle brackets message.attach_alternative(f'… <img src="cid:{cid[1:-1]}"> …', "text/html")
La documentation Python de
email.contentmanager.set_content()décrit les arguments pris en charge pourMIMEPart.set_content().Changed in Django 6.0:La prise en charge des pièces jointes
MIMEParta été ajoutée.Obsolète depuis la version 6.0: La prise en charge des pièces jointes
email.mime.base.MIMEBaseest obsolète. Utilisez plutôtMIMEPart.
- attach_file(path, mimetype=None)[source]¶
Crée une nouvelle pièce jointe à partir d’un fichier du système de fichiers. Appelez-la avec le chemin du fichier à joindre et, facultativement, le type MIME à utiliser pour ce fichier. Si vous omettez le type MIME, il sera déduit du nom de fichier. Voici comment l’utiliser :
message.attach_file("/images/weather_map.png")
Pour les types MIME commençant par text/, les données binaires sont traitées comme pour
attach().
- class EmailAttachment¶
Un tuple nommé pour stocker les pièces jointes d’un courriel.
Le tuple nommé possède les index suivants :
filenamecontentmimetype
Envoi d’autres types de contenus¶
Envoi de plusieurs versions de contenus¶
Il peut être utile d’inclure plusieurs versions du contenu d’un courriel. L’exemple classique est d’envoyer à la fois les versions texte et HTML d’un message Avec la bibliothèque de messagerie de Django, cela est rendu possible par la classe EmailMultiAlternatives.
- class EmailMultiAlternatives[source]¶
Une sous-classe de
EmailMessagequi permet des versions supplémentaires du corps du message du courriel via la méthodeattach_alternative(). Cette classe hérite directement de toutes les méthodes deEmailMessage(y compris l’initialisation de la classe).- alternatives¶
Une liste de tuples nommés
EmailAlternative. Ceci est particulièrement utile dans les tests :self.assertEqual(len(msg.alternatives), 1) self.assertEqual(msg.alternatives[0].content, html_content) self.assertEqual(msg.alternatives[0].mimetype, "text/html")
Les alternatives ne devraient être ajoutées que par la méthode
attach_alternative(), ou passées directement dans le constructeur.
- attach_alternative(content, mimetype)[source]¶
Ajoute une représentation alternative du corps du message dans le courriel.
Par exemple, pour envoyer une combinaison de texte et de HTML, vous pourriez écrire :
from django.core.mail import EmailMultiAlternatives subject = "hello" from_email = "from@example.com" to = "to@example.com" text_content = "This is an important message." html_content = "<p>This is an <strong>important</strong> message.</p>" msg = EmailMultiAlternatives(subject, text_content, from_email, [to]) msg.attach_alternative(html_content, "text/html") msg.send()
- body_contains(text)[source]¶
Renvoie une valeur booléenne indiquant si la valeur
textfournie est contenue dans le corpsbodydu courriel ou dans toutes les alternatives liées avec le type MIMEtext/*.Cela peut être utile lors de tests de courriels. Par exemple :
def test_contains_email_content(self): subject = "Hello World" from_email = "from@example.com" to = "to@example.com" msg = EmailMultiAlternatives(subject, "I am content.", from_email, [to]) msg.attach_alternative("<p>I am content.</p>", "text/html") self.assertIs(msg.body_contains("I am content"), True) self.assertIs(msg.body_contains("<p>I am content.</p>"), False)
- class EmailAlternative¶
Un tuple nommé pour stocker les versions alternatives du contenu d’un courriel.
Le tuple nommé possède les index suivants :
contentmimetype
Mise à jour du type de contenu par défaut¶
Par défaut, le type MIME du paramètre body d’un EmailMessage est "text/plain". Il est recommandé de le laisser tel quel, car il garantit que tout destinataire sera capable de lire le courriel, quel que soit son client de messagerie. Cependant, si vous savez que vos destinataires savent gérer un autre type de contenu, vous pouvez utiliser l’attribut content_subtype de la classe EmailMessage pour modifier le type de contenu principal. Le type primaire sera toujours "text", mais vous pouvez modifier le sous-type. Par exemple :
msg = EmailMessage(subject, html_content, from_email, [to])
msg.content_subtype = "html" # Main content is now text/html
msg.send()
Safely sending email¶
Any public website that can send email will eventually be targeted by attempts to abuse it for spam, phishing, or other malicious content. While a complete discussion of vulnerabilities in sending email is beyond the scope of Django’s documentation, there are many references available on the web. Two good starting points are:
Princeton University’s guidance on preventing email abuse in web forms. Although this is an internal reference for users of Princeton’s Drupal Site Builder, nearly all of its advice applies equally to sites built with Django (or any web framework).
OWASP’s Email Validation and Verification in Identity Systems Cheat Sheet. This primarily covers using email in authentication contexts. While many of its recommendations are handled by
django.contrib.authand other Django features, items like rate limiting and securing email change workflows are the developer’s responsibility.
Thinking through how email might be abused (and taking steps to mitigate it) is especially important if your site can send to unverified addresses. Features like newsletter sign-up, contact forms that cc or auto-reply to the sender, and « share this page » can be attractive targets.
Formatting email addresses¶
Email addresses allow a « friendly » display name alongside the user@domain
address. For example, you could include your company name in the
DEFAULT_FROM_EMAIL setting:
DEFAULT_FROM_EMAIL = '"Example, Inc." <contact@example.com>'
The double quotes around "Example, Inc." are needed so the comma isn’t read
as separating two different addresses. A fixed address, written out by hand as
in the example above, is safe, but composing one from variable parts
(especially untrusted input) needs more care.
Avertissement
Never use string formatting to build an email address from variable parts.
For example, f'"{name}" <{email}>' is unsafe.
Email address headers have complex syntax rules (much like HTML or SQL), so
constructing them by combining strings creates an injection vulnerability. Even
if you’ve validated the format of email, an
attacker could exploit the name portion to inject additional addresses.
To avoid this, always use a well-tested library specifically meant to format
email addresses, like Python’s email.headerregistry.Address class (the
replacement for the legacy formataddr() function, which does
not support internationalized domain names).
For example, to include a user’s full name when sending them email (where
user is an instance of the default User model):
from django.core.mail import send_mail
from email.headerregistry import Address
def send_mail_to_user(user, subject, body, from_email=None):
# Safely create an email address with the user's name.
# (addr_spec is the technical term for the user@domain address.)
address = Address(
display_name=user.get_full_name(),
addr_spec=user.email,
)
send_mail(subject, body, from_email, [address])
Django’s built-in email backends support using
Address objects directly in any address field,
as shown here. So do many custom and third-party email backends. But if this
causes a TypeError or other problem with a particular backend, use
str(address) to convert the object to a safe, properly formatted string.
Prévention de l’injection d’en-têtes¶
Email header injection is a security exploit in which an attacker manipulates email headers to change the intended sender or recipients, subject, or potentially even the entire visible message body.
One type of header injection exploits address header syntax. You are responsible for preventing this when constructing email addresses from user-supplied input, as described in Formatting email addresses above.
Another (perhaps better understood) attack, CRLF injection, uses carriage
return and line feed characters to insert additional headers into the email.
Django prevents this by raising a ValueError if those characters appear
in any header field when trying to send the message.
Les versions précédentes généraient django.core.mail.BadHeaderError si certains en-têtes n’étaient pas valides. Il s’agit maintenant d’une erreur ValueError.
Django’s CRLF protection relies on using Python’s modern
EmailPolicy in Django’s EmailMessage.message().
Custom email backends that don’t call that function, or that call it with the
legacy compat32 policy, are responsible for implementing
their own CRLF injection prevention.
Sending many messages efficiently¶
L’établissement et la fermeture d’une connexion SMTP (ou de toute autre connexion réseau, en fait) est un processus coûteux. Si vous avez beaucoup de courriels à envoyer, il est logique de recycler une connexion SMTP plutôt que de créer puis détruire une connexion lors de chaque envoi de message.
There are two ways to tell an email backend to reuse a connection. Both involve
obtaining an email backend instance from mail.mailers and using the
backend’s API.
The first approach is to use the backend’s send_messages() method. This
takes a list of EmailMessage (or subclass) instances, and sends them
all using that single connection.
For example, if you have a function called get_notification_emails() that
returns a list of EmailMessage objects representing some periodic
email you wish to send out, you could send these emails using a single call to
send_messages():
from django.core import mail
email_list = get_notification_emails()
# Use the default mailer. You could substitute
# mail.mailers["alias"] for a specific mailer.
backend = mail.mailers.default
backend.send_messages(email_list)
In this example, the call to send_messages() opens a connection on the
backend, sends the list of messages, and then closes the connection again.
(This is how send_mass_mail() is implemented.)
The second approach is to use the open() and close() methods on the
email backend to manually control the connection. send_messages() will not
open or close the connection if it is already open, so if you
manually open the connection, you can control when it is closed. For example:
from django.core import mail
# Use the "notifications" mailer configuration.
backend = mail.mailers["notifications"]
# Manually open the connection.
backend.open()
# Construct an email message. (Passing None as the third argument
# uses settings.DEFAULT_FROM_EMAIL as the "From:" address.)
email1 = mail.EmailMessage("Hi", "Message", None, ["to1@example.com"])
# Send the email. The connection was already open, so send_messages()
# leaves it open after sending.
backend.send_messages([email1])
# Construct and send two more messages. The connection is still open.
email2 = mail.EmailMessage("Hi", "Message", None, ["to2@example.com"])
email3 = mail.EmailMessage("Hi", "Message", None, ["to3@example.com"])
backend.send_messages([email2, email3])
# Because we opened it, we need to manually close the connection.
backend.close()
When you manually open a backend’s connection, you are responsible for ensuring
it gets closed. The example above actually has a bug: if an exception occurs
while sending the messages, the connection will not be closed. This can be
fixed with a try-finally statement, but using the backend instance as a
context manager is preferable, as it automatically calls open() and
close() as needed.
This is equivalent to the previous example, but uses the backend as a context manager to avoid leaving the connection open on errors:
from django.core import mail
# Use mail.mailers[...] as a context manager.
with mail.mailers["notifications"] as backend:
# The backend connection is automatically opened inside the context.
email1 = mail.EmailMessage("Hi", "Message", None, ["to1@example.com"])
backend.send_messages([email1])
# The connection is still open, and is reused for the second send.
email2 = mail.EmailMessage("Hi", "Message", None, ["to2@example.com"])
email3 = mail.EmailMessage("Hi", "Message", None, ["to3@example.com"])
backend.send_messages([email2, email3])
# After exiting the context (either normally or because of an error),
# the backend connection is automatically closed.
Moteurs de messagerie¶
L’envoi réel d’un courriel est géré par le moteur de messagerie.
Django comes with several email backends. With the exception of the SMTP backend, these are mainly useful during testing and development. If the built-in backends don’t meet your needs there are third-party packages available. You can also subclass one of the built-in backends to change its behavior, or even write your own email backend.
Le moteur SMTP¶
The SMTP email backend connects to an SMTP server to send email. To use it, set
BACKEND to
"django.core.mail.backends.smtp.EmailBackend".
The SMTP backend supports these OPTIONS:
"host"(required): the SMTP server hostname or IP address."port": the port number to connect to on the SMTP host. If omitted, uses the standard port for the connection protocol depending on the"use_tls"and"use_ssl"options:587for TLS,465for SSL, or25for an unsecured connection."username"and"password": set these if your server requires SMTP authentication (« SMTP AUTH » credentials, sometimes called SMTP login).Although the username is often an email address, it should not be confused with default « From: » addresses. Those are defined by the
DEFAULT_FROM_EMAILandSERVER_EMAILsettings."use_tls"or"use_ssl": set one of these options toTrueto connect to the SMTP server using a secure protocol –"use_tls"for explicit TLS or"use_ssl"for SSL (implicit TLS)."ssl_certfile"and"ssl_keyfile": if the SMTP server’s SSL/TLS connection requires client certificate authentication, use these options to specify the paths to a PEM-formatted certificate chain file and private key file. (The key file can be omitted if the certificate file includes the private key.)These options are not intended for use with a private certificate authority or self-signed SMTP server certificate. See Private and self-signed SMTP server certificates below.
Note that these options don’t result in checking certificate validity. They are passed to the underlying SSL connection. Refer to the documentation of Python’s
ssl.SSLContext.wrap_socket()method for details on how the certificate chain file and private key file are handled."timeout": the timeout (in seconds) for connecting to the SMTP server and other blocking operations. If not specified, the value is obtained fromsocket.getdefaulttimeout(), which defaults to no timeout (None) meaning SMTP operations can block indefinitely."fail_silently": set toTrueto ignore certain errors while sending a message. AllOSErrors are ignored while opening the SMTP connection, andsmtplib.SMTPExceptionerrors are ignored while communicating with the server. This will suppress both transient network glitches and also serious configuration problems. However, it does not ignore all errors, and problems with serializing the message will not fail silently. (This option is available for backward compatibility but is not recommended for typical use.)
Exemple :
MAILERS = {
"default": {
"BACKEND": "django.core.mail.backends.smtp.EmailBackend",
"OPTIONS": {
"host": "smtp.example.net",
"use_tls": True,
"username": "my-app",
"password": os.environ["MY_APP_SMTP_PASSWORD"],
"timeout": 10,
},
},
}
Obsolète depuis la version 6.1: When the MAILERS setting is not defined, Django uses the SMTP
backend as the default mailer (the default EMAIL_BACKEND),
connecting to localhost on port 25. This behavior will be removed in Django
7.0, which will not have a default mailer configuration.
When the SMTP backend is used without MAILERS defined,
the options listed above are obtained from the deprecated
EMAIL_HOST, EMAIL_PORT, EMAIL_HOST_USER,
EMAIL_HOST_PASSWORD, EMAIL_USE_TLS,
EMAIL_USE_SSL, EMAIL_SSL_KEYFILE,
EMAIL_SSL_CERTFILE, and EMAIL_TIMEOUT settings,
respectively. (There is no setting equivalent to the "fail_silently"
option.)
- class backends.smtp.EmailBackend¶
Directly instantiating an
EmailBackendclass is not recommended. Usemailersto obtain a backend instance.When constructed directly (without going through
mailers), the SMTPEmailBackendclass accepts the options listed above as keyword arguments. Default values come from the corresponding, deprecatedEMAIL_*settings.hostis not required and defaults to"localhost", andportdefaults to25even ifuse_tlsoruse_sslis True.When the
MAILERSsetting is defined, attempting to directly create an SMTPEmailBackendwill raise anAttributeError.Obsolète depuis la version 6.1: Directly constructing an instance of an
EmailBackendclass will be unsupported in Django 7.0. Undocumented use will result in different default argument handling compared to earlier releases.
Private and self-signed SMTP server certificates¶
If the SMTP server uses an SSL certificate from a private certificate authority
(CA), the CA’s root certificate should be added to the system CA bundle on the
client (where Django is running). Likewise, if the server uses a self-signed
certificate, it should be added to the client’s system CA bundle so it can be
trusted. (The SMTP backend’s "ssl_certfile" option cannot be used for CA
roots or self-signed certificates.)
Follow platform-specific instructions for adding to the system CA bundle. If
modifying the system bundle is not possible or desired, an alternative is using
OpenSSL’s SSL_CERT_FILE or SSL_CERT_DIR environment variables to
specify a custom certificate bundle.
For more complex scenarios, the SMTP backend can be subclassed to add root
certificates to its ssl_context using
ssl.SSLContext.load_verify_locations().
Le moteur console¶
Instead of sending out real emails, the console backend writes the emails that
would be sent to the standard output. To use it, set BACKEND to "django.core.mail.backends.console.EmailBackend".
The console backend supports these OPTIONS:
"stream": a stream-like object to write to. Defaults tostdout."fail_silently": set toTrueto ignore all errors while writing the message to the stream, including errors serializing the message. (This option is available for backward compatibility but is not recommended.)
Ce moteur n’est pas conçu pour être utilisé en production, il n’est fourni que par commodité et destiné à être utilisé durant le développement.
The settings file created by startproject now defines
MAILERS with the console backend as the default configuration.
Le moteur fichier¶
The file backend writes emails to a file. A new file is created for each new
session that is opened on this backend. To use it, set BACKEND to "django.core.mail.backends.filebased.EmailBackend".
The file backend supports these OPTIONS:
"file_path"(required): the directory to which the files are written. Can be a string or apathlib.Pathobject. If the directory does not exist, the file backend will attempt to create it."fail_silently": set toTrueto ignore all errors while writing the message to the file – including errors serializing the message – but not errors related to ensuring the file path directory exists. (This option is available for backward compatibility but is not recommended.)
Ce moteur n’est pas conçu pour être utilisé en production, il n’est fourni que par commodité et destiné à être utilisé durant le développement.
Obsolète depuis la version 6.1: When the file backend is used without the MAILERS setting
defined, it will get its file_path option from the
EMAIL_FILE_PATH setting.
Le moteur mémoire¶
The 'locmem' backend stores messages in a special attribute of the
django.core.mail module. The outbox attribute is created when the first
message is sent. It’s a list with an EmailMessage instance for each
message that would be sent. Messages in the outbox are annotated with a
sent_using attribute that identifies the MAILERS alias used to
send the message.
To use the in-memory backend, set BACKEND to
"django.core.mail.backends.locmem.EmailBackend". It does not support any
OPTIONS.
Django’s test runner automatically switches to this backend for testing.
Ce moteur n’est pas conçu pour être utilisé en production, il n’est fourni que par commodité et destiné à être utilisé durant le développement et les tests.
The sent_using attribute was added to messages in the outbox.
Le moteur bidon¶
As the name suggests the dummy backend does nothing with your messages. To use
it, set BACKEND to
"django.core.mail.backends.dummy.EmailBackend". It does not support any
OPTIONS.
Ce moteur n’est pas conçu pour être utilisé en production, il n’est fourni que par commodité et destiné à être utilisé durant le développement.
Moteurs de tierce partie¶
There are community-maintained solutions!
Django possède un écosystème dynamique. Il existe des moteurs de messagerie mis en évidence sur la page Community Ecosystem. La grille sur la messagerie de Django Packages présente encore d’autres options à votre disposition.
Third-party email backends are available that:
Integrate directly with commercial email service providers” APIs (which often have extra functionality not available through SMTP).
Offload email sending to asynchronous task queues.
Add features to other email backends, such as enforcing do-not-send lists or logging sent messages.
Provide development and debugging tools, such as sandbox capture and in-browser email previews.
Définition d’un moteur de messagerie personnalisé¶
If you need to change how emails are sent you can write your own email backend.
To use a custom backend, set BACKEND to the Python
import path for your backend class and OPTIONS to
any __init__() keyword arguments your backend supports.
Les moteurs de messagerie personnalisés doivent hériter de BaseEmailBackend qui se trouve dans le module django.core.mail.backends.base. Un moteur de messagerie personnalisé doit implémenter la méthode send_messages(email_messages). Celle-ci reçoit une liste d’instances EmailMessage et renvoie le nombre de message délivrés avec succès. Si votre moteur contient la notion de session ou connexion persistante, vous devriez aussi implémenter les méthodes open() et close(). Référez-vous à smtp.EmailBackend pour une implémentation de référence.
Obtention d’une instance d’un moteur de messagerie¶
The mailers factory in django.core.mail returns instances of email
backends.
- mailers¶
- New in Django 6.1.
You can access the mailers configured in the
MAILERSsetting through a dict-like object:django.core.mail.mailers:>>> from django.core.mail import mailers >>> mailers["notifications"]
If the named key is not defined, a
MailerDoesNotExisterror will be raised. Other configuration problems will raise anInvalidMailererror.
- mailers.default¶
- New in Django 6.1.
As a shortcut, the default mailer can be accessed through
django.core.mail.mailers.default:>>> from django.core.mail import mailers >>> mailers.default
This is equivalent to
mailers["default"]. If no default mailer has been configured, aMailerDoesNotExisterror will be raised.Obsolète depuis la version 6.1: If the
MAILERSsetting is not defined,mailers.defaultwill create an email backend instance from the deprecatedEMAIL_BACKENDand related settings. This supports backward compatibility with Django 6.0 and earlier.This behavior (and those settings) will be removed in Django 7.0.
- get_connection(backend=None, *, fail_silently=False, **kwargs)[source]¶
The deprecated
django.core.mail.get_connection()function creates and returns an instance of an email backend. Its behavior depends on theMAILERSsetting and how the function is called.If the
MAILERSsetting is defined:get_connection()with no arguments will returnmailers.default.get_connection(...)called with onlyfail_silentlyor other keyword arguments will create an instance ofMAILERS["default"]with any keywords added to the default mailer’sOPTIONS.get_connection(backend, ...)with a backend import path will raise an error.
If the
MAILERSsetting is not defined:get_connection()with no arguments will return an instance of the email backend specified inEMAIL_BACKEND.If you specify the
backendargument, an instance of that backend will be instantiated.If the keyword argument
fail_silentlyis True, certain backend-dependent exceptions during the email sending process will be silently ignored.Tous les autres paramètres nommés sont directement transmis au constructeur du moteur de messagerie.
Obsolète depuis la version 6.0: Passing
fail_silentlyas a positional argument is deprecated.Obsolète depuis la version 6.1:
get_connection()is deprecated and will be removed in Django 7.0. Switch tomailers[alias]. See Replacing get_connection() and connection arguments for migration suggestions.
Email backend API¶
Instances of an email backend class have the following methods:
open()instancie une connexion persistante d’envoi de messages.close()ferme la connexion actuelle vers le système d’envoi de messages.send_messages(email_messages)envoie une liste d’objetsEmailMessage. Si la connexion n’est pas ouverte, cet appel ouvrira implicitement la connexion, puis la fermera à la fin de l’opération. Si la connexion est déjà ouverte, elle sera conservée ouverte après l’envoi des messages.
A backend instance can also be used as a context manager, which will
automatically call open() and close() as needed. An example is in
Sending many messages efficiently.
Configuration de la messagerie pour le développement¶
À certains moments, vous ne voulez absolument pas que que Django envoie des courriels. Par exemple, pendant le développement d’un site Web, vous ne voulez certainement pas envoyer des milliers de courriels, mais vous voulez peut-être valider que ces courriels seraient envoyés aux bonnes personnes et aux bonnes conditions, et que leur contenu est correct.
La manière la plus simple de configurer la messagerie électronique lors du développement local est d’utiliser le moteur de messagerie console. Ce moteur redirige tous les courriels vers la sortie standard stdout, ce qui permet d’inspecter leur contenu.
Le moteur de messagerie fichier peut aussi être utile durant le développement ; ce moteur redirige le contenu de chaque connexion SMTP dans un fichier qui peut ensuite être examiné à souhait.
Another approach is to use a mocked SMTP server that receives the emails locally and displays them to the terminal, but does not actually send anything. The aiosmtpd package provides a way to accomplish this:
python -m pip install "aiosmtpd >= 1.4.5"
python -m aiosmtpd -n -l localhost:8025
This command will start a minimal SMTP server listening on port 8025 of
localhost. This server prints to standard output all email headers and the
email body. You then only need to set an SMTP backend’s "host" and
"port" OPTIONS accordingly. For a more
detailed discussion of SMTP server options, see the documentation of the
aiosmtpd module.
Pour plus d’informations sur les tests unitaires impliquant l’envoi de courriels par votre application, consultez la section Services de messagerie de la documentation sur les tests.