Setup guide · Sending
Connect Amazon SES
Sendalto sends lifecycle email through your own Amazon SES account, so your domain, reputation and AWS bill stay yours. This guide takes about 30 minutes plus DNS and AWS review time.
Checked against Sendalto on
Before you start
- An AWS account where you can create IAM users, SES resources and an SNS topic.
- A domain whose DNS you control. Use the exact domain you will send from: if you send from
[email protected], the sending domain ismail.example.com. - One AWS region for everything — the SES domain, the configuration set and the SNS topic, for example
eu-central-1. - Owner or admin access to the Sendalto workspace with two-factor sign-in turned on.
- Your workspace ID. Open Settings → Integrations, choose Configure on Amazon SES: the ID is part of the tenant name
sendalto-WORKSPACE_IDand of the feedback address shown there.
Below, replace REGION, ACCOUNT_ID (your 12-digit AWS account ID), example.com (your sending domain) and WORKSPACE_ID with your values.
1. Create an IAM user with this policy
Create a dedicated IAM user for Sendalto without console access, attach the policy below as an inline policy, and create an access key for it. Sendalto stores the key encrypted for this workspace only.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AccountStatus",
"Effect": "Allow",
"Action": "ses:GetAccount",
"Resource": "*"
},
{
"Sid": "SendingDomain",
"Effect": "Allow",
"Action": [
"ses:CreateEmailIdentity",
"ses:GetEmailIdentity",
"ses:PutEmailIdentityMailFromAttributes"
],
"Resource": "arn:aws:ses:REGION:ACCOUNT_ID:identity/example.com"
},
{
"Sid": "ConfigurationSet",
"Effect": "Allow",
"Action": [
"ses:CreateConfigurationSet",
"ses:GetConfigurationSet",
"ses:GetConfigurationSetEventDestinations",
"ses:PutConfigurationSetSuppressionOptions"
],
"Resource": "arn:aws:ses:REGION:ACCOUNT_ID:configuration-set/sendalto-WORKSPACE_ID"
},
{
"Sid": "Tenant",
"Effect": "Allow",
"Action": [
"ses:CreateTenant",
"ses:TagResource",
"ses:GetTenant",
"ses:ListTenantResources",
"ses:PutTenantSuppressionAttributes"
],
"Resource": "arn:aws:ses:REGION:ACCOUNT_ID:tenant/sendalto-WORKSPACE_ID/*"
},
{
"Sid": "TenantResources",
"Effect": "Allow",
"Action": "ses:CreateTenantResourceAssociation",
"Resource": [
"arn:aws:ses:REGION:ACCOUNT_ID:tenant/sendalto-WORKSPACE_ID/*",
"arn:aws:ses:REGION:ACCOUNT_ID:identity/example.com",
"arn:aws:ses:REGION:ACCOUNT_ID:configuration-set/sendalto-WORKSPACE_ID"
]
},
{
"Sid": "Send",
"Effect": "Allow",
"Action": "ses:SendEmail",
"Resource": [
"arn:aws:ses:REGION:ACCOUNT_ID:identity/example.com",
"arn:aws:ses:REGION:ACCOUNT_ID:configuration-set/sendalto-WORKSPACE_ID"
]
}
]
}The policy lists exactly the SES API calls Sendalto makes with your key, and nothing else. Each one is limited to your domain, your configuration set and your tenant, except ses:GetAccount, which AWS does not allow to scope.
| Permission | When Sendalto uses it |
|---|---|
ses:GetAccount | Connection check and every send: production access, sending status and quota. |
ses:GetEmailIdentity | Connection check, every send and Settings → Delivery: domain, DKIM and MAIL FROM status. |
ses:GetConfigurationSet | Connection check and every send: the configuration set is not paused and keeps tenant suppression. |
ses:GetConfigurationSetEventDestinations | Connection check and every send: the SNS feedback destination exists. |
ses:GetTenant | Connection check, every send and Create SES resources: tenant sending status and suppression. |
ses:ListTenantResources | Connection check and every send: the domain and configuration set belong to your tenant. |
ses:SendEmail | Sending an approved email or a test. |
ses:PutEmailIdentityMailFromAttributes | Setting a MAIL FROM subdomain in Settings → Delivery. |
ses:CreateTenant, ses:TagResource | Create SES resources: creates the tenant sendalto-WORKSPACE_ID tagged with your workspace ID. |
ses:CreateEmailIdentity | Create SES resources: adds your sending domain to SES if it is not there yet. |
ses:CreateConfigurationSet | Create SES resources: creates the configuration set sendalto-WORKSPACE_ID. |
ses:CreateTenantResourceAssociation | Create SES resources: attaches the domain and configuration set to the tenant. |
ses:PutTenantSuppressionAttributes, ses:PutConfigurationSetSuppressionOptions | Create SES resources: suppresses addresses that bounced or complained, for this tenant. |
2. Create an SNS topic for feedback
In the Amazon SNS console, in the same region, create a topic of type Standard (SES does not publish to FIFO topics), for example sendalto-feedback. Copy its ARN, such as arn:aws:sns:REGION:ACCOUNT_ID:sendalto-feedback. Do not add a subscription yet — Sendalto confirms it only once the topic ARN is saved in the workspace.
3. Enter the details in Sendalto
- Open Settings → Integrations and choose Configure on Amazon SES.
- Enter the AWS region, the access key ID and the secret access key of the IAM user. Leave the session token empty: temporary credentials expire, and checks and sending stop when they do.
- Enter the sending domain (a domain such as
example.com, not an email address), keep the configuration setsendalto-WORKSPACE_ID, and paste the SNS topic ARN. - Choose Save encrypted credentials, then Create SES resources. Sendalto creates the tenant
sendalto-WORKSPACE_ID, adds the domain and the configuration set, attaches both to the tenant and turns on suppression of bounced and complained addresses for that tenant. Resources that already exist are kept.
Saving new credentials resets the connection status and cancels sends queued through the old ones, so plan key rotation for a quiet moment.
4. Add the DNS records
Settings → Delivery shows the exact records for your domain and marks each one as found or missing. Your technical teammate can work there without access to contacts or credentials.
- DKIM. SES uses Easy DKIM: three CNAME records
TOKEN._domainkey.example.com→TOKEN.dkim.amazonses.com. The tokens appear after Create SES resources. - Custom MAIL FROM. Pick a subdomain such as
bounce.example.comin Settings → Delivery (Sendalto sets it in SES with Reject message on MX failure, which the check requires), then add its MX and SPF records. If you set it in the SES console instead, choose Reject message as the behaviour on MX failure. - DMARC. A TXT record exactly at
_dmarc.<your sending domain>withp=none,p=quarantineorp=reject. Sendalto looks only at that name: if you send frommail.example.com, publish_dmarc.mail.example.comeven ifexample.comhas its own record. Start withp=noneand aruaaddress for reports.
; DKIM (Easy DKIM): three records, tokens come from SES
TOKEN1._domainkey.example.com CNAME TOKEN1.dkim.amazonses.com
TOKEN2._domainkey.example.com CNAME TOKEN2.dkim.amazonses.com
TOKEN3._domainkey.example.com CNAME TOKEN3.dkim.amazonses.com
; Custom MAIL FROM, for example bounce.example.com
bounce.example.com MX 10 feedback-smtp.REGION.amazonses.com
bounce.example.com TXT "v=spf1 include:amazonses.com ~all"
; DMARC, exactly at _dmarc.<sending domain>
_dmarc.example.com TXT "v=DMARC1; p=none; rua=mailto:[email protected]"DNS changes can take from minutes to several hours to appear. SES verifies the domain once the DKIM records are visible.
5. Send bounces and complaints to Sendalto
- In the SES console open Configuration sets →
sendalto-WORKSPACE_ID→ Event destinations → Add destination. - Select at least Hard bounces, Complaints, Deliveries and Rejects (Sendalto requires these four; others are optional), keep event publishing enabled, choose Amazon SNS and the topic from step 2.
- Give SES permission to publish to the topic: in the SNS console edit the topic’s Access policy and add the statement below.
- In the SNS console create a subscription on the topic: protocol HTTPS, endpoint
https://sendalto.com/api/webhooks/email?workspace=WORKSPACE_IDwith your workspace ID. Leave Enable raw message delivery off. - Sendalto verifies the signed confirmation from SNS and confirms the subscription by itself; the subscription turns Confirmed within a minute. If it stays Pending confirmation, check that the topic ARN saved in Sendalto is the same, then choose Request confirmation.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AllowSesEventPublishing",
"Effect": "Allow",
"Principal": { "Service": "ses.amazonaws.com" },
"Action": "sns:Publish",
"Resource": "arn:aws:sns:REGION:ACCOUNT_ID:TOPIC_NAME",
"Condition": {
"StringEquals": {
"AWS:SourceAccount": "ACCOUNT_ID",
"AWS:SourceArn": "arn:aws:ses:REGION:ACCOUNT_ID:configuration-set/sendalto-WORKSPACE_ID"
}
}
}
]
}With feedback in place, a hard bounce or a complaint suppresses the address in Sendalto at once and cancels its queued emails. A complaint also pauses all sending in the workspace. The owner reviews what caused it and resumes sending in Settings → Workspace → Sending with Resume sending… (this needs two-factor sign-in and a recent sign-in). Complained addresses stay suppressed.
6. Request SES production access
New SES accounts start in the sandbox, where email goes only to verified addresses. In the SES console of your region open Account dashboard → Request production access and describe your use: permission-based lifecycle email, how people subscribe, and how you handle bounces, complaints and unsubscribes (Sendalto adds one-click unsubscribe to every marketing email). AWS usually answers within a day. Production access is granted per region.
7. Run the connection check
Choose Check connection on the Amazon SES card. Sendalto reads your SES account with the saved key and lists anything still missing under Check details. The connection is ready when every item below passes.
| Message | What to do |
|---|---|
| SES production access is not enabled in this region. | Step 6, in the region saved in Sendalto. |
| SES account sending is paused or under enforcement. | Resolve the notice in the SES Account dashboard with AWS. |
| The sending domain is not verified. | Step 4: the DKIM records verify the domain. |
| DKIM is not verified and enabled. | Step 4: all three DKIM CNAME records, with DKIM signing on. |
| A verified custom MAIL FROM with reject-on-MX-failure is required. | Step 4: MAIL FROM subdomain with MX and SPF, behaviour Reject message. |
| The configuration set is paused. | Resume sending for the configuration set in the SES console. |
| SES tenant sending is not enabled. | Re-enable sending for the tenant sendalto-WORKSPACE_ID in the SES console. |
| Tenant bounce and complaint suppression must be enabled. | Run Create SES resources again. |
| Configuration-set suppression must not override tenant protection. | Remove the configuration set’s own suppression settings, or run Create SES resources again. |
| Identity and configuration set must both be associated with this tenant. | Run Create SES resources again. |
| Configure the authenticated SNS feedback destination for bounce, complaint, delivery and rejection. | Step 5: event destination with all four event types, enabled, on the saved topic. |
| Confirm the signed SNS subscription to this workspace feedback endpoint. | Step 5: subscribe the HTTPS endpoint with your workspace ID. |
| A valid DMARC policy record is required. | Step 4: one DMARC record at _dmarc.<sending domain>. |
| DMARC DNS record could not be verified. | Step 4: there is no TXT record at _dmarc.<sending domain> yet, or DNS has not updated. Publish it and check again later. |
| SES sending quota is unavailable or exhausted. | Wait for the 24-hour quota to free up, or ask AWS for a higher quota. |
| Provider check failed. Confirm credentials, network access and required provider permissions. | SES refused or could not answer a request. Check the access key and secret, that the region matches where your SES resources are, and that the IAM policy from step 1 is attached. If you have not run Create SES resources yet, run it first: the tenant must exist before the check. |
Sendalto repeats these checks before every send, and a check older than 24 hours must be run again before sending. Emails are sent from addresses at the sending domain itself: with example.com connected, use [email protected].
After the check passes
You can send test emails to your own address right away. Real sending to your audience also needs an approved business review by Sendalto and a paid plan or an early-access pilot. Plans are not on sale yet; during early access Sendalto offers free pilots to reviewed workspaces. See what works today.