Contenuto dal repository con titoli, esempi, codice, tabelle, link e immagini preservati.
Amazon SES
Recommended: Use the AWS MCP Server with SES permissions for sandboxed execution and CloudTrail audit logging. Without MCP: All operations use standard AWS CLI syntax (aws sesv2 ...).Overview
This skill helps developers and DevOps engineers configure Amazon SES for production email sending. It targets users who are not email authentication experts — guiding them through complete domain setup following AWS best practices without requiring deep knowledge of DKIM, SPF, or DMARC.
Routing
| If the user wants to... | Read |
|---|---|
| Set up a domain for sending, configure email authentication, or troubleshoot DKIM | Setting up SES domain identity |
Security
- Use IAM roles with ephemeral credentials (STS) — never long-lived access keys
- Scope IAM permissions to specific SES actions per workflow (see reference files for required permissions)
- Enable CloudTrail for SES API call auditing
- DMARC
p=noneis monitoring only — plan progression top=quarantineafter confirming alignment - Never hardcode credentials, endpoints, or secrets in examples
Critical Rules
- MUST create a domain identity (not email identity) for production sending
- MUST configure custom MAIL FROM subdomain for SPF alignment
- MUST configure DMARC TXT record (
p=noneminimum) for domain alignment - MUST present all DNS records together in one batch
- MUST ask user for preferred MAIL FROM subdomain (do not assume a default)
- SHOULD check if Route 53 hosts the domain and offer automatic DNS creation
- SHOULD NOT claim 72-hour wait — verification typically completes in minutes once DNS propagates

