Skip to documentation

Get started

Add and verify a domain

Connect a domain you own before sending email.

Add your domain

Complete the AWS setup, then open Domains → Add domain. Any team member can add a domain.

  • Name: a domain or subdomain you own, without http:// or a path. A subdomain such as updates.example.com keeps transactional reputation separate from marketing.
  • Region: the AWS region for the domain’s SES identity. Only regions your installation has finished setting up are listed, and the installation’s default region is preselected.
  • Custom Return-Path (under Advanced options): the subdomain that carries the MX and SPF records for bounces. It defaults to send and cannot be changed later.

After you add the domain, its page opens. AWS issues the DKIM keys within a few seconds and the records appear.

Publish the DNS records

The domain page lists the records in sections:

SectionRecordsPurpose
Domain VerificationDKIMProves you own the domain and signs your messages
Enable SendingSPF and MX on the return-path subdomainLets receivers accept mail from SES and routes bounces
Enable ReceivingMXPoints inbound mail at SES; off until you turn it on
RecommendedDMARCTells inboxes what to do with mail that fails SPF or DKIM

Copy the exact names and values into your DNS provider. The menu next to the records can copy all records, download a zone file, or export a CSV. Auto configure fills in the records at providers that support Domain Connect; it is disabled for other providers, and you confirm the changes at the provider.

The receiving MX record replaces the mail provider the domain uses today. Use a subdomain if that mailbox must keep working.

Verify and send

Choose Check DNS records after publishing. Checks are limited to one per domain every 10 seconds, and Opensend also checks automatically for 72 hours. When every record is found, Amazon SES still confirms them on its own schedule, which can take up to 72 hours. Once the domain shows as verified, send from an address on it.

bash
curl "$OPENSEND_BASE_URL/emails" \
  -H "Authorization: Bearer $OPENSEND_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"from":"Acme <hello@example.com>","to":["you@example.net"],"subject":"Hello from Opensend","html":"<p>Your first email is on its way.</p>"}'

If the domain is already in use

Each domain belongs to one team. If another team on the installation registered the name, the dialog shows Domain already in use and offers Claim domain. A claim gives you one TXT record to publish at the domain. Choose I’ve added the records to have it checked. Verifying ownership transfers the domain to your team and revokes the other team’s access. The domain then gets new DKIM records, which you publish and verify as above. A claim expires after seven days; Cancel claim removes it and the current owner keeps the domain. The same flow is available through the domain claim API.

If verification is pending

Check DNS propagation, duplicate records, and the host label your provider expects. A pending tracking record alone does not block otherwise ready sending. Accounts in the SES sandbox also need a verified recipient or an SES mailbox simulator address.