Domains
TLS policy
Choose whether delivery to receiving mail servers must use TLS.
How it works
The TLS policy decides how Amazon SES delivers your domain's mail to the receiving server:
- Opportunistic TLS (the default) always tries a secure connection. If the receiving server cannot make one, the message goes unencrypted.
- Enforced TLS requires TLS for every message. Mail to a server that does not support it is not delivered.
Change it
Open the domain, go to the Configuration tab, and choose a value under TLS (Transport Layer Security). The change is applied to the domain's SES configuration set.
Through the API, pass tls when you create a domain, or update it once it is provisioned:
bash
curl -X PATCH "$OPENSEND_BASE_URL/domains/YOUR_DOMAIN_ID" \
-H "Authorization: Bearer $OPENSEND_API_KEY" -H "Content-Type: application/json" \
-d '{"tls":"enforced"}'Things to know
This policy covers delivery from SES to recipients only. HTTPS for your API and dashboard is set up at your reverse proxy, and the SMTP gateway has its own certificate.