Guide
DNS records for SES sending
Four record groups stand between a domain and a sendable identity: one ownership TXT, three DKIM CNAMEs, a custom MAIL FROM with its MX and SPF, and DMARC. This guide is the order to create them in, with the dig command that proves each one landed.
The four record groups
| Record | Required | What it does |
|---|---|---|
| Ownership TXT | Required | Proves you control the domain. Nothing sends until this passes. |
| DKIM CNAMEs, three of them | Required | Signs your outgoing mail. All three must resolve. |
| MAIL FROM MX and SPF | Recommended | Routes bounces through your own subdomain and adds a second authentication path. |
| DMARC TXT | Recommended | Tells receivers what to do when SPF or DKIM fails, and gives you reporting. |
The dashboard shows you the exact records for your domain, with the real tokens in them, on the domain detail page. This guide is the shape, the order and the verification.
1. Ownership, one TXT record
Add the TXT record
Name_amazonses.example.com, value the token from your dashboard, TTL 300.Check your provider's name convention first
Some providers want the fully qualified_amazonses.example.com. Others append your domain for you and want only_amazonses. Getting it wrong produces_amazonses.example.com.example.com, which never verifies.Confirm it resolves, then verify
Run the dig command below, then press Verify ownership on the domain detail page.
dig TXT _amazonses.example.com +short
A single line containing your token means the record is published. An empty result means it is not there yet, or the name is wrong.
2. DKIM, three CNAME records
DKIM signs every message you send, and receivers check that signature against the public key in your DNS. Without it, many providers flag your mail as suspicious or drop it without telling you.
| Type | Name | Value |
|---|---|---|
| CNAME | <token1>._domainkey.example.com | <token1>.dkim.amazonses.com |
| CNAME | <token2>._domainkey.example.com | <token2>.dkim.amazonses.com |
| CNAME | <token3>._domainkey.example.com | <token3>.dkim.amazonses.com |
dig CNAME token1._domainkey.example.com +short # expect: token1.dkim.amazonses.com
Run it for all three tokens. Each must resolve to a .dkim.amazonses.com hostname. A provider that strips the trailing dot will leave you with a relative answer that looks wrong but is not.
When all three resolve, choose Verify DKIM on the domain detail page. Once that passes the domain is send-ready.
3. Custom MAIL FROM, MX and SPF
The MAIL FROM domain is the envelope sender, or Return-Path. It is separate from the From: address your recipient sees. SES uses its own by default; setting a subdomain of yours gives you a second authentication path and routes bounces back through your domain.
| Type | Name | Value |
|---|---|---|
| MX | send.example.com | 10 feedback-smtp.us-east-1.amazonses.com |
| TXT | send.example.com | "v=spf1 include:amazonses.com ~all" |
dig MX send.example.com +short dig TXT send.example.com +short
The MX answer should be a single line with priority 10 and an amazonses.com host. The TXT answer should start with v=spf1 and contain exactly one include:amazonses.com.
4. DMARC, one TXT record
DMARC tells receivers what to do when SPF or DKIM fails, and gives you a report of who is sending as your domain.
_dmarc.example.com TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com"
dig TXT _dmarc.example.com +short # one line means enforced. Two or more means it is not.
If a check will not pass
| Symptom | Likely cause | What to do |
|---|---|---|
| Ownership keeps failing | The record has not propagated, or the subdomain prefix was doubled. | Wait 15 to 30 minutes, confirm with dig, then verify again. |
| DKIM fails after adding records | One or two of the three CNAMEs are missing, or a provider mangled a trailing dot. | Check all three with dig. Each must resolve to a .dkim.amazonses.com name. |
| MAIL FROM stays pending | The MX record is missing, or points at the wrong region. | Compare the MX value against the region on your dashboard. |
| DMARC reports conflicting records | More than one v=DMARC1 record exists. | Keep the one you want enforced and delete the rest. |
| Everything verifies and mail still lands in spam | Authentication is necessary and not sufficient. | Confirm DMARC is published, then look at content, sending history and list quality. |
Next
With the records in place the domain is sendable. The one-request send guide has a working request in five languages, and the Webhooks reference covers what to do with the delivery events that come back.