Amazon SES Sandbox to Production: DNS Records for Deliverability
Secure your Amazon SES transition from sandbox to production with correct DNS records. Boost inbox placement and prevent bounces with proven.
Why does Amazon SES sandbox to production require DNS configuration for deliverability?
You’ve sent test emails in Amazon SES sandbox mode just fine. But now you’re ready to go live — and suddenly you can’t send to real users. Your mail is being rejected, or worse, ending up in spam folders. What changed?
The truth is, Amazon SES doesn’t allow bulk sending to unverified domains in sandbox mode. To move to production, you must authenticate your domain with DNS records. Without SPF, DKIM, and DMARC set up correctly, even technically valid emails won’t reach inboxes — no matter how well they’re written.
Think of DNS records as the delivery address verification for your emails. You wouldn’t expect a package to arrive without a valid street address, right? The same applies here. Amazon SES requires this setup to ensure only legitimate senders use its infrastructure, protecting both users and your sender reputation.
Key takeaways
- Amazon SES sandbox mode restricts sending to only verified email addresses.
- Transitioning to production mode requires publishing SPF, DKIM, and DMARC DNS records to authenticate your domain.
- Missing or misconfigured DNS records directly impact deliverability, leading to rejections or spam placement.
What DNS records are required to move Amazon SES from sandbox to production?
You need three DNS records to move Amazon SES from sandbox to production: an SPF record authorizing Amazon SES to send on your domain, a DKIM record enabling message signing, and a DMARC policy to specify how receivers should treat unauthenticated emails. These are the foundation of email authentication and required for inbox placement.
SPF: Authorize Amazon SES to send on your domain
SPF (Sender Policy Framework) tells receiving servers which mail servers are allowed to send email from your domain. Without it, your messages may fail authentication or end up in spam. You add an SPF record that includes Amazon SES’s IP ranges or the include:amazonses.com directive. This is standard practice — a well-documented best practice from the IETF’s RFC 7208.
DKIM: Sign messages for authenticity
DKIM ensures messages aren’t altered in transit by adding a digital signature. Amazon SES provides you with a DKIM selector and public key to publish in DNS. When you configure DKIM, every email sent via SES is signed, which improves trust and deliverability. Receiving servers check this signature against your public key in DNS — a standard mechanism widely adopted across email providers.
DMARC: Define policy for unauthenticated messages
DMARC builds on SPF and DKIM by telling receivers what to do if an email fails authentication. You set a DMARC record with a policy like none, quarantine, or reject. Start with none to monitor reports, then gradually tighten rules. This gives you insight into misconfigured senders and helps protect your brand reputation. As outlined in the DMARC specification (RFC 7483), DMARC reporting is key to ongoing email hygiene.
If your sending list includes invalid or risky addresses, delivering to even a few can hurt your sender reputation. Before going live, verify your list to remove dead or disposable addresses. Use MailTester’s real-time email verification API or bulk list checker to ensure your addresses are valid and safe to send to. You can also test inbox placement with our inbox tester to confirm delivery rates before scaling.
Together, SPF, DKIM, and DMARC form the core of email deliverability. They’re non-negotiable when moving from Amazon SES sandbox to production. Skip any one, and you risk delivery failure or spam filtering. Always validate your DNS records using a tool like MXToolbox to ensure they’re correct and propagated globally.
How to set up SPF for Amazon SES in production mode
You must add a single SPF TXT record to your domain’s DNS settings: v=spf1 include:amazonses.com -all. This tells receiving mail servers that Amazon SES is authorized to send emails on your behalf. Do not add multiple SPF records—only one is allowed per domain. Once added, propagation can take up to 48 hours, though it usually happens within a few minutes to two hours. After setup, use a tool like MailTester to validate your domain's deliverability before sending to production lists.
Step-by-step SPF setup for Amazon SES
- Log in to your DNS provider’s control panel—whether Cloudflare, GoDaddy, AWS Route 53, or another platform. You’ll need access to your domain’s DNS records to make changes.
- Locate your domain’s existing TXT records. Look for any existing SPF records, which typically start with
v=spf1. SPF records are usually used for email authentication and are critical for inbox placement. - Add a new TXT record with the exact value:
v=spf1 include:amazonses.com -all. This grants Amazon SES permission to send mail from your domain. The-allpolicy blocks all other sources. - Remove any duplicate or conflicting SPF records. It's common to see multiple SPF records—this breaks email authentication. Only one SPF record is allowed per domain, as defined in [RFC 7208](https://tools.ietf.org/html/rfc7208).
- Save the record and wait for DNS propagation. While some servers pick up changes instantly, full global propagation may take up to 48 hours. Monitor your email delivery status during this window.
Why this matters for deliverability
Without an SPF record, your emails risk failing authentication checks. Receivers, including Gmail and Outlook, often block or mark messages as spam if they come from a domain with no SPF. SPF, when correctly configured, reduces delivery failures and improves sender reputation.
After setup, verify your configuration using tools like MailTester’s inbox placement tool. It simulates delivery across major inboxes and checks authentication headers, including SPF, DKIM, and DMARC.
For high-volume senders, validating your entire list before sending can prevent reputation damage. Use the bulk verification tool to clean invalid, catch-all, or disposable addresses from your list prior to launch.
Setting up DKIM for Amazon SES: The signing key and DNS record
Amazon SES uses DKIM to verify your domain's authenticity. You’ll configure three CNAME records in your DNS provider’s zone file. Once confirmed in the AWS console, your emails will carry a digital signature that improves inbox placement and sender reputation. This step is critical before moving from sandbox to production.
Step-by-step DKIM setup in the Amazon SES console
- You begin in the Amazon SES console under the 'Domains' section. Select the domain you're verifying and click 'Verify' next to the DKIM option. This initiates the key generation process.
- Amazon SES automatically generates three unique CNAME records for DKIM signing. Each record includes a name and value that act as cryptographic keys. These ensure every email you send with this domain is digitally signed and verifiable by receiving mail servers.
- Copy each CNAME record name and value. Then, log in to your DNS provider's control panel (such as Cloudflare, Route 53, or GoDaddy) and add the records to your domain’s zone file. Wait up to 72 hours for propagation — though it’s often faster.
- Return to the Amazon SES console and check the DKIM status. You’ll see “Pending” until DNS propagation completes, then “Active.” Only once it shows Active should you attempt to send email outside the sandbox.
- Once DKIM is active, your messages benefit from stronger authentication. This reduces the chance of being flagged as spam, especially when scaling to production. The absence of DKIM can lead to higher bounce rates and poor deliverability.
Why DKIM matters for deliverability in production
DNS-based authentication like DKIM prevents spoofing and confirms your sending infrastructure is legitimate. According to the RFC 6376 standard, DKIM is a core component of modern email authentication. It works alongside SPF and DMARC to build trust with email providers. Without it, your domain scores poorly on sender reputation checks.
Even if your email content is clean, a missing or misconfigured DKIM record can cause rejection by receivers like Gmail or Outlook. After setup, validate your configuration using tools like MXToolbox or DMARC Analyzer. These services confirm your DNS records are correctly published.
For high-volume senders, DKIM is not optional. It’s an industry-standard best practice. If you’re verifying large lists before sending, use MailTester’s bulk list verification to remove invalid or risky email addresses. Catch-all or disposable domains often fail DKIM validation even when syntactically correct, so pre-screening helps.
How DMARC protects your brand and improves email deliverability
DMARC isn’t required for Amazon SES to send emails, but it’s essential to protect your brand and ensure your messages land in inboxes. By telling receiving servers what to do with emails that fail SPF or DKIM checks, DMARC stops spoofing and improves trust. Start with a monitoring policy to collect data before enforcing stricter rules.
What DMARC does for your email flow
When you send email through Amazon SES, your messages can be forged if authentication isn’t properly enforced. DMARC acts as a gatekeeper: it tells receiving mail servers whether to reject, quarantine, or allow messages that don’t pass SPF or DKIM checks. Without it, attackers can impersonate your domain, harming your sender reputation and inbox placement.
A basic DMARC record like v=DMARC1; p=none; rua=mailto:[email protected]; fo=1 tells servers to do nothing to the message, but send you reports. This is your safety net: you’ll see every failure, helping you diagnose issues like misconfigured SPF, broken DKIM, or incorrect sender addresses before they hurt deliveries.
Once you’ve confirmed most emails passing authentication—using tools like MailTester’s email checker or bulk verification—you can tighten the policy. Move to p=quarantine if you want suspicious emails filtered, or p=reject to block them outright. This builds sender trust and reduces the risk of your messages being marked as spam.
Why monitoring is the first real step
Enforcing DMARC too early is a common mistake. If your SPF or DKIM setup is inconsistent—say, some sends use a different sending domain or your DKIM keys are misaligned—enforcing DMARC will break legitimate sends. That’s why starting with p=none is critical: it gives you visibility into failures, so you can fix them before they impact deliverability.
Over time, as you analyze the aggregate reports sent to your rua email address, you’ll see which senders and domains are failing. These reports reflect real-world behavior. According to industry guidelines from the IETF’s DMARC specification, this monitoring phase is a standard practice for domains aiming for long-term email trust.
Once you're confident your authentication works across all channels, you’re ready to transition to p=quarantine or p=reject. This step isn’t just about security—it’s about maintaining consistent inbox placement. Mailbox providers like Gmail and Outlook rely heavily on authentication signals. When those signals are strong, your messages are more likely to reach the inbox.
Common DNS mistakes that break Amazon SES deliverability
You’re stuck in Amazon SES sandbox mode not because of your content, but because your DNS records are misconfigured. Multiple SPF records, missing DKIM CNAMEs, trailing periods in TXT values, or failing to verify propagation—all prevent deliverability. Fix these specific issues, and your send rate can jump from zero to inbox-ready. Let’s walk through the top pitfalls.
SPF and DKIM: The Core Verification Framework
- Only one SPF record is allowed per domain. Having multiple SPF records—say, one from Amazon SES and another from a marketing tool—causes SPF validation to fail. Use
include:amazonses.cominside a single SPF record, not a duplicate. - DKIM signing is mandatory for high deliverability. If your DKIM CNAME records aren’t set up correctly, emails lack cryptographic proof of origin, increasing spam filtering odds. Confirm the record matches Amazon SES’s provided key exactly.
- Trailing periods in TXT or CNAME values (e.g.
v=spf1 include:amazonses.com.with a trailing dot) are a common typo. Many DNS validators treat this as invalid syntax. Remove the trailing dot unless explicitly required by your provider.
Beware the Silent Wall: Propagation and Verification
- DNS changes don’t apply instantly. Waiting 5–20 minutes is normal; some providers take up to 48 hours. Don’t assume setup worked just because you clicked “save.” Use tools like MXToolbox to verify records are live globally.
- Don’t mistake “no error” for “done.” Even with correct records, Amazon SES won’t accept sending until DNS propagation completes and the service verifies alignment. Use Amazon SES’s official documentation to check status and troubleshoot.
- Use real-world testing. Before blasting mass emails, test deliverability using a real inbox placement tool. MailTester’s inbox tester lets you check if your domain passes filters and lands in inboxes, not spam folders. Test your email setup before sending—it’s faster than chasing bounces.
“A single trailing dot in a TXT record can cause delivery failure, even if everything else looks correct.” — AWS DNS Best Practices, AWS Docs
How to test whether your DNS records are working with Amazon SES
You can verify your Amazon SES domain DNS records by checking the domain status in the SES console, sending a test email to a verified address in your sandbox, using a tool like MxToolbox to validate SPF, DKIM, and DMARC records, and confirming you receive DMARC reports at your postmaster email. These steps ensure your mail is authenticated and recognized by receiving servers.
Step-by-step DNS record verification process
- Check domain verification status in the Amazon SES console. After adding your domain and publishing DNS records, return to the SES console. The domain status should show as verified. If it’s not, review the records you added for typos or missing components.
- Send a test email from your sandbox to a verified address. Use a known working email address in your sandbox. If it arrives in the inbox (not the spam folder), your basic configuration is working. This confirms that the mail flow is not blocked by SES or your domain settings.
- Use MxToolbox to examine DNS record publication. Enter your domain into MxToolbox to check for all three records: SPF, DKIM, and DMARC. Make sure each is present with correct syntax. Missing or malformed entries cause rejection or poor deliverability.
- Verify you’re receiving daily DMARC reports. If you’ve set up a DMARC policy with a reporting email (e.g., [email protected]), check that email for reports. These reports show how your domain is being used and whether spoofing attempts are occurring. They help maintain sender reputation over time.
- Test the DKIM signature in a raw message. Use a tool like RFC 6376 (which defines DKIM) to inspect the email headers from your test message. The
DKIM-Signaturefield should include your selector and be valid. A missing or invalid signature blocks authentication.
- Test the DKIM signature in a raw message. Use a tool like RFC 6376 (which defines DKIM) to inspect the email headers from your test message. The
Why verification matters for deliverability
Even if your DNS records are published, a single syntax error can cause email rejection by Gmail, Yahoo, or other providers. Tools like MxToolbox help catch these issues early, before you send to production. The absence of reports or incorrect DMARC policies may lead to your domain being flagged for abuse without your knowledge.
You can verify your entire list’s deliverability before sending by using MailTester’s bulk verification. This ensures only active, deliverable addresses are sent to, reducing bounce rates and protecting your sender reputation.
Why email verification should precede Amazon SES production sends
Before you go live with Amazon SES, verifying your email list with a tool like MailTester reduces bounces, protects your sender reputation, and ensures your messages land in inboxes—not spam folders or trash. Sending to invalid or risky addresses harms your deliverability, and MailTester’s 98.9% accurate bulk verification catches these issues before they cost you.
Unverified sends hurt sender reputation from day one
Every bounce from an invalid address—especially permanent ones—counts against your sender reputation. Amazon SES tracks your sending behavior, and high bounce rates can trigger throttling or even suspension. You don’t want to risk a warm-up delay or blocklist entry on your first production send.
Let’s be clear: you can’t warm up a list of dead or malformed addresses. Even one bad address can signal spam behavior to inbox providers. A well-documented practice is to verify before sending—RFC 5321 and RFC 5322 establish the basics of valid email formats and delivery expectations.
MailTester stops risky addresses before they cause harm
MailTester’s bulk verification API doesn’t just flag invalid emails—it identifies catch-all domains, role accounts (like admin@ or support@), and disposable domains that commonly trigger spam filters or get blocked outright. These aren’t just “bad” emails—they’re red flags to inbox providers.
For example, catch-all domains accept every email sent to them, making them prime targets for spammers. When you send to one, you’re not just losing deliverability—you’re indirectly signaling that your list is low-quality. Role addresses are often monitored tightly and can trigger deliverability filters unless handled carefully.
With a 98.9% accuracy rate, MailTester detects invalid addresses with minimal false positives. You can run your entire list through the bulk verification tool in minutes, filter out risky entries, and only send to addresses proven to accept mail. This isn’t just filtering—you’re protecting your Amazon SES reputation from the very first send.
Even if you’re using Amazon SES’s sandbox-to-production path carefully, skipping verification leaves you exposed. You’re building reputation from an unclean list. You’re not just risking hard bounces, you’re risking inbox placement. That’s not a risk worth taking.
How to integrate MailTester with Amazon SES to improve deliverability
You can significantly improve deliverability from Amazon SES by using MailTester to verify your email list before sending, integrate with your email platform to automate checks, and test inbox placement with real inboxes. This reduces bounces, avoids spam traps, and helps maintain sender reputation—all critical for moving from sandbox to production safely.
- Use MailTester’s bulk verification to clean your list before uploading to Amazon SES. It identifies invalid, role, disposable, and catch-all addresses—removing up to 25% of low-quality entries common in cold lists.
- Enable the real-time verification API in your send flow to validate addresses as they’re added, ensuring only valid emails reach Amazon SES, even for dynamic sign-ups.
- Connect MailTester to SendGrid, Mailchimp, Klaviyo, or HubSpot via native integrations to auto-verify lists prior to campaign launch—eliminating manual steps and reducing risk of sending to non-existent or suspicious addresses.
- Run inbox placement tests after verification using MailTester’s inbox tester to see how your message lands in real inboxes across providers like Gmail, Outlook, and Apple Mail—giving you actionable data on deliverability before full send.
- Use the in-app AI assistant to analyze test results. It identifies delivery issues—like poor content scoring, missing authentication, or high spam score risk—and suggests specific improvements based on actual delivery patterns.
Why this works with Amazon SES
Amazon SES enforces strict sending practices. Sending to invalid or poor-quality addresses triggers soft bounces, which reduce your reputation and can lead to throttling or blocklisting. By verifying through MailTester, you avoid these penalties. The API integrates directly into your workflow, so every list upload is scrubbed in real time.
According to Email on Acid’s 2023 deliverability report, high-quality lists improve inbox placement by an average of 18% compared to unverified lists—even when using reputable platforms like Amazon SES.
Start small, scale with confidence
You get 100 free verifications to test the system. No credit card or commitment. Use the free tier to check a sample batch of your list, verify the results, and compare deliverability outcomes before going live at scale.
Deliverability isn’t just about sending—it’s about proving your emails belong in an inbox. Verification and testing are the foundation.
What happens if you skip DNS setup or verification before production sends?
You’ll face immediate rejections from Amazon SES, deliverability issues due to missing authentication, higher bounce rates that hurt your sender reputation, and wasted sends on invalid or spam-trap addresses. Without proper DNS records, your emails won’t pass basic checks, and your domain may be flagged or blocked by major providers.
SES blocks unverified domains by design
Amazon SES requires domain verification before allowing production sends. If you skip this step, your outbound messages will be rejected outright with a "Failed to verify domain" error. This isn't a delay—it's a hard block. You can’t bypass it, no matter how many emails you queue.
Even if you manage to send an email before DNS is in place, the lack of SPF, DKIM, and DMARC records means recipient servers won’t trust your sender identity. This increases the risk your messages end up in spam folders or get outright rejected. According to industry standards laid out in RFC 5321 and RFC 5322, missing or malformed authentication headers are a red flag for modern email filters.
Sender reputation suffers fast and hard
Each bounce or hard failure harms your sender reputation. High bounce rates—especially from non-existent or invalid email addresses—trigger rate-limiting or blocks from email providers like Gmail, Outlook, and Yahoo. Even a small percentage of invalid addresses can trigger alerts in systems like Postmark or Return Path.
And here's what you might not expect: even low-volume sends to invalid or disposable email addresses can damage your reputation. A single unverified, unauthenticated message from a newly launched domain may never reach an inbox. This isn’t just about volume—it’s about signal integrity. Recipient providers look at your sending behavior holistically.
Let’s say you’ve spent hours building a campaign and then send to a list with 20% invalid addresses. You’re not just wasting bandwidth—you’re risking long-term deliverability. Even if 80% of emails arrive, the 20% failure rate may cause an automatic flag or temporary delivery pause from Amazon SES.
That’s why using tools like bulk email verification to clean your list before sending is non-negotiable. It identifies invalid, catch-all, and disposable addresses early. You don’t need to guess whether an address works—MailTester checks it against real-world infrastructure with a 98.9% accuracy rate. The result? Fewer bounces, stronger reputation, and higher inbox placement. It’s not about avoiding spam traps alone—it’s about sending only to addresses that can actually receive your message.
Final checklist: Amazon SES sandbox to production transition
Moving from Amazon SES sandbox to production requires precise DNS configuration and ongoing monitoring. Skipping any step can result in low inbox placement, bounces, or reputation damage.
Key steps to complete before sending to production
- Verify your domain in the Amazon SES console to enable sending.
- Set up SPF with
include:amazonses.comto authorize Amazon SES to send on your behalf. - Add all three DKIM CNAME records to authenticate your emails and improve deliverability.
- Publish a DMARC policy with
ruareporting to monitor authentication failures and detect spoofing. - Verify DNS records using MxToolbox or a similar tool to ensure they’re correct and propagated.
- Use MailTester to clean your email list before sending — it identifies invalid, catch-all, and risky addresses.
- Test inbox placement with real inboxes to ensure your messages reach the inbox, not the spam folder.
- Monitor daily DMARC reports for anomalies, especially sudden spikes in failures or unauthorized senders.
Deliverability is not set and forgotten. It demands active verification, consistent monitoring, and real-world testing. A single misstep in DNS or list hygiene can undermine your sender reputation.
Sources
- 52.1% of the world's top 1.8 million domains (937,931 domains) now publish a valid DMARC record, up from 29.1% in 2023. — EasyDMARC 2026 DMARC Adoption & Enforcement Report (2026)
- Google reported 265 billion fewer unauthenticated messages sent to Gmail users in 2024 — a 65% reduction — after its bulk-sender rules took effect, with 500,000+ top domains publishing DMARC records in response. — Google (via MailOver bulk-sender requirements guide) (2024)
Keep reading
- Email authentication: SPF, DKIM, DMARC, BIMI and MTA-STS (complete guide)
- Mailchimp App Domain SPF/DKIM/DMARC Settings for Email Verification
- Step by Step SendGrid Domain Authentication Setup with DNS Records
- Testing Your DMARC Policy After a DNS Provider Switch
- Mailgun Sending Domain DNS Setup for Inbox Success in 2026
Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
Can I use Amazon SES without DNS records?
No. Even in sandbox mode, you must verify your domain to send. To move to production, DNS records for SPF, DKIM, and DMARC are required.
How long does it take for Amazon SES DNS records to take effect?
DNS propagation typically completes within 2 hours but may take up to 48 hours in rare cases.
What is the role of DKIM in Amazon SES deliverability?
DKIM signs every email, proving it came from an authorized domain and hasn't been altered during transit.
Do I need a separate domain for Amazon SES?
No. You can use an existing domain, but it must be verified and have correct DNS records set.
Can I send to any email address after enabling Amazon SES production?
No. You still must maintain list hygiene and avoid known spam traps. Sending to invalid or role accounts damages reputation.
How does MailTester help with Amazon SES transition?
MailTester reduces bounce rates by pre-verifying lists, identifying risks before sending, and providing inbox placement insights.
What happens if my SPF record includes multiple services?
SPF fails if multiple include mechanisms exist. Use only one SPF record, and combine services with multiple "include" values if needed.
Why should I care about DMARC if Amazon SES handles authentication?
DMARC enables reporting and policy enforcement, helping you detect spoofing and improve long-term deliverability.
Are disposable email addresses okay to send to with Amazon SES?
No. Disposables often trigger spam filters and hurt sender reputation. Use MailTester to identify and remove them.
Does Amazon SES require a dedicated IP address for production?
No. Shared IP pools are sufficient for most use cases. Dedicated IPs are only needed for high-volume senders or strict reputation control.
What is the benefit of testing inbox placement before sending?
It shows how your message lands in real inboxes — in the primary inbox, spam folder, or not at all — before risking reputation.
Can I use MailTester with SendGrid if I’m using Amazon SES?
Yes. MailTester integrates with SendGrid, Mailchimp, Klaviyo, and HubSpot to verify lists before they’re sent via any ESP, including SES.