Know why sandbox email doesn’t send — and when it would

“Sandboxes don’t email customers” is a setting, not a law. silobase turns the deliverability rules into a pass/fail checklist your admins re-run and sign off after every refresh.

Acme Corp UAT/Deliverability checklist
Re-check now
All emailSends can reach real inboxes
Refreshed 2026-06-14

Why it fails · This sandbox is on "All email" — every workflow, flow, and Apex sender can reach real addresses.

Fix · Setup → Email → Deliverability → set access level to "System email only" until UAT sends are whitelisted.

3 of 6 checks passingNot safe to test
Access levels

Three access levels, one false sense of safety

Salesforce ships three email access levels — No access, System email only, and All email. Only the first two protect customers, and nothing stops a sandbox from sitting on All email for months. The checklist reads the real setting from metadata, not from what the team remembers.

How the detector reads settings

Email access level

What each setting actually allows

No access

Nothing leaves the org. Safest — and rarest in practice.

Safe

System email only

Password resets and system mail only. The sensible default after a refresh.

Safe

All email

Every workflow, flow, and Apex sender delivers to whatever address the record holds.

Would send
Read from Setup metadata on every scan
Refresh resets

Every refresh can quietly re-arm your sandbox

A refresh copies production data — real contact addresses included — and resets configuration you fixed last time. silobase watches refresh dates per sandbox and reopens the checklist the moment a copy lands, so the re-check happens before the first test run, not after the first complaint.

See the proof packet shape

Refresh watch

Checklist state per sandbox copy

UAT

Partial Copy · refreshed 2026-06-14

Re-check open

qa-regression

Developer Pro · refreshed 2026-06-21

Signed off

FullCopy-2026

Full · refreshed 2026-05-30

Re-check open

hotfix-jul

Developer · refreshed 2026-06-27

Signed off
A new refresh reopens every row of the checklist
Sign-off

Make “safe to test” someone’s signature

When every row passes, an admin signs the checklist and the ledger stores who, when, and against which refresh. UAT starts with a named go-ahead — and the next incident review starts with evidence instead of archaeology.

See a signed checklist

Checklist sign-off

hotfix-jul · refresh of 2026-06-27

Checks passing6 of 6

Pat Rivera

Signed · 2026-06-28

Approved

Jordan Blake

Reviewed · 2026-06-28

Witness
“All rows green after the June refresh. Safe-test plan v3 applies — UAT may begin.”
Stored on the ledger with the release record

Refresh day stops being the risky day

2 of 5
tracked sandboxes were on “All email” at last scan
14
risky paths found sitting behind “All email” in one org
100%
of refreshes reopen the checklist automatically

Make “it won’t send” a fact, not a hope.

Run the checklist against your own sandbox metadata — the first findings are free.

    Deliverability Checklist — silobase — silobase