Domains
Manage domains
Add a sending domain, publish its DNS records, and change its settings.
Add a domain
Every team member can add and manage the team's domains. Open Domains and click Add domain.
- Enter the Name, for example
updates.example.com. Leave outhttp://and any path. - Choose the Region: the AWS region your SES identity lives in. The list shows the regions the installation administrator has set up. See regions.
- Optionally open Advanced options and change the Custom Return-Path. It defaults to
send, so bounces come back tosend.<your domain>. It cannot be changed later. - Click Add domain.
You can use separate subdomains such as updates.example.com and receipts.example.com for marketing and transactional mail. This separates their sending identities; it does not guarantee that reputation problems cannot affect the root domain or other subdomains.
Opensend creates the SES identity in your AWS account and opens the domain's page. Adding a domain, in the dashboard or through the API, never gives anyone AWS credentials; only the installation holds them.
Publish the DNS records
The Records tab lists what to add at your DNS provider, grouped as:
| Section | Records | Purpose |
|---|---|---|
| Domain Verification | DKIM CNAMEs | Proves you own the domain and signs every message. They appear a few seconds after the domain is added, once AWS has issued the keys. |
| Enable Sending | SPF TXT and MX on the Return-Path subdomain | Lets receiving servers accept mail from SES and routes bounces back. The switch turns sending on or off. |
| Enable Receiving | MX on the domain | Points inbound mail at SES. See receiving. |
| Recommended | DMARC TXT | See DMARC. |
Each row shows Type, Name, Content, TTL, Priority and Status. The ... menu next to Check DNS records offers Copy all records, Download zone file (BIND format) and Export as CSV.
Auto configure works when your DNS provider supports Domain Connect and has onboarded the Opensend template. It opens the provider in a pop-up with every record filled in; you confirm there and the window closes. Opensend never asks for a provider password or API token. For other providers the button is disabled and you add the records by hand.
Verify
After you add the records, click Check DNS records. Opensend also checks automatically after provisioning or a refresh, often at first and then hourly, for up to 72 hours. Automatic checks stop when the domain verifies.
The banner at the top of the page tells you where the domain stands:
| Banner | Meaning |
|---|---|
| Verification not started, Waiting for your DNS records | Add the records, then check. |
| Domain partially verified | Some records resolve and some do not. The unverified rows are still missing. |
| Records found | Every record is published. Amazon SES confirms them on its own schedule, which can take up to 72 hours. |
| Domain verified | The domain is ready to send. |
| Verification failed | The records were not found. Review them and check again. |
| Temporary failure | Your DNS provider did not answer the last lookup. Check again. |
The Domain events trail above the tabs shows when the domain was added and verified. Through the API, use verify domain.
Change settings
The Configuration tab has:
- Enable tracking metrics: click Configure to set the tracking subdomain and turn click and open tracking on. See open and click tracking.
- TLS (Transport Layer Security): Opportunistic TLS or Enforced TLS. See TLS policy.
- Return-Path: the bounce subdomain chosen when the domain was added. It is read-only.
The Enable Sending and Enable Receiving switches are on the Records tab. Settings can change only once the domain has been provisioned.
Delete a domain
Choose Delete domain from the domain's ... menu and confirm. Sending from the domain stops at once and AWS cleanup is queued. DNS records stay at your provider until you remove them. Adding the same name again creates a new domain with a new ID; a sending-only API key restricted to the old domain never gains access to the new one. A team cannot be deleted while it still has domains.
Existing SES identities
If the domain already exists as an SES identity in your AWS account, provisioning stops and the installation administrator sees Review existing identity. The Connect existing domain dialog shows the identity's current configuration set and MAIL FROM. Review AWS settings reads them again, and Approve identity changes lets Opensend take the identity over. Existing DKIM records are kept, and deleting the domain later restores the reviewed settings where safe. If someone changed the identity in AWS meanwhile, cleanup can require operator review.
Claim a domain another team uses
A domain name belongs to only one team in the installation. If another team has verified it, Add domain shows Domain already in use and its button becomes Claim domain.
- Click Claim domain. A placeholder domain opens with one TXT record named after the domain, with the value
opensend-domain-verification=.... - Add the TXT record at your DNS provider, then click I've added the records.
- When the record is found, the domain is removed from the previous team and set up again for yours. Then add the sending records shown on the domain page.
A claim expires after seven days; after that, Start new claim issues a new TXT value. The transfer waits while the previous team still has queued or scheduled emails from the domain. Cancel claim removes the placeholder and leaves the domain with its current owner. Through the API, use POST /domains/claim, GET /domains/{domain_id}/claim and POST /domains/{domain_id}/claim/verify. Active AWS operations also block transfer; an adopted SES identity must first be released by its current owner.
Domain changes fire domain.created, domain.updated and domain.deleted webhooks.