Guide

DNS records for SES sending

Four record groups stand between a domain and a sendable identity: one ownership TXT, three DKIM CNAMEs, a custom MAIL FROM with its MX and SPF, and DMARC. This guide is the order to create them in, with the dig command that proves each one landed.

The four record groups

Records for a SendFleet sending domain
RecordRequiredWhat it does
Ownership TXTRequiredProves you control the domain. Nothing sends until this passes.
DKIM CNAMEs, three of themRequiredSigns your outgoing mail. All three must resolve.
MAIL FROM MX and SPFRecommendedRoutes bounces through your own subdomain and adds a second authentication path.
DMARC TXTRecommendedTells receivers what to do when SPF or DKIM fails, and gives you reporting.

The dashboard shows you the exact records for your domain, with the real tokens in them, on the domain detail page. This guide is the shape, the order and the verification.

1. Ownership, one TXT record

  1. Add the TXT record

    Name _amazonses.example.com, value the token from your dashboard, TTL 300.
  2. Check your provider's name convention first

    Some providers want the fully qualified _amazonses.example.com. Others append your domain for you and want only _amazonses. Getting it wrong produces _amazonses.example.com.example.com, which never verifies.
  3. Confirm it resolves, then verify

    Run the dig command below, then press Verify ownership on the domain detail page.
Check the ownership record
dig TXT _amazonses.example.com +short

A single line containing your token means the record is published. An empty result means it is not there yet, or the name is wrong.

2. DKIM, three CNAME records

DKIM signs every message you send, and receivers check that signature against the public key in your DNS. Without it, many providers flag your mail as suspicious or drop it without telling you.

DKIM records, one row per token
TypeNameValue
CNAME<token1>._domainkey.example.com<token1>.dkim.amazonses.com
CNAME<token2>._domainkey.example.com<token2>.dkim.amazonses.com
CNAME<token3>._domainkey.example.com<token3>.dkim.amazonses.com
Check one DKIM record
dig CNAME token1._domainkey.example.com +short
# expect: token1.dkim.amazonses.com

Run it for all three tokens. Each must resolve to a .dkim.amazonses.com hostname. A provider that strips the trailing dot will leave you with a relative answer that looks wrong but is not.

When all three resolve, choose Verify DKIM on the domain detail page. Once that passes the domain is send-ready.

3. Custom MAIL FROM, MX and SPF

The MAIL FROM domain is the envelope sender, or Return-Path. It is separate from the From: address your recipient sees. SES uses its own by default; setting a subdomain of yours gives you a second authentication path and routes bounces back through your domain.

MAIL FROM records
TypeNameValue
MXsend.example.com10 feedback-smtp.us-east-1.amazonses.com
TXTsend.example.com"v=spf1 include:amazonses.com ~all"
Check the MAIL FROM records
dig MX send.example.com +short
dig TXT send.example.com +short

The MX answer should be a single line with priority 10 and an amazonses.com host. The TXT answer should start with v=spf1 and contain exactly one include:amazonses.com.

4. DMARC, one TXT record

DMARC tells receivers what to do when SPF or DKIM fails, and gives you a report of who is sending as your domain.

DMARC record
_dmarc.example.com  TXT  "v=DMARC1; p=none; rua=mailto:dmarc@example.com"
Count the DMARC records
dig TXT _dmarc.example.com +short
# one line means enforced. Two or more means it is not.

If a check will not pass

Symptoms and causes
SymptomLikely causeWhat to do
Ownership keeps failingThe record has not propagated, or the subdomain prefix was doubled.Wait 15 to 30 minutes, confirm with dig, then verify again.
DKIM fails after adding recordsOne or two of the three CNAMEs are missing, or a provider mangled a trailing dot.Check all three with dig. Each must resolve to a .dkim.amazonses.com name.
MAIL FROM stays pendingThe MX record is missing, or points at the wrong region.Compare the MX value against the region on your dashboard.
DMARC reports conflicting recordsMore than one v=DMARC1 record exists.Keep the one you want enforced and delete the rest.
Everything verifies and mail still lands in spamAuthentication is necessary and not sufficient.Confirm DMARC is published, then look at content, sending history and list quality.

Next

With the records in place the domain is sendable. The one-request send guide has a working request in five languages, and the Webhooks reference covers what to do with the delivery events that come back.