Sending provider
Amazon SES SPF, DKIM and DMARC setup
Amazon SES signs with Easy DKIM: three CNAME records, <token>._domainkey pointing to <token>.dkim.<region>.amazonses.com. SPF needs nothing on your domain by default, because SES uses its own MAIL FROM domain. For SPF to align under DMARC, set a custom MAIL FROM subdomain with one MX record and v=spf1 include:amazonses.com ~all, then publish DMARC at _dmarc.
Amazon SES
Records at a glance
- SPF (custom MAIL FROM)
v=spf1 include:amazonses.com ~all- DKIM
Three CNAMEs: <token>._domainkey
- DMARC
TXT at _dmarc, p=none first, then quarantine and reject
Check Amazon SES on your domain
Enter the domain you send from: the check looks for the Amazon SES SPF include, its DKIM key and your DMARC record, and says what to fix.
Lookups go from your browser to Cloudflare's public DNS resolver.
DNS records
The Amazon SES records
Values in angle brackets are specific to your account; copy them from the provider. Hosts are relative to your domain, as most DNS panels expect them.
- Name / host
<token>._domainkeyValue<token>.dkim.<region>.amazonses.comSES gives three tokens per identity; publish all three. Tokens and region come from the SES console
- Return pathMXsource (opens the vendor's page in a new tab)Name / host
<subdomain> (custom MAIL FROM)Value10 feedback-smtp.<region>.amazonses.comOptional. Exactly one MX on a subdomain that does not send or receive other mail
- Name / host
<subdomain> (custom MAIL FROM)Valuev=spf1 include:amazonses.com ~allOn the MAIL FROM subdomain; without a custom MAIL FROM, SES handles SPF on its own domain
- Name / host
_dmarcValuev=DMARC1;p=quarantine;rua=mailto:my_dmarc_report@example.comAWS's example; it suggests starting at p=none and moving through quarantine to reject
Good to know
- By default the MAIL FROM domain is a subdomain of amazonses.com, so SPF passes for SES but does not align with your From domainsource (opens the vendor's page in a new tab)
- DMARC passes on DKIM alignment with Easy DKIM; for SPF alignment you need the custom MAIL FROM subdomain and no aspf=ssource (opens the vendor's page in a new tab)
- Easy DKIM keys are 2048-bit by default, 1024-bit optional, and the key length can change once every 24 hourssource (opens the vendor's page in a new tab)
- Identities are per AWS Region: a domain verified in us-east-1 is set up again in eu-west-1source (opens the vendor's page in a new tab)
Step by step
Turn on Easy DKIM in Amazon SES
Open the identitysource (opens the vendor's page in a new tab)
In the SES console go to Configuration > Identities and choose your domain, or Create identity > Domain
Edit DKIMsource (opens the vendor's page in a new tab)
On the Authentication tab, under DomainKeys Identified Mail (DKIM), click Edit
Pick Easy DKIMsource (opens the vendor's page in a new tab)
Under Advanced DKIM settings set Identity type to Easy DKIM and the signing key length to RSA_2048_BIT
Enable signaturessource (opens the vendor's page in a new tab)
Check Enabled under DKIM signatures and save the changes
Publish the CNAMEssource (opens the vendor's page in a new tab)
Copy the three CNAME records to your DNS host, or Publish to Route 53. DKIM shows Successful and the identity Verified once SES finds them
Where the records go
Field by field for the DNS panel your domain uses:
DMARC
DMARC with Amazon SES
- Publish a TXT record at _dmarc; AWS's example is v=DMARC1;p=quarantine;rua=mailto:my_dmarc_report@example.comsource (opens the vendor's page in a new tab)
- Roll the policy out in phases: p=none, then p=quarantine, then p=rejectsource (opens the vendor's page in a new tab)
- Sending from a subdomain aligns with relaxed DKIM alignment against the organizational domainsource (opens the vendor's page in a new tab)
TXT at _dmarc
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.comReplace the address with a mailbox you read; move to p=quarantine when the reports show every sender passing.
Troubleshooting
Common Amazon SES errors and fixes
DKIM pending verification
SES can take up to 72 hours to detect the records; check each record name meanwhilesource (opens the vendor's page in a new tab)
Host doubled: x._domainkey.example.com.example.com
Remove the domain from the host name, or end the full name with a periodsource (opens the vendor's page in a new tab)
Extra underscore before the token
The name is abc123._domainkey.example.com with no leading underscore before abc123source (opens the vendor's page in a new tab)
DNS host rejects underscores
_domainkey needs the underscore; ask the DNS host to support itsource (opens the vendor's page in a new tab)
DKIM setup revoked
Publish the CNAME records again; if SES revoked the setup, start DKIM setup oversource (opens the vendor's page in a new tab)
MAIL FROM Failed or MailFromDomainNotVerified
Publish exactly one MX record, feedback-smtp.<region>.amazonses.com, on the subdomain and restart the setupsource (opens the vendor's page in a new tab)
For cold email
Mailboxes that come with the DNS records done
If the domain is for cold outreach, keep Amazon SES on your main domain and send from separate domains. Outreach2day buys the domains, publishes SPF, DKIM and DMARC, creates the mailboxes and starts warm-up, then sends your campaigns from its own sequencer or exports the mailboxes to Instantly or Smartlead.
- SPF, DKIM and DMARC set for youOn every domain, checked after setup and kept in place
- $2.50 a mailbox a month12-mailbox minimum; warm-up and the sending engine included
- 1,000+ mailboxesA volume price per mailbox, quoted on a call
Questions
Do I need include:amazonses.com in my SPF record?
Not on your root domain. SES sends with its own MAIL FROM domain by default and handles SPF there. The include goes on a custom MAIL FROM subdomain, which you need only for SPF alignment under DMARC.
What is the Amazon SES DKIM selector?
Each identity gets three tokens, and each token is a selector: <token>._domainkey.<yourdomain>. Copy them from the identity's DKIM section in the SES console.
Why is Amazon SES DKIM still pending?
SES checks for up to 72 hours. If it stays pending, the usual causes are a host name with the domain added twice, an extra underscore before the token, or a missing record of the three.
Is Amazon SES a good fit for cold email?
SES is built for mail people expect, and AWS reviews accounts that draw complaints. Cold outreach usually runs from separate domains and mailboxes with warm-up, so complaints never reach the SES account your product mail depends on.
Sources
Amazon SES documentation, checked . Menus and values change; if a step differs, Amazon SES's own page is the reference.
Deliverability call
Talk to our deliverability team
Book a call with the people who run our mailbox infrastructure. We look at your current setup and tell you what to change. Running 1,000+ mailboxes? We also quote a volume price below every vendor list price in our comparisons, warm-up and sending included.
- Review your domains, DNS records and current inbox placement
- Size the setup: domains, mailboxes per domain and daily volume per mailbox
- Plan warm-up and the move from your current provider or sequencer
- 1,000+ mailboxes: a volume price per mailbox for your setup
Free call
See open times in your time zone and book on this page.
Or open the booking pageLoading available times…
Open the booking page instead