Chapter · DMARC for Amazon SES
    Revised 17 Jun 2026
    Guide · DMARC · Amazon SES

    How to set up DMARC for Amazon SES.

    Amazon SES (Simple Email Service) is the cheapest at-scale transactional ESP. Setup is more steps than the polished SaaS ESPs but the records are stable and well-documented.

    Afsan Rahmatullah
    Afsan RahmatullahMailerMonk

    DMARC (RFC 7489) tells receiving mail servers what to do when a message claiming to be from your domain fails SPF or DKIM. You publish exactly one DMARC record at `_dmarc.<your-domain>`, regardless of which ESP you use — DMARC is a domain-level policy, not a per-sender configuration. Amazon SES doesn't run DMARC for you, but their SPF + DKIM setup is what makes your DMARC checks pass.

    Start every domain at `p=none` with a `rua` (aggregate report) address pointing somewhere you actually read. Watch the reports for two to four weeks to confirm 100% of legitimate mail is aligned, then progress to `p=quarantine` and finally `p=reject`. Skipping the monitoring step is the single most common way founders accidentally block their own mail.

    Publish these DNS records

    Add the following record(s) to your domain's DNS zone. Most registrars (Cloudflare, Route 53, Namecheap, GoDaddy) accept values exactly as shown.

    Record · TXT
    Type
    TXT
    Host
    _dmarc
    Value
    v=DMARC1; p=none; rua=mailto:dmarc-reports@your-domain.com
    Why this matters
    • SES respects the From: header for DMARC alignment when Easy DKIM and a custom MAIL FROM domain are both configured.
    • If you skip the custom MAIL FROM step, your SPF check will pass against `amazonses.com` and DMARC will fail SPF alignment. The fix is the MAIL FROM CNAME, not changing DMARC.

    Where in Amazon SES

    The DMARC configuration lives in AWS Console → SES → Configuration → Verified identities → Create identity.

    Verify the records

    Once published, run the DMARC Checker on your apex domain to confirm the record parses, reporting URIs are valid, and the policy is what you intended.

    From a terminal
    dig +short TXT _dmarc.your-domain.com
    Run the free DMARC checker

    Common pitfalls

    Pitfall
    • SES new accounts start in sandbox mode (200/day, verified-recipients-only). Production access is a manual approval — apply early.
    • SES regions are independent. A domain verified in `us-east-1` is not verified in `eu-west-1`. If you fail over regions, verify in both.
    • The custom MAIL FROM domain step is optional in the SES UI but functionally required for DMARC alignment. Don't skip it.
    After you publish

    Want to know if it actually keeps working?

    MailerMonk continuously watches your DMARC record, aggregate DMARC reports, and inbox placement — and pings you the moment something drifts. Free for the first domain.

    Start free trial

    About the author

    Afsan Rahmatullah
    Afsan Rahmatullah
    MailerMonk

    Building tools that keep cold email out of spam. Writes about deliverability, DMARC, and what actually moves inbox placement.

    Related · Amazon SES

    Other records for Amazon SES