Skip to content
Sendtier Docs

Domains and DNS

Publish six SES records and verify your sending domain.

Create a domain with a full key and copy the exact record names and values in its response. A sending key cannot add or verify a domain. SES provides three DKIM tokens. The MAIL FROM host is send.<domain> in the current SES implementation; use the returned host for your domain. Sending uses eu-central-1 only.

RecordNameValue
DKIM CNAME 1<token1>._domainkey.<domain><token1>.dkim.amazonses.com
DKIM CNAME 2<token2>._domainkey.<domain><token2>.dkim.amazonses.com
DKIM CNAME 3<token3>._domainkey.<domain><token3>.dkim.amazonses.com
Return-path MXsend.<domain>feedback-smtp.eu-central-1.amazonses.com, priority 10
SPF TXTsend.<domain>v=spf1 include:amazonses.com ~all
DMARC TXT_dmarc.<domain>v=DMARC1; p=none;

Verification rule

Call POST /domains/{domain_id}/verify. A nonempty record set is verified only when every record is valid. Failed lookups or mismatches are invalid.

CNAME and MX targets compare case-insensitively and ignore a trailing dot. The MX check compares the host, not priority. SPF must start with v=spf1 and contain include:amazonses.com. DMARC must start with v=dmarc1, case-insensitively. The checker does not require an exact DMARC policy string.

A live key that sends from an unverified domain returns 422 domain_not_verified. A test key may send from a domain this tenant has added that is not deleted, including pending and failed. Those emails are not delivered. An unknown, deleted, or other-tenant domain returns 404 not_found for both keys. That response does not ask for DNS records.

Sources: expected records and checks (internal/dns/check.go), SES identities (internal/ses/sesv2.go), domain handlers (internal/api/domains.go), send validation (internal/api/emails.go).

On this page