Official DNS Guide • Cloud Infrastructure & High-Volume Delivery

Amazon Simple Email Service (SES) SPF Record Setup & Validator

Complete guide for Amazon SES SPF configuration, custom MAIL FROM domain setup, and Easy DKIM CNAME generation.

Quick Answer • Exact Amazon SES SPF Syntax

To authorize Amazon Simple Email Service (SES) to send emails on behalf of your domain, add include:amazonses.com to your domain's single DNS TXT SPF record before the terminating ~all mechanism. The standard record is v=spf1 include:amazonses.com ~all.

Live Amazon SES DNS Validator

Test your domain's published SPF, DKIM, and DMARC records via global DoH edge nodes in real time.

Zero-Log Client Evaluation

Understanding Amazon Simple Email Service (SES) Email Authentication

Amazon SES requires a Custom MAIL FROM subdomain (e.g. mail.yourdomain.com) with Easy DKIM for full DMARC compliance.

When Amazon Simple Email Service (SES) delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting Amazon Simple Email Service (SES)'s IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.

Required DNS Records for Amazon SES

Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):

TypeHost / NameValue / TargetTTLPurpose
TXTmailv=spf1 include:amazonses.com ~all3600Custom MAIL FROM SPF.

Step-by-Step Setup Instructions

1

In AWS Console > Amazon SES > Verified Identities > Select domain.

2

Copy the 3 Easy DKIM CNAME records and add them to DNS.

3

Set Custom MAIL FROM domain (e.g. mail.yourdomain.com).

4

Publish MX and SPF records for the subdomain.

Common Amazon SES SPF Configuration Mistakes

× Shared Return-Path DMARC Fail

Cause: Using default MAIL FROM.

Fix: Configure Custom MAIL FROM subdomain.

Frequently Asked Questions

Why does SES use 3 CNAME records?

To support automated background key rotation.

What is a Custom MAIL FROM domain and why does Amazon SES require it?

By default, SES uses its own shared Return-Path domain (e.g. us-east-1.amazonses.com), which means SPF aligns with amazonses.com rather than your From: domain. DMARC requires SPF or DKIM to align with your From: domain. A Custom MAIL FROM domain (e.g. mail.yourdomain.com) creates Return-Path alignment under your domain.

What SPF record do I add for Amazon SES Custom MAIL FROM?

Add a TXT record to your Custom MAIL FROM subdomain (e.g. mail.yourdomain.com), not the root domain: "v=spf1 include:amazonses.com ~all". Also add an MX record to the same subdomain pointing to feedback-smtp.[region].amazonses.com with priority 10.

What are the 3 Easy DKIM CNAME records for SES?

Amazon SES generates three unique CNAME token records (e.g. token1._domainkey, token2._domainkey, token3._domainkey) when you set up Easy DKIM. All three are required. SES rotates keys across all three records automatically every 7 days.

Can I use Amazon SES DKIM with a 2048-bit RSA key instead of Easy DKIM?

Yes. SES supports BYODKIM (Bring Your Own DKIM) where you generate a 2048-bit RSA key pair independently and publish the public key as a TXT record. This gives you direct control over DKIM key material, though it requires manual key rotation.

How do I check my Amazon SES sending reputation?

In the AWS Console, navigate to Amazon SES > Account Dashboard to review bounce rate, complaint rate, and sending quota. High bounce or complaint rates trigger automated SES account review. IncogSay's DMARC Checker can audit your published DMARC policy to confirm reports are being collected at your rua address.