Get started
Add and verify a domain
Connect a domain you own before sending email.
Add your domain
Complete the AWS setup, then open Domains → Add domain. Any team member can add a domain.
- Name: a domain or subdomain you own, without
http://or a path. A subdomain such asupdates.example.comkeeps transactional reputation separate from marketing. - Region: the AWS region for the domain’s SES identity. Only regions your installation has finished setting up are listed, and the installation’s default region is preselected.
- Custom Return-Path (under Advanced options): the subdomain that carries the MX and SPF records for bounces. It defaults to
sendand cannot be changed later.
After you add the domain, its page opens. AWS issues the DKIM keys within a few seconds and the records appear.
Publish the DNS records
The domain page lists the records in sections:
| Section | Records | Purpose |
|---|---|---|
| Domain Verification | DKIM | Proves you own the domain and signs your messages |
| Enable Sending | SPF and MX on the return-path subdomain | Lets receivers accept mail from SES and routes bounces |
| Enable Receiving | MX | Points inbound mail at SES; off until you turn it on |
| Recommended | DMARC | Tells inboxes what to do with mail that fails SPF or DKIM |
Copy the exact names and values into your DNS provider. The menu next to the records can copy all records, download a zone file, or export a CSV. Auto configure fills in the records at providers that support Domain Connect; it is disabled for other providers, and you confirm the changes at the provider.
The receiving MX record replaces the mail provider the domain uses today. Use a subdomain if that mailbox must keep working.
Verify and send
Choose Check DNS records after publishing. Checks are limited to one per domain every 10 seconds, and Opensend also checks automatically for 72 hours. When every record is found, Amazon SES still confirms them on its own schedule, which can take up to 72 hours. Once the domain shows as verified, send from an address on it.
curl "$OPENSEND_BASE_URL/emails" \
-H "Authorization: Bearer $OPENSEND_API_KEY" \
-H "Content-Type: application/json" \
-d '{"from":"Acme <hello@example.com>","to":["you@example.net"],"subject":"Hello from Opensend","html":"<p>Your first email is on its way.</p>"}'If the domain is already in use
Each domain belongs to one team. If another team on the installation registered the name, the dialog shows Domain already in use and offers Claim domain. A claim gives you one TXT record to publish at the domain. Choose I’ve added the records to have it checked. Verifying ownership transfers the domain to your team and revokes the other team’s access. The domain then gets new DKIM records, which you publish and verify as above. A claim expires after seven days; Cancel claim removes it and the current owner keeps the domain. The same flow is available through the domain claim API.
If verification is pending
Check DNS propagation, duplicate records, and the host label your provider expects. A pending tracking record alone does not block otherwise ready sending. Accounts in the SES sandbox also need a verified recipient or an SES mailbox simulator address.