Server-side credentials only. Sender credentials are configured server-side and are never stored in the Partner extension or browser. The sender should represent the business/domain used by the verification session.
The Google Workspace or Gmail sending account and domain must be authenticated server-side. App-password, OAuth, and provider credentials are not entered in this browser UI.
The Microsoft 365 or Outlook sending account and domain must be authenticated server-side. Microsoft credentials are not entered in this browser UI.
A verified sender/domain and Cloudflare server-side binding or configuration are required.
Only SMTP routing metadata and a server-side secret reference are stored here. The SMTP password is never entered or stored in this UI.
Local development: Delivery is captured by Local Outbox only; no provider is contacted.