amazon-ses
작성자: aws
프로덕션 이메일 전송을 위한 Amazon SES V2 구성 — 도메인 자격 증명 생성, DKIM/SPF/DMARC 인증, 원샷 DNS 레코드 제시 등을 포함합니다.
npx skills add https://github.com/aws/agent-toolkit-for-aws --skill amazon-sesAmazon SES
Recommended: Use the AWS MCP Server with SES permissions for sandboxed execution and CloudTrail audit logging. Without MCP: All operations use standard AWS CLI syntax (
aws sesv2 ...).
Overview
This skill helps developers and DevOps engineers configure Amazon SES for production email sending. It targets users who are not email authentication experts — guiding them through complete domain setup following AWS best practices without requiring deep knowledge of DKIM, SPF, or DMARC.
Routing
| If the user wants to... | Read |
|---|---|
| Set up a domain for sending, configure email authentication, or troubleshoot DKIM | Setting up SES domain identity |
Security
- Use IAM roles with ephemeral credentials (STS) — never long-lived access keys
- Scope IAM permissions to specific SES actions per workflow (see reference files for required permissions)
- Enable CloudTrail for SES API call auditing
- DMARC
p=noneis monitoring only — plan progression top=quarantineafter confirming alignment - Never hardcode credentials, endpoints, or secrets in examples
Critical Rules
- MUST create a domain identity (not email identity) for production sending
- MUST configure custom MAIL FROM subdomain for SPF alignment
- MUST configure DMARC TXT record (
p=noneminimum) for domain alignment - MUST present all DNS records together in one batch
- MUST ask user for preferred MAIL FROM subdomain (do not assume a default)
- SHOULD check if Route 53 hosts the domain and offer automatic DNS creation
- SHOULD NOT claim 72-hour wait — verification typically completes in minutes once DNS propagates