Skip to main content
ESP AUTHENTICATION GUIDESPF Lookups: 1 / 10DKIM Type: CNAMEBIMI: Supported

How to Set Up SPF & DKIM for Amazon Simple Email Service (SES): DNS Authentication Guide

Configure authoritative DNS records for Amazon Simple Email Service (SES). Prevent spoofing, maintain high inbox placement at Google & Yahoo, and verify alignment without exceeding RFC 7208 lookup limits.

Required DNS Records for Amazon Simple Email Service (SES)

1. Sender Policy Framework (SPF)
Type: TXT
Host / Name:@
Value / Content:
v=spf1 include:amazonses.com ~all
Uses 1 of your domain's 10 allowed DNS lookups under RFC 7208. Do not add duplicate SPF TXT records.
2. DomainKeys Identified Mail (DKIM)
Type: CNAME
Selector / Host Name:token1._domainkey
Target / Key Content:
token1.dkim.amazonses.com
Delegates cryptographic signing to Amazon Simple Email Service (SES). Alignment mode is set to relaxed.

Recommended DMARC Policy for Amazon Simple Email Service (SES)

Once both SPF and DKIM are verified on your domain, enforce DMARC to prevent attackers from sending unauthorized emails spoofing your brand:

v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourcompany.com; pct=100; aspf=r; adkim=r

Vendor Resources & RFC Standards

RFC 7208 (SPF)RFC 6376 (DKIM)RFC 7489 (DMARC)Amazon Simple Email Service (SES) Official Setup Guide
Live DNS & SPF Analyzer

Verify Your Amazon Simple Email Service (SES) SPF & DKIM Records in Real-Time

Test your authoritative domain now to check DNS lookup limits, evaluate DMARC alignment, and ensure 100% deliverability to Google and Microsoft inboxes.

Run SPF & DKIM Audit