Set up SPF, DKIM and DMARC for Amazon SES
The exact SPF, DKIM and DMARC records Amazon SES needs, where to add them and how to check they pass and align, so Amazon SES mail reaches the inbox.
Updated September 30, 2026
Amazon SES needs three Easy DKIM CNAME records at <token>._domainkey, a custom MAIL FROM subdomain (for example mail.example.com) with an MX record to feedback-smtp.<region>.amazonses.com and an SPF record of v=spf1 include:amazonses.com ~all, and a DMARC record at _dmarc. Easy DKIM alone makes SES mail pass DMARC; the custom MAIL FROM adds aligned SPF as a second path.
Records at a glance
| Host | Type | Value |
|---|---|---|
<token1>._domainkey | CNAME | <token1>.dkim.amazonses.comThree of these, with tokens from the SES console. Copy the exact target: it can include a Region. |
<token2>._domainkey | CNAME | <token2>.dkim.amazonses.com |
<token3>._domainkey | CNAME | <token3>.dkim.amazonses.com |
mail | MX | 10 feedback-smtp.<region>.amazonses.comOn your custom MAIL FROM subdomain, e.g. mail.example.com. Use your SES Region, such as us-east-1. |
mail | TXT | v=spf1 include:amazonses.com ~all |
_dmarc | TXT | v=DMARC1; p=none; rua=mailto:<your report address> |
Set up SPF for Amazon SES
You don’t need to add SES to the SPF record on your main domain. Receivers check SPF against the envelope sender (MAIL FROM), and by default SES uses its own subdomain of amazonses.com there. That passes SPF, but for Amazon’s domain, not yours.
The SPF record that matters is the one on your custom MAIL FROM subdomain: v=spf1 include:amazonses.com ~all. As of September 2026, amazonses.com lists IP ranges directly, so the include costs one DNS lookup. Because it lives on its own subdomain, it doesn’t count against the lookup budget of your main domain’s SPF record.
If SES is the only thing sending from the MAIL FROM subdomain, keep that record as is. If you also send as your root domain through another service, the root record stays separate, for example:
v=spf1 include:_spf.google.com ~allSet up Easy DKIM
- Open the SES console in the Region you send from. Under Configuration, choose Identities, then Create identity and choose Domain. (For an existing identity, open it, go to the Authentication tab and choose Edit in the DKIM container.)
- Under Advanced DKIM settings, choose Easy DKIM and a signing key length: RSA_2048_BIT (the default) or RSA_1024_BIT. Make sure DKIM signatures is Enabled.
- Create the identity, then expand Publish DNS records and copy the three CNAME records. If your domain is in Route 53 in the same account, SES can publish them for you.
- Add the CNAMEs at your DNS host exactly as shown. When SES finds all three, DKIM configuration shows Successful and the identity shows Verified. That can take up to 72 hours.
SES signs every message from a verified domain with that domain’s key once Easy DKIM is successful. To confirm, send a test and look for dkim=pass with header.d= your domain in the Authentication-Results header. Identities are per Region: sending from a second Region means a second identity and its own records.
Make it pass DMARC (alignment)
- DKIM aligns once Easy DKIM is set up, because SES signs with your domain. This is the path that makes SES mail pass DMARC.
- SPF doesn’t align by default. The envelope sender is an
amazonses.comaddress. Fix it with a custom MAIL FROM domain on a subdomain you own.
To set up a custom MAIL FROM domain:
- Open the verified domain identity, and in the Custom MAIL FROM domain pane choose Edit.
- Select Use a custom MAIL FROM domain and enter a subdomain, such as
mail. It must not be a subdomain you send From or receive mail at. - For Behavior on MX failure, choose Use default MAIL FROM domain (mail keeps flowing but SPF stops aligning) or Reject message (SES refuses to send).
- Publish exactly one MX record and the SPF TXT record from the table above on that subdomain. SES checks for up to 72 hours and emails you when it succeeds.
With relaxed alignment (the DMARC default), mail.example.com aligns with example.com. If your DMARC record has aspf=s, SPF can’t align through a subdomain, so leave it relaxed. DMARC alignment explains why.
Add a DMARC record
v=DMARC1; p=none; rua=mailto:<your report address>DMARC Dojo recognizes Amazon SES in DMARC reports, so you can see SES traffic separately from your other senders and confirm it passes with alignment before you move to quarantine and reject. If you also use DMARC Dojo’s hosted SPF, you add senders to your root domain in the dashboard instead of editing DNS.
Check your domain after SES setup
Enter your domain to see its DMARC policy, SPF and DKIM results, a score out of 100 and the fixes to make.
Troubleshooting
- DKIM stays Pending. The DNS host appended your domain to the name, creating
<token>._domainkey.example.com.example.com. Enter the name without the domain, or add a trailing dot to the full name. - DMARC reports show SPF failing for SES mail. That’s expected without a custom MAIL FROM, because SPF is checked for
amazonses.com. DMARC still passes through DKIM; add a custom MAIL FROM if you want both. - Custom MAIL FROM setup Failed. The subdomain has more than one MX record, or the MX points at the wrong Region. Fix the record and restart the setup.
- Mail from a new Region isn’t signed. Identities and DKIM tokens are per Region. Create and verify the identity in that Region too.
- Switching from BYODKIM to Easy DKIM. SES may send unsigned mail while Easy DKIM is pending. Switch during a quiet period or test on a subdomain first.
Frequently asked questions
Do I add include:amazonses.com to my root SPF record?
No, unless you have a specific reason. SES never uses your root domain as the envelope sender. Put include:amazonses.com on the custom MAIL FROM subdomain, where receivers actually check it.
Why does SES give me three DKIM records?
Easy DKIM publishes three selectors so AWS can rotate the keys behind them without you changing DNS. Publish all three; SES doesn’t mark DKIM successful until it finds them.
Can I use the same custom MAIL FROM subdomain in several Regions?
Each Region needs its own verified identity, and the MX record points to one Region’s feedback endpoint. Use a separate MAIL FROM subdomain per Region if you send from more than one.
Is Easy DKIM enough to pass DMARC?
Yes. DMARC needs SPF or DKIM to pass with alignment, and Easy DKIM signs with your domain. A custom MAIL FROM adds aligned SPF as a backup and moves bounces onto your own subdomain.