SPF record for Amazon SES
Last updated 2026-08-26
Amazon SES sends everything from application mail to bulk campaigns. Here is what to publish so it can do that as your domain, and what has to line up before DMARC will pass.
What to add.
include:amazonses.com in your SPF record, plus the DKIM records below.
What signs your mail. DKIM records Amazon SES generates for your account.
You verify the domain in one AWS Region and send from another, where it is still unverified. SES identities are per-region, and the console does not shout about it.
The SPF record
Add one mechanism to the SPF record on your sending domain:
In a complete record, alongside Google Workspace, that looks like:
You need this on whichever domain ends up as the envelope sender. If you leave the default MAIL FROM in place that is Amazon's own domain, not yours, and your root record does not need the include at all. If you configure a custom MAIL FROM domain, which you should, the include goes on that subdomain.
Then count your lookups. SPF allows ten DNS-querying mechanisms across the entire nested chain, and the eleventh turns the record into a permerror that authorises nothing. The record still reads correctly to a human while every check fails. Run the domain through the SPF checker after every change, because the number moves when your providers change their own records, not just when you change yours.
DKIM
Easy DKIM gives you three CNAME records with generated tokens, all of the same shape:
Publish all three. SES rotates keys behind them, so this is set-and-forget. If you have a compliance reason to hold your own private key, SES supports bring-your-own DKIM instead, and then you own rotation.
Return path and SPF alignment
Configure a custom MAIL FROM subdomain so SPF aligns. It takes two records on the subdomain, with the region matching your SES region:
The MX is how SES receives bounces for that domain. Getting the region wrong is a quiet failure: verification stays pending and nothing explains why.
DMARC alignment with Amazon SES
DMARC passes when SPF or DKIM passes and the domain it authenticated matches the domain in your visible From address. A provider can pass both checks for its own domain and leave you failing. These are the Amazon SES specifics:
- New accounts are in the sandbox and can only send to verified addresses. That is not an authentication problem, though it looks like one at first.
- Without a custom MAIL FROM, SPF authenticates
amazonses.comand only DKIM aligns. That is enough for DMARC, and it also means an SES problem takes your only aligned identifier with it. - Configuration sets with open and click tracking rewrite links, which happens before signing and is fine. A downstream gateway rewriting them again is not, and shows up as a body hash failure.
The general case is covered in alignment, explained, and the header you read to prove it is on the dmarc=fail page.
Verify it
Substitute your domain, and run these after the TTL on anything you replaced has expired:
Then send one message through Amazon SES to a Gmail address you control, open Show original,
and look for dkim=pass with your domain in header.i. That single
check is worth more than any number of DNS lookups, because it tests the thing receivers
actually do.
Our SPF checker gives you the lookup count, the DKIM checker confirms a selector resolves and the key is long enough, and the DMARC checker reads your policy back to you. All three are free and none of them ask for an account.
Values here were checked against Amazon SES's own documentation, at AWS SES developer guide. Providers change DNS requirements without much announcement, so if their screen disagrees with this page, believe their screen and tell us.
A record can read correctly and still fail alignment once real mail moves through it. Receivers write that verdict into the reports they send. We read them for you, and paid plans email you the same day one names a new sender that failed, instead of holding it for Monday. See whether this sender passes. Your first domain is free.
Watch every sender on this domain
You published records for one sender, and the domain behind it usually carries several. One weekly summary covers them all. When a report first names a new source failing, we email you the same day. Pro holds 5 domains for $19 a month.
Get the weekly digestNo card · 12+ months of history · The free plan does not expire
Questions
Does Amazon SES need include:amazonses.com in my root SPF record?
Only if your root domain is the envelope sender, which it is not under the default setup. With a custom MAIL FROM subdomain the include belongs on that subdomain's SPF record instead, which keeps your root record's lookup count down.
Keep reading
Adding this to a domain that already sends? Our SPF record generator merges the include into the record you publish today rather than replacing it, the SPF checker resolves every include and counts the lookups, and the DKIM checker confirms the selector answers.