Amazon SES SPF, DKIM and DMARC check
Enter the domain you send from with Amazon SES. We check the SPF include, the Amazon SES DKIM key, your DMARC policy and MX records, and tell you what is missing.
What Amazon SES expects
SPF
Add include:amazonses.com to your single SPF record, for example: v=spf1 include:amazonses.com ~all
The include goes on your custom MAIL FROM subdomain (for example bounce.yourdomain.com), not your root. Without a custom MAIL FROM, SES uses amazonses.com for the envelope, so SPF never aligns with your domain and DMARC relies on DKIM alone.
Build a combined SPF record if you send from more than one service.
DKIM
Easy DKIM gives you three CNAME records whose selectors are random tokens (token._domainkey.yourdomain). Copy one token from the SES console (Verified identities > your domain > DKIM) into the selector box to check it.
DMARC
DMARC is set on your domain, not in Amazon SES. If you have none, start with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com and tighten it once reports look clean. Generate one.
MX
SES does not host your mailbox. Keep your mailbox provider’s MX. Your MAIL FROM subdomain needs its own MX pointing at feedback-smtp.<region>.amazonses.com.
Values come from Amazon SES’s public setup documentation and can change. The Amazon SES console always shows the exact records for your account. Use those if they differ from this page.
Keep it working after setup
The usual failures come later: a second SPF record added for a new tool, a DKIM CNAME lost in a DNS move, a DMARC record deleted with an old zone. SenderBeacon checks twice a day and emails you in plain English. From $9/month, 14-day free trial, no card.
Start free trialQuestions
How long until Amazon SES DNS changes show up?
Usually minutes, sometimes up to an hour, depending on the TTL on your records and your DNS host. Re-run the check after publishing.
Why does the check say DKIM is missing when Amazon SES says it is verified?
Most often the record went on the wrong host (for example _domainkey.yourdomain.com.yourdomain.com, because the DNS host appended the domain twice), or you are checking a different domain or subdomain than the one you send from.