Skip to content
Transactional EmailMillions of businesses

Amazon SES (Simple Email Service): SPF, DKIM & DMARC Setup Guide

AWS SES is powerful and cheap, but its default configuration uses Amazon's domain for SPF alignment. For proper DMARC compliance and domain reputation, you need a custom MAIL FROM domain and Easy DKIM.

1SPF Record Setup

Recommended SPF record for AWS SES:

v=spf1 include:amazonses.com ~all

Standard SES uses amazon.com for the MAIL FROM envelope, which breaks SPF alignment with your From: domain. For DMARC to pass via SPF, you MUST configure a custom MAIL FROM domain. Without it, only DKIM alignment can save you.

Step-by-step setup:

  1. 1In AWS SES Console, go to Verified Identities → select your domain
  2. 2Under Custom MAIL FROM domain, set a subdomain like mail.yourdomain.com
  3. 3AWS will provide MX and TXT records to add for the MAIL FROM subdomain
  4. 4Add: MX record for mail.yourdomain.com pointing to feedback-smtp.[region].amazonses.com
  5. 5Add: TXT record for mail.yourdomain.com with v=spf1 include:amazonses.com ~all
  6. 6Wait for AWS to verify the MAIL FROM domain

2DKIM Setup

Example DKIM record location:

[random]._domainkey.yourdomain.com

AWS SES Easy DKIM generates 3 CNAME records pointing to Amazon's signing infrastructure. This gives 2048-bit DKIM with automatic key rotation. BYODKIM (bring your own key) is also supported for advanced users.

Step-by-step setup:

  1. 1In AWS SES Console, go to Verified Identities → your domain
  2. 2Under DomainKeys Identified Mail (DKIM), select Easy DKIM
  3. 3Choose 2048-bit RSA key length
  4. 4AWS provides 3 CNAME records — add all three to your DNS
  5. 5Wait for AWS to show DKIM status as 'Successful'
  6. 6Verify with our DKIM checker (look for the SES selectors)

3DMARC Policy

Recommended DMARC record:

v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; pct=100

Add as a TXT record at: _dmarc.yourdomain.com

With Easy DKIM and custom MAIL FROM configured, both DKIM and SPF will align with your domain for DMARC. Without custom MAIL FROM, only DKIM alignment works. AWS SES also supports DMARC feedback — point rua= to your address.

Common AWS SES Deliverability Issues

DMARC failing despite SPF and DKIM passing

Check alignment — DMARC requires the SPF domain (MAIL FROM) or DKIM domain (d= tag) to match your From: header domain. Without a custom MAIL FROM, the MAIL FROM is an amazonaws.com subdomain, which won't align.

SES account in sandbox mode — emails only going to verified addresses

Request production access in AWS SES Console under Account dashboard → Request production access. Provide use case details, estimated volume, and bounce/complaint handling plans.

High bounce rates causing SES to pause sending

AWS SES auto-pauses accounts with bounce rates over 10% or complaint rates over 0.5%. Clean your list, implement double opt-in, and use SES Bounce and Complaint notifications via SNS.

Emails going to spam when using SES shared IPs

Move to dedicated IPs (available at $24.95/month per IP) for high-volume or sensitive senders. Warm up the IP gradually over 4–6 weeks before sending full volume.

Is Your AWS SES Domain Blacklisted?

Authentication passing is necessary — but not sufficient. Check if your sending domain or IP is on any of 60 blacklists. Free, instant, no signup.

Check Your Domain Free

Checks all 60 blacklists + SPF, DKIM, DMARC, MX in under 10 seconds

Related Free Tools

Other Email Provider Guides