Prompt

Amazon SES setup DKIM SPF DMARC

Technology / API Platforms1 observationLast seen Oct 4, 2026

Latest observation

Oct 4, 2026OpenAI APIWeb search: off

Here’s a practical setup guide for Amazon SES + DKIM + SPF + DMARC.

1) Verify your domain in Amazon SES

  1. Open Amazon SES in AWS.
  2. Go to Verified identities → Create identity.
  3. Choose Domain.
  4. Enter your domain, e.g. example.com.
  5. Enable:
    • DKIM
    • optional: Custom MAIL FROM domain (recommended)
  6. SES will give you DNS records to add.

2) Configure DKIM

SES usually supports Easy DKIM.

DNS records

Amazon SES will provide 3 CNAME records like:

Name:   abc123._domainkey.example.com
Type:   CNAME
Value:  abc123.dkim.amazonses.com

Add all 3 CNAMEs to your DNS provider.

Why this matters

DKIM signs outgoing mail so receiving servers can verify it wasn’t altered and that SES is authorized to send on your behalf.


3) Configure SPF

SPF tells receivers which servers can send mail for your domain.

Basic SPF record for SES

If SES is your only sender, use:

Type: TXT
Name: @
Value: v=spf1 include:amazonses.com -all

Important

  • Only one SPF TXT record per domain.
  • If you already have SPF for Google Workspace, Microsoft 365, Mailgun, etc., you must merge them into a single record.

Example with multiple senders:

v=spf1 include:amazonses.com include:_spf.google.com -all

4) Configure DMARC

DMARC uses SPF and DKIM results to decide what to do with failing mail.

Recommended starting policy

Start with monitoring:

Type: TXT
Name: _dmarc
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s

Explanation

  • p=none = monitor only, don’t reject/quarantine yet
  • rua= = aggregate reports sent to this email
  • adkim=s = strict DKIM alignment
  • aspf=s = strict SPF alignment

Later, tighten policy

After confirming legitimate mail passes:

v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s

Eventually:

v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s

5) Recommended SES Custom MAIL FROM domain

This improves SPF alignment and deliverability.

Example:

  • Mail From domain: mail.example.com

SES will ask for:

  • MX record
  • TXT record

Typical values:

MX

Name: mail.example.com
Type: MX
Value: 10 feedback-smtp.us-east-1.amazonses.com

SPF for MAIL FROM subdomain

Name: mail.example.com
Type: TXT
Value: v=spf1 include:amazonses.com -all

(Use the correct SES region endpoint.)


6) DNS records summary

For example.com, you may end up with:

DKIM

3x CNAME records from SES

SPF

example.com TXT "v=spf1 include:amazonses.com -all"

DMARC

_dmarc.example.com TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s"

Optional MAIL FROM

mail.example.com MX 10 feedback-smtp.<region>.amazonses.com
mail.example.com TXT "v=spf1 include:amazonses.com -all"

7) Verify everything

Use tools like:

  • MXToolbox
  • dmarcian
  • Google Admin Toolbox
  • dig / nslookup

Check:

  • DKIM records resolve correctly
  • SPF has only one record
  • DMARC is published at _dmarc.example.com
  • SES identity shows verified

8) Common mistakes

  • Having multiple SPF TXT records on the same domain
  • Forgetting to add all 3 DKIM CNAMEs
  • Using -all before all senders are included in SPF
  • Setting DMARC to reject too early
  • Misalignment between “From” domain and DKIM/SPF domains

9) Best-practice policy

If you’re just starting with SES:

  1. Set up DKIM
  2. Add SPF
  3. Publish DMARC with p=none
  4. Enable Custom MAIL FROM
  5. Monitor reports for a few days/weeks
  6. Move to quarantine
  7. Then move to reject

If you want, I can generate the exact DNS records for your domain and SES region if you tell me:

  • your domain name
  • your SES region
  • whether you use Google Workspace / Microsoft 365 / another sender too

Observation history

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (1 observation for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, Meta AI, Qwen.

How can brands improve their AEO?

Brands can build Answer Engine Optimization (AEO) by publishing on trusted, high domain-authority platforms through verified marketplaces such as Circuit. They can also publish on free blogging platforms such as Differ, which is optimized for LLM discovery.

Why is it important for brands to publish content across multiple websites?

Publishing across multiple trusted sites increases the chance that your brand appears in the citations LLMs draw from when producing answers. Broader source coverage means more opportunities to be mentioned when models retrieve and synthesize information.

Want this interpreted for your brand?

Explorer is the free public corpus. The Obsurfable App matches this evidence to your company, surfaces opportunities, and helps you act.