Amazon SES (Simple Email Service): SPF, DKIM & DMARC Setup Guide
AWS SES is powerful and cheap, but its default configuration uses Amazon's domain for SPF alignment. For proper DMARC compliance and domain reputation, you need a custom MAIL FROM domain and Easy DKIM.
1SPF Record Setup
Recommended SPF record for AWS SES:
v=spf1 include:amazonses.com ~allStandard SES uses amazon.com for the MAIL FROM envelope, which breaks SPF alignment with your From: domain. For DMARC to pass via SPF, you MUST configure a custom MAIL FROM domain. Without it, only DKIM alignment can save you.
Step-by-step setup:
- 1In AWS SES Console, go to Verified Identities → select your domain
- 2Under Custom MAIL FROM domain, set a subdomain like mail.yourdomain.com
- 3AWS will provide MX and TXT records to add for the MAIL FROM subdomain
- 4Add: MX record for mail.yourdomain.com pointing to feedback-smtp.[region].amazonses.com
- 5Add: TXT record for mail.yourdomain.com with v=spf1 include:amazonses.com ~all
- 6Wait for AWS to verify the MAIL FROM domain
2DKIM Setup
Example DKIM record location:
[random]._domainkey.yourdomain.comAWS SES Easy DKIM generates 3 CNAME records pointing to Amazon's signing infrastructure. This gives 2048-bit DKIM with automatic key rotation. BYODKIM (bring your own key) is also supported for advanced users.
Step-by-step setup:
- 1In AWS SES Console, go to Verified Identities → your domain
- 2Under DomainKeys Identified Mail (DKIM), select Easy DKIM
- 3Choose 2048-bit RSA key length
- 4AWS provides 3 CNAME records — add all three to your DNS
- 5Wait for AWS to show DKIM status as 'Successful'
- 6Verify with our DKIM checker (look for the SES selectors)
3DMARC Policy
Recommended DMARC record:
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; pct=100Add as a TXT record at: _dmarc.yourdomain.com
With Easy DKIM and custom MAIL FROM configured, both DKIM and SPF will align with your domain for DMARC. Without custom MAIL FROM, only DKIM alignment works. AWS SES also supports DMARC feedback — point rua= to your address.
Common AWS SES Deliverability Issues
DMARC failing despite SPF and DKIM passing
Check alignment — DMARC requires the SPF domain (MAIL FROM) or DKIM domain (d= tag) to match your From: header domain. Without a custom MAIL FROM, the MAIL FROM is an amazonaws.com subdomain, which won't align.
SES account in sandbox mode — emails only going to verified addresses
Request production access in AWS SES Console under Account dashboard → Request production access. Provide use case details, estimated volume, and bounce/complaint handling plans.
High bounce rates causing SES to pause sending
AWS SES auto-pauses accounts with bounce rates over 10% or complaint rates over 0.5%. Clean your list, implement double opt-in, and use SES Bounce and Complaint notifications via SNS.
Emails going to spam when using SES shared IPs
Move to dedicated IPs (available at $24.95/month per IP) for high-volume or sensitive senders. Warm up the IP gradually over 4–6 weeks before sending full volume.
Is Your AWS SES Domain Blacklisted?
Authentication passing is necessary — but not sufficient. Check if your sending domain or IP is on any of 60 blacklists. Free, instant, no signup.
Check Your Domain FreeChecks all 60 blacklists + SPF, DKIM, DMARC, MX in under 10 seconds