CandidatePulse sends configured recruitment messages through a mailbox connection associated with the recruiter account.
Prefer supported OAuth connections
Use the Google or Microsoft connection flow when available. OAuth avoids entering the primary mailbox password into CandidatePulse and lets the provider control consent.
Use SMTP only when appropriate
For providers requiring an app password, generate a dedicated credential rather than using the normal password. Custom SMTP endpoints are validated and restricted to reduce unsafe network access.
Never paste credentials into notes, templates, support messages, or screenshots.
Test before activating sequences
Use the settings test action with a recipient you control. Confirm sender identity, reply handling, formatting, and provider policy before scheduling candidate messages.
Revoke unused connections
Remove provider access and rotate credentials when a mailbox changes owner, an account is compromised, or CandidatePulse is no longer authorized to send.