Why migrate from Mailgun to Amazon SES in 2026?

You’re sending 100,000 emails a month. Your Mailgun bill hits $1,200. You check the dashboard and see AWS offers the same deliverability for under $200. Why are you still paying more?

Migrating from Mailgun to Amazon SES isn’t about chasing hype. It’s about cost efficiency, tighter automation, and avoiding paywalls as your volume grows. In 2026, for high-volume senders, SES isn’t just an alternative—it’s the practical choice.

You’re not just switching email providers. You’re rethinking how your sends integrate with your infrastructure. If you’re using AWS already, SES is built-in. No extra middleware. No surprise fees. Just predictable pricing and deep service integration.

Key takeaways

  • Amazon SES charges less per email than Mailgun at scale, with no setup fees, making it ideal for high-volume transactional and marketing sends.
  • SES integrates natively with AWS services like Lambda, CloudWatch, and S3, enabling automated workflows without third-party tools.
  • Mailgun’s pricing model can become cost-prohibitive over time, especially for transactional-heavy workloads, while SES scales efficiently and predictably.

What’s the first step in migrating from Mailgun to Amazon SES?

You start by analyzing your current Mailgun sending volume and deliverability performance using historical data. This helps you understand your baseline—how many emails you send daily, your bounce and complaint rates, and how often messages land in inboxes versus spam. Without this, you can’t measure success post-migration. It also reveals potential pain points like high spam complaints or throttling issues.

Assess your current Mailgun sending volume and deliverability

  • Export your Mailgun delivery logs for the past 30–90 days. Look for consistent volume patterns, bounce types (hard/soft), and complaint rate trends.
  • Check if your sender reputation is clean. High complaint rates or frequent hard bounces can impact your SES warm-up success.
  • Use tools like Spamhaus to verify your sending IP isn’t blacklisted in your current setup.
  • Validate the quality of your email list using a service like MailTester’s bulk verification—clean lists reduce risk during migration.

Prepare your AWS and DNS environment

  • Sign in to your AWS account and navigate to Amazon SES. Choose the region where you’ll send emails (e.g., us-east-1).
  • Verify your sending domain in SES using the verification wizard. This requires adding a CNAME or TXT record to your DNS zone.
  • Ensure all DNS records are correctly propagated. You can check this using tools like MXToolbox or the AWS SES health dashboard.
  • Set up an IAM user with programmatic access. Attach the AmazonSESFullAccess policy (or a least-privilege custom policy) to allow application-level access.
  • Store the access key and secret securely. Never hardcode these in production applications.

Once your domain is verified and your IAM credentials are ready, you’re set to begin the actual migration process. This groundwork ensures your SES configuration aligns with your current delivery needs and avoids unexpected failures early on.

How do you set up Amazon SES for sending emails?

You sign in to the AWS Console, go to Amazon SES, verify your domain or email address, wait for DNS propagation (up to 72 hours), and then configure sending limits. Start low—50–100 messages per day—and increase gradually to build sender reputation. This protects against being flagged as spam.

Step-by-step setup in the AWS Console

  1. Sign in to the AWS Console. Navigate to the Amazon SES service. If you're new, you'll need to enable the service in your AWS account.
  2. Verify your sending domain or email address. SES requires verification to prevent abuse. Enter your domain (e.g., yourcompany.com) or a specific email ([email protected]). SES will generate DNS TXT records you must add to your domain's DNS zone.
  3. Wait for DNS propagation. DNS changes can take up to 72 hours to fully propagate across the internet. You can confirm completion using tools like MxToolbox or dnschecker.org. Propagation is complete when the record appears globally.
  4. Set up sending limits. After verification, enable your account for sending. You’ll start in the "sandbox" environment, limited to 200 messages per 24 hours to 50 recipients. For full access, request production access with a detailed business use case. Begin with low volume to avoid triggering abuse filters.
  5. Ramp up gradually. Many senders report that sudden spikes in volume—especially without prior warm-up—lead to deliverability issues. Start with under 50 emails per day, monitor bounces and complaints, and scale up as your sender reputation stabilizes.

Why sender reputation matters more than speed

Amazon SES tracks your sending behavior closely. High volume early on, especially with poorly engaged recipients, can lead to your IP being throttled or blacklisted. This isn’t just theory—industry standards like RFC 6655 define how ISPs evaluate sender trustworthiness.

Consider using a real-time verification service to filter out invalid or risky addresses before sending. You can test your list with MailTester’s bulk verification to detect expired domains, role addresses, or catch-alls that may harm your sender reputation.

What DNS records are required for Amazon SES setup?

You need three types of DNS records to set up Amazon SES for sending: an SPF record with include:amazonses.com, three DKIM CNAME records provided by AWS, and an MX record only if you're also receiving email. SPF and DKIM authenticate your domain; MX is optional for sending-only use.

SPF: Authenticate Your Sending Domain

SPF (Sender Policy Framework) tells receiving servers which servers are authorized to send email on your domain’s behalf. For Amazon SES, you must include include:amazonses.com in your SPF record. If you use other services like Mailgun or SendGrid, combine them using include mechanisms, but avoid exceeding the 10 mechanism limit. The full record might look like v=spf1 include:amazonses.com ~all, where ~all soft-fails unlisted senders.

Use tools like MXToolbox’s SPF Checker to validate your record before deployment. Incorrect SPF can cause bounces or deliverability issues.

DKIM: Verify Message Integrity

DKIM adds a digital signature to each outgoing email, proving it wasn’t altered in transit. AWS provides three CNAME records for your domain to enable DKIM. These records are unique to your account and must be added exactly as shown in the AWS Console. After setup, they take effect within minutes to a few hours.

Keep these records active. Removing them breaks DKIM verification, which harms sender reputation. Most ESPs, including Amazon SES, expect DKIM to be enabled when using custom domains. For verification, use MailTester’s email checker to validate if your domain’s DKIM signing is working post-setup.

MX Record: Only for Receiving Mail

MX (Mail Exchange) records direct incoming mail to your mail server. You only need them if you’re using Amazon SES to receive inbound emails—such as handling replies or form submissions. If you’re only sending emails, skip MX records entirely.

Leaving them out doesn’t affect sending. You can add them later if you enable inbound mail processing. The SMTP RFC 5321 defines the standard behavior of MX records, but AWS documentation provides exact details for SES inbound setup.

How do you ensure deliverability during the migration switch?

You reduce inbox placement risk by running both Mailgun and Amazon SES in parallel for 14 to 30 days. This allows you to compare deliverability, detect bounces or complaints early, and gradually warm up your new SES domain—avoiding sudden spikes that trigger spam filters. Monitor sender reputation on both sides and use real-time data, not assumptions.

Protect your sender reputation during the transition

  • Don’t cut over immediately. Keep both Mailgun and SES sending simultaneously for 14–30 days to compare inbox placement results side by side.
  • Use Amazon SES’s built-in bounce and complaint tracking to monitor delivery failures and user-reported spam in real time.
  • Set up alerts for spikes in hard bounces or complaints—these are early signs of deliverability issues.
  • Enable feedback loops (FBLs) if available through your email provider or inbox placement tools.

Warm up your new Amazon SES domain properly

  • Start sending only 100–500 emails per day on your new SES domain for 3–5 days to build sender trust with ISPs.
  • Gradually increase volume by doubling or tripling your daily sends each day—never jump to full volume too fast.
  • Send only to engaged users. A high engagement rate helps signal a healthy relationship with ISPs.
  • Verify recipient addresses before sending with a real-time email checker to reduce invalid or toxic addresses.

Even after migration, keep a test email list ready to validate inbox placement. Use inbox placement testing tools to simulate real-world delivery and confirm your new SES setup delivers reliably across Gmail, Outlook, and other inbox providers.

The goal isn’t to mimic Mailgun’s setup—it’s to build a new, trusted, and sustainable sending path. According to industry-standard practices, inconsistent send patterns or rapid volume increases are common causes of spam filtering. Let’s avoid those. Use SES’s metrics, verify your list, and let your sending pattern evolve naturally.

How can you test inbox placement before going live with SES?

You can test inbox placement before going live with Amazon SES by sending real test emails through a trusted service like MailTester’s inbox-placement tester. This sends your email to actual inboxes at Gmail, Outlook, and Yahoo, letting you see if it lands in the inbox, gets flagged as spam, or is blocked outright—based on real recipient behavior, not just sender reputation or DNS checks. This prevents surprises after migration.

Simulate real-world delivery behavior

When you migrate from Mailgun to Amazon SES, your new sender reputation, domain policy, and message headers don’t just affect deliverability—they shape how your message is received. Use MailTester’s inbox-placement tool to send a representative sample of your emails directly to Gmail, Outlook, and Yahoo. These aren’t automated test accounts; they’re real mailboxes monitored by the providers themselves, so results reflect what your audience will see.

This lets you catch early issues like content triggers that flag your email as spam, misconfigured headers, or unintended reputation drops. For example, a missing or inconsistent SPF/DKIM alignment can trigger filtering even if your domain is verified. MailTester’s reports show not just placement (inbox or spam), but why—highlighting header problems, sender reputation risks, or content red flags that might not show up in a standard bounce test.

Let’s say your email lands in spam. The report will tell you if it’s due to a flagged subject line, high spam score, or poor authentication setup. You can address each issue before going live with your full list. This step is critical—especially when switching from Mailgun to SES, where you're now managing your own IP reputation.

For deeper verification, combine inbox placement testing with pre-send validation. Use the MailTester email checker to clean your list first, removing invalid, role, or disposable addresses. Then run deliverability scans via the inbox placement tester to simulate what happens after the migration. This two-step process reduces failure risk and saves time on troubleshooting post-launch.

Industry standards like those from RFC 5322 define email formatting rules, but real inbox placement depends on how receivers interpret your message. Testing with real inboxes—before you send to thousands—is how you avoid reputation damage. It’s not about technical perfection; it’s about confirming your message reaches the intended user, not the spam folder. For more context on sender reputation and email standards, refer to Spamhaus’ public data on blocklist trends.

How do you verify your email list before switching to Amazon SES?

Before migrating to Amazon SES, use MailTester’s bulk list verification to filter out invalid, disposable, and role-based email addresses. This reduces bounce rates, prevents spam complaints, and improves sender reputation—key for landing in inboxes instead of spam folders. A clean list means fewer delivery failures and better sender metrics, which Amazon SES tracks closely.

Step 1: Remove invalid and high-risk addresses

  • Run your entire email list through MailTester’s bulk verification tool to flag invalid or non-existent addresses. This catches typos, deleted accounts, and syntax errors before they cause hard bounces.
  • Automatically filter out disposable email domains—like tempmail.org or yopmail.com—using MailTester’s database of known ephemeral providers. These domains rarely lead to engagement and damage sender reputation.
  • Identify and remove role-based addresses (e.g. sales@, admin@, info@) that are often used for bulk sends but rarely opened, increasing spam complaint risk.

Step 2: Reduce risky and catch-all addresses

  • Filter out catch-all addresses, which accept all incoming mail regardless of recipient. These cause high bounce rates and are often flagged as spam traps. MailTester detects these with high precision (98.9% accuracy).
  • Remove addresses marked as "risky" due to known spam trap indicators or poor engagement history. These are especially damaging when sending to Amazon SES, which monitors for sender abuse.
  • Verify deliverability with real inbox testing. Use MailTester’s inbox placement tester to simulate message delivery and ensure your emails reach the inbox, not spam, across major providers like Gmail and Outlook.

Industry standards, like those from Return Path and RFC 5322, emphasize the importance of list hygiene to maintain sender reputation and avoid filtering. A single high-volume bounce or spam complaint can trigger rate limiting or suspension.

MailTester’s API lets you automate verification in your workflow. Whether you're onboarding via Mailchimp, HubSpot, or Klaviyo, you can verify addresses in real time. You start with 100 free verifications—no risk, no expiration on purchased credits.

What integrations work with Amazon SES and MailTester?

You can use MailTester to verify email lists before sending through Amazon SES, and it integrates natively with platforms like Mailchimp, Klaviyo, HubSpot, and SendGrid for automated verification workflows. SES itself works with custom SMTP apps, AWS Lambda, and third-party tools via its API, allowing flexible, scalable email delivery. Verifying addresses in real time—before hitting SES—catches invalid, catch-all, or risky emails early, improving deliverability.

How MailTester fits into your SES workflow

When you’re migrating from Mailgun to Amazon SES, you still need to validate your list. MailTester plugs into your existing setup via API or bulk upload, checking each address in real time—not just syntax, but if the mailbox exists, if it’s a role account, or if it’s on a blocklist. This step stops bounces before they happen.

Use the MailTester Verification API to embed verification directly into your application or automation. For marketing platforms, the MailTester integrations with Klaviyo, Mailchimp, and HubSpot ensure your subscriber lists stay clean at every touchpoint.

SES compatibility and setup flexibility

Amazon SES supports sending through SMTP clients, HTTP APIs, and serverless functions like AWS Lambda—perfect for developers who need programmatic control. It also integrates with major tools like Salesforce and Zapier. Unlike some legacy services, SES doesn’t require shared IPs or complex configuration for high-volume sends.

For example, using SES with Lambda means you can trigger verification and delivery in a single event-driven flow. While SES doesn’t provide built-in verification, combining it with a tool like MailTester is the industry-standard way to maintain sender reputation and inbox placement. The AWS SES documentation stresses the importance of list hygiene, especially during migrations.

Let’s be clear: you can't rely solely on SES to catch invalid addresses. Sending to a catch-all or disposable address wastes send credits and harms your reputation. Using MailTester’s real-time email checker before sending helps avoid this. A single check costs pennies, but the cost of a failed delivery or a blocked IP is much higher.

How do you monitor sender reputation with Amazon SES?

You monitor sender reputation in Amazon SES by using CloudWatch to track real-time sending metrics like bounces, complaints, and delivery rates. Combine this with inbox placement testing to confirm whether emails land in inboxes—critical after migrating from Mailgun. This gives you visibility into both technical performance and real-world deliverability.

Set up real-time monitoring with CloudWatch

  • Enable Amazon SES sending statistics in CloudWatch immediately after setup; it’s built into the service.
  • Set up alarms for spikes in bounce or complaint rates—anything above 0.1% complaints or 1% bounces per domain should trigger investigation.
  • Monitor delivery rates per domain or IP; sudden drops signal issues like new blocks or poor content filtering.

Validate inbox placement with real-user testing

  • Run inbox placement reports using real email addresses across major providers (Gmail, Outlook, Yahoo).
  • Test emails in environments that mirror your audience—use MailTester’s inbox placement reports to see if your content lands in the inbox, spam, or trash.
  • Compare results before and after migration from Mailgun to identify regressions early, as reported in industry best practices by Mimecast’s deliverability guide.
  • Use these reports to adjust email content, frequency, or list hygiene—some deliverability issues stem from behavioral signals, not just technical ones.
  • Recheck your sender reputation monthly or after major campaigns to catch drift before it impacts deliverability.

Don’t rely on CloudWatch alone. While it tracks what the server reports, inbox placement reports show what users experience. That distinction is crucial when you're migrating services, where reputation can shift subtly.

Use a tool like MailTester’s inbox placement testing to send test emails to real inboxes and validate deliverability across providers—no guesswork, just results. You’ll catch issues with content, sender reputation, or infrastructure before your next campaign.

What are common mistakes during migration to Amazon SES?

Many teams jump into Amazon SES without properly configuring DKIM, sending too aggressively from day one, or launching full campaigns without inbox testing—each of these can trigger spam filters, throttle limits, or outright suspension. You’re not just switching providers; you're resetting your deliverability foundation.

Skipping DKIM setup weakens sender reputation

Amazon SES requires you to set up DKIM to authenticate your outbound emails, and skipping this step means your messages lack cryptographic proof of origin. Without it, inbox providers are more likely to flag your emails as suspicious or spoofed, especially if you’re sending to domains that enforce strict authentication policies. According to the DMARC.org technical documentation, domains using DMARC with strict policies often reject unauthenticated mail—even if it’s technically valid. You don’t need to trust Amazon’s default alignment; it’s better to validate your own signing process.

Speeding up too fast triggers throttling or suspension

Amazon SES enforces sending limits based on your account’s reputation and volume history. Starting with high-volume bursts—especially during initial migration—can trigger throttling within minutes. Even if you’ve completed setup correctly, sudden spikes in delivery rate signal behavior resembling spam. The best practice is to start small: send a few hundred emails per day, monitor bounce and complaint rates, then scale gradually. This is where tools like MailTester’s inbox placement tester can show exactly where your emails land in real inboxes before you fully deploy.

Skipping real inbox testing risks full campaign failure

Just because an email passes DNS checks doesn’t mean it lands in the inbox. Many migrations fail not because of misconfigurations, but because the content or sending patterns don’t align with the actual filtering behavior of Gmail, Outlook, or Apple Mail. Without real-world testing, you might assume everything works—until your first promotional campaign lands in spam or is silently filtered. Let’s say you’re migrating your transactional system: test it in actual client inboxes before going live. Use tools that simulate real user behavior, not just server-level validation. You can preview how your message appears across platforms, and catch formatting or content issues early. A single ignored complaint can hurt your reputation more than a thousand failed SMTP connections.

Why is list hygiene critical when migrating from Mailgun to AWS SES?

Invalid or dormant email addresses increase bounce rates, which directly impacts sender reputation. AWS SES monitors sending behavior closely, and sustained high bounce rates can trigger throttling or hard bounces.

Disposable or role-based addresses (like admin@ or info@) are commonly filtered or rejected by receivers. These addresses don’t represent real users and can lower engagement metrics, which affects inbox placement across platforms.

A clean, verified list improves deliverability, reduces the risk of blacklisting, and boosts open rates—critical for maintaining performance during and after migration.

Sources

Keep reading

Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

Can I use Amazon SES without using AWS?

Yes — you can send via SES using any SMTP client or third-party tool, as long as you have valid credentials and DNS records set up.

How long does DNS propagation take after setting up SES?

DNS changes typically propagate within 24–72 hours. Use tools like MxToolbox to verify propagation status.

What happens if my SES account gets throttled?

SES throttles send rates to prevent abuse. You must reduce volume, wait 24 hours, or request higher sending quotas via AWS Support.

Is Mailgun still better than SES for small senders?

For low volumes and ease of use, Mailgun may feel more beginner-friendly. But SES offers better pricing and transparency at scale.

Do I need to re-verify my domain after migrating?

Yes — you must verify the sending domain in Amazon SES, even if it was verified in Mailgun.

Can I use MailTester with AWS SES and other ESPs?

Yes — MailTester supports integration with SendGrid, Klaviyo, Mailchimp, and HubSpot, and offers real-time API verification for any sending platform.

What is the best way to warm up a new SES domain?

Start with 100–500 emails per day for 3–5 days, gradually increasing volume while monitoring delivery and complaint rates.

Should I disable Mailgun after switching to SES?

Not immediately. Run parallel sends for 2–4 weeks to compare deliverability, then disable Mailgun after confirmation.

What is the accuracy of MailTester’s email verification?

MailTester achieves 98.9% accuracy in identifying valid, invalid, catch-all, and risky email addresses.

Do purchased MailTester credits expire?

No — credits never expire, so you can verify lists at your own pace, even months after purchase.

How does SES handle bounce and complaint reporting?

SES sends bounce and complaint notifications via SNS or CloudWatch, allowing automated triage and list cleanup.

Can I migrate all my Mailgun templates to Amazon SES?

Yes — email templates and content are transferable, but you must re-upload them via SES or your mailing system.