amazon-ses

por aws

Configura o Amazon SES V2 para envio de e-mails em produção — incluindo criação de identidade de domínio, autenticação DKIM/SPF/DMARC, apresentação de registros DNS em uma única etapa,…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill amazon-ses

Amazon SES

Recommended: Use the AWS MCP Server with SES permissions for sandboxed execution and CloudTrail audit logging. Without MCP: All operations use standard AWS CLI syntax (aws sesv2 ...).

Overview

This skill helps developers and DevOps engineers configure Amazon SES for production email sending. It targets users who are not email authentication experts — guiding them through complete domain setup following AWS best practices without requiring deep knowledge of DKIM, SPF, or DMARC.

Routing

If the user wants to...Read
Set up a domain for sending, configure email authentication, or troubleshoot DKIMSetting up SES domain identity

Security

  • Use IAM roles with ephemeral credentials (STS) — never long-lived access keys
  • Scope IAM permissions to specific SES actions per workflow (see reference files for required permissions)
  • Enable CloudTrail for SES API call auditing
  • DMARC p=none is monitoring only — plan progression to p=quarantine after confirming alignment
  • Never hardcode credentials, endpoints, or secrets in examples

Critical Rules

  • MUST create a domain identity (not email identity) for production sending
  • MUST configure custom MAIL FROM subdomain for SPF alignment
  • MUST configure DMARC TXT record (p=none minimum) for domain alignment
  • MUST present all DNS records together in one batch
  • MUST ask user for preferred MAIL FROM subdomain (do not assume a default)
  • SHOULD check if Route 53 hosts the domain and offer automatic DNS creation
  • SHOULD NOT claim 72-hour wait — verification typically completes in minutes once DNS propagates

Additional Resources

Mais skills de aws

agents-build
aws
Use to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource…
official
agents-connect
aws
Use when connecting your agent to external APIs, tools, or services via Gateway, or restricting tool access with Cedar policies. Handles gateway setup, target…
official
agents-debug
aws
Use quando seu agente ou ambiente estiver quebrado — respostas erradas, erros, timeouts, falhas de ferramentas ou problemas de CLI. Lê traces e logs para diagnosticar causas raiz.…
official
agents-deploy
aws
Use when deploying your agent to AWS, or when a deploy has failed. Handles pre-flight validation, CDK/IAM/quota error diagnosis, version management, rollback,…
official
agents-get-started
aws
Use quando um desenvolvedor quiser criar um novo projeto de agente ou começar com o AgentCore. Lida com seleção de framework, scaffolding de projeto, primeiro deploy e…
official
agents-harden
aws
Use when preparing your agent for production — IAM scoping, inbound auth (JWT, SigV4), secrets management, cold start optimization, session lifecycle, rate…
official
agents-pay
aws
Use quando ESTE agente precisar pagar por conteúdo protegido por x402 em tempo de execução: encontrar um paywall no meio da tarefa, resolver isso via AgentCore Payments e aplicar…
official
amazon-aurora-mysql
aws
Amazon Aurora MySQL — cria, modifica e orienta sobre clusters Aurora MySQL especificamente (mecanismo compatível com MySQL, Aurora serverless, consulta paralela).…
official