Understanding Amazon Simple Email Service (SES) Email Authentication
Amazon SES requires a Custom MAIL FROM subdomain (e.g. mail.yourdomain.com) with Easy DKIM for full DMARC compliance.
When Amazon Simple Email Service (SES) delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting Amazon Simple Email Service (SES)'s IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.
Required DNS Records for Amazon SES
Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):
| Type | Host / Name | Value / Target | TTL | Purpose |
|---|---|---|---|---|
| TXT | v=spf1 include:amazonses.com ~all | 3600 | Custom MAIL FROM SPF. |
Step-by-Step Setup Instructions
In AWS Console > Amazon SES > Verified Identities > Select domain.
Copy the 3 Easy DKIM CNAME records and add them to DNS.
Set Custom MAIL FROM domain (e.g. mail.yourdomain.com).
Publish MX and SPF records for the subdomain.
Common Amazon SES SPF Configuration Mistakes
× Shared Return-Path DMARC Fail
Cause: Using default MAIL FROM.
Fix: Configure Custom MAIL FROM subdomain.
Frequently Asked Questions
Why does SES use 3 CNAME records?
To support automated background key rotation.
What is a Custom MAIL FROM domain and why does Amazon SES require it?
By default, SES uses its own shared Return-Path domain (e.g. us-east-1.amazonses.com), which means SPF aligns with amazonses.com rather than your From: domain. DMARC requires SPF or DKIM to align with your From: domain. A Custom MAIL FROM domain (e.g. mail.yourdomain.com) creates Return-Path alignment under your domain.
What SPF record do I add for Amazon SES Custom MAIL FROM?
Add a TXT record to your Custom MAIL FROM subdomain (e.g. mail.yourdomain.com), not the root domain: "v=spf1 include:amazonses.com ~all". Also add an MX record to the same subdomain pointing to feedback-smtp.[region].amazonses.com with priority 10.
What are the 3 Easy DKIM CNAME records for SES?
Amazon SES generates three unique CNAME token records (e.g. token1._domainkey, token2._domainkey, token3._domainkey) when you set up Easy DKIM. All three are required. SES rotates keys across all three records automatically every 7 days.
Can I use Amazon SES DKIM with a 2048-bit RSA key instead of Easy DKIM?
Yes. SES supports BYODKIM (Bring Your Own DKIM) where you generate a 2048-bit RSA key pair independently and publish the public key as a TXT record. This gives you direct control over DKIM key material, though it requires manual key rotation.
How do I check my Amazon SES sending reputation?
In the AWS Console, navigate to Amazon SES > Account Dashboard to review bounce rate, complaint rate, and sending quota. High bounce or complaint rates trigger automated SES account review. IncogSay's DMARC Checker can audit your published DMARC policy to confirm reports are being collected at your rua address.