Prompt
Amazon SES setup DKIM SPF DMARC
Latest observation
Here’s a practical setup guide for Amazon SES + DKIM + SPF + DMARC.
1) Verify your domain in Amazon SES
- Open Amazon SES in AWS.
- Go to Verified identities → Create identity.
- Choose Domain.
- Enter your domain, e.g.
example.com. - Enable:
- DKIM
- optional: Custom MAIL FROM domain (recommended)
- SES will give you DNS records to add.
2) Configure DKIM
SES usually supports Easy DKIM.
DNS records
Amazon SES will provide 3 CNAME records like:
Name: abc123._domainkey.example.com
Type: CNAME
Value: abc123.dkim.amazonses.com
Add all 3 CNAMEs to your DNS provider.
Why this matters
DKIM signs outgoing mail so receiving servers can verify it wasn’t altered and that SES is authorized to send on your behalf.
3) Configure SPF
SPF tells receivers which servers can send mail for your domain.
Basic SPF record for SES
If SES is your only sender, use:
Type: TXT
Name: @
Value: v=spf1 include:amazonses.com -all
Important
- Only one SPF TXT record per domain.
- If you already have SPF for Google Workspace, Microsoft 365, Mailgun, etc., you must merge them into a single record.
Example with multiple senders:
v=spf1 include:amazonses.com include:_spf.google.com -all
4) Configure DMARC
DMARC uses SPF and DKIM results to decide what to do with failing mail.
Recommended starting policy
Start with monitoring:
Type: TXT
Name: _dmarc
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s
Explanation
p=none= monitor only, don’t reject/quarantine yetrua== aggregate reports sent to this emailadkim=s= strict DKIM alignmentaspf=s= strict SPF alignment
Later, tighten policy
After confirming legitimate mail passes:
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s
Eventually:
v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s
5) Recommended SES Custom MAIL FROM domain
This improves SPF alignment and deliverability.
Example:
- Mail From domain:
mail.example.com
SES will ask for:
- MX record
- TXT record
Typical values:
MX
Name: mail.example.com
Type: MX
Value: 10 feedback-smtp.us-east-1.amazonses.com
SPF for MAIL FROM subdomain
Name: mail.example.com
Type: TXT
Value: v=spf1 include:amazonses.com -all
(Use the correct SES region endpoint.)
6) DNS records summary
For example.com, you may end up with:
DKIM
3x CNAME records from SES
SPF
example.com TXT "v=spf1 include:amazonses.com -all"
DMARC
_dmarc.example.com TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s"
Optional MAIL FROM
mail.example.com MX 10 feedback-smtp.<region>.amazonses.com
mail.example.com TXT "v=spf1 include:amazonses.com -all"
7) Verify everything
Use tools like:
- MXToolbox
- dmarcian
- Google Admin Toolbox
dig/nslookup
Check:
- DKIM records resolve correctly
- SPF has only one record
- DMARC is published at
_dmarc.example.com - SES identity shows verified
8) Common mistakes
- Having multiple SPF TXT records on the same domain
- Forgetting to add all 3 DKIM CNAMEs
- Using
-allbefore all senders are included in SPF - Setting DMARC to
rejecttoo early - Misalignment between “From” domain and DKIM/SPF domains
9) Best-practice policy
If you’re just starting with SES:
- Set up DKIM
- Add SPF
- Publish DMARC with p=none
- Enable Custom MAIL FROM
- Monitor reports for a few days/weeks
- Move to
quarantine - Then move to
reject
If you want, I can generate the exact DNS records for your domain and SES region if you tell me:
- your domain name
- your SES region
- whether you use Google Workspace / Microsoft 365 / another sender too