Guides
Sending domains
Verify a domain, publish the DNS records, and scope keys to it.
Every from address must sit on a verified sending domain. Until your
domain is verified, sends from it fail with from_domain_not_verified.
Domains are managed in the console under Domains (not through the public REST API).
Setup
- Add your domain in the console (e.g.
mail.acme.comoracme.com). - Publish the DNS records it shows. The console tailors instructions to your DNS provider (relative vs. FQDN hosts, copy-paste values).
- Wait for verification — usually under five minutes. The console shows SPF, DKIM, DMARC, and MAIL FROM status per record.
The records
| Type | Host | Value | Purpose |
|---|---|---|---|
| TXT | your domain | v=spf1 include:amazonses.com ~all | SPF — authorizes SES to send for you |
| CNAME | <token>._domainkey.<domain> | <token>.dkim.amazonses.com | DKIM (one per token; Easy-DKIM) |
| TXT | <selector>._domainkey.<domain> | v=DKIM1; k=rsa; p=<public key> | DKIM (bring-your-own-key domains: one record instead of CNAMEs) |
| MX | mail.<domain> | 10 feedback-smtp.<region>.amazonses.com | Custom MAIL FROM — SPF alignment |
| TXT | mail.<domain> | v=spf1 include:amazonses.com ~all | SPF for the custom MAIL FROM |
| TXT | _dmarc.<domain> | v=DMARC1; p=none; adkim=s; aspf=s | DMARC policy (start at none, ramp later) |
Merge, never duplicate, SPF
If you already publish a v=spf1 record, merge include:amazonses.com into
it before the trailing all — a second SPF record at the same host is a
permanent SPF failure. The console shows the merged value for your domain.
Domain-scoped API keys
A sending_access key can be pinned to one verified domain. Sends from any
other from domain with that key fail from_domain_not_verified — a good
guardrail for per-brand services. See
Authentication.
Keep it healthy
- Never send from a domain you don't control — reputation is domain-scoped.
- Watch the console's deliverability view: bounce and complaint rates move your SES account health, and hard bounces auto-suppress the recipient.
- Move DMARC from
p=nonetowardquarantine/rejectas you gain confidence in your sending graph.