Skip to documentation

Self-hosting

AWS SES onboarding

Connect your AWS account and prepare your sending regions.

Run the wizard

The first account created becomes the installation administrator and must verify its email before setup. Choose Connect AWS, select a region, and enter account credentials. Create AWS user downloads a scoped CloudFormation template. Upload it in AWS, acknowledge IAM changes, and create an access key for the generated user. Importing the key CSV parses it in your browser.

Enable callbacks

Set a public HTTPS callback origin that reaches Convex HTTP on port 3211. Opensend verifies that it reaches this installation. Provision regional resources, create a team, then add your sending domain.

Regions and sandbox

The verified release offers us-east-1, eu-west-1, sa-east-1, and ap-northeast-1. Sending quotas and sandbox status are regional. Request production access in the SES console for each sending region. Until approval, use verified recipients or SES simulator addresses.

Troubleshoot permissions

Download the current IAM permissions from the domain or instance settings. Update the existing policy, then retry the failed operation. Explicit denies in organization policies or permission boundaries need to be resolved in AWS. Do not replace a key just to retry provisioning.

bash
pnpm backend logs --history 50

Manage the installation

After setup, choose Amazon SES below My profile in the profile menu. Only the installation administrator can use these controls; team admins do not gain AWS access.

  • AWS connection → Update connection validates replacement credentials or additional regions. Download permissions provides the current scoped IAM policy. The CloudFormation helper creates a user and managed policy, not an access key or console login; create the key in IAM after the stack finishes.
  • Sending regions shows each region's quota, sandbox state and delivery status. These account quotas are shared by all teams. See Usage.
  • Delivery updates → Check connection checks the public callback and refreshes the AWS connection status. Change moves an existing installation to a new public URL.
  • Team sending controls regional sending for each team's SES tenant. See SES tenancy.

Set up account email

In Account email sender, choose a verified Sending domain, enter From name and From local part, then click Save. Opensend uses this sender for verification, password resets, email changes, invitations and export notifications.

Configure it before inviting others. Without a sender, only the first administrator's account links appear in backend logs; other users' account mail needs this sender. Clear removes the sender. Once a sender is configured, failed delivery does not fall back to logging secret links.