How to configure Amazon SES (Simple Email Service) in your DNS
Follow these 4 straightforward steps to publish your authentication records on Cloudflare, GoDaddy, Namecheap, or AWS Route 53.
Verify Domain in AWS SES
In the Amazon SES Console, create a new Identity for your domain and enable Easy DKIM (publishes 3 CNAME records).
Configure Custom MAIL FROM Domain
Assign a subdomain such as mail.yourdomain.com. AWS will generate an MX record and an SPF TXT record specifically for this subdomain.
v=spf1 include:amazonses.com ~allRoot Domain Fallback Include (Optional)
If also sending directly from apex domain, add include:amazonses.com to your root SPF record.
v=spf1 include:amazonses.com ~allEnforce DMARC Policy
Publish your _dmarc TXT record with aggregate reporting.
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@yourdomain.com; pct=100Frequently Asked Questions for Amazon SES (Simple Email Service)
Technical answers regarding lookup limits, multiple records, and delivery errors.
Why does Amazon SES fail SPF alignment without a custom MAIL FROM?▼
How many lookups does amazonses.com use?▼
Is DKIM mandatory for Amazon SES in 2026?▼
Common Providers Used with Amazon SES (Simple Email Service)
Send marketing and transactional emails alongside your corporate inbox.
Twilio SendGrid
High-Volume Transactional & Marketing Email API
Postmark
Lightning-Fast Transactional Email with Dedicated Streams
Mailgun
Developer-First Email API & Verification Platform
Google Workspace (Gmail)
Official Business Gmail & Google Cloud Email
Need to combine multiple providers into one SPF record?
Our full in-browser engine merges SPF records, calculates RFC 7208 lookups in real-time, and generates custom DMARC policies.