Amazon SES: Email Infrastructure Review
Amazon SES strips away SaaS markups to offer bare-metal email infrastructure. Here is a practical deep dive into how SES works under the hood, key deliverability features like DKIM and Custom MAIL FROM, and what it takes to run high-volume email at scale.
While platforms like SendGrid, Postmark, and Mailgun deliver developer-friendly setups and turnkey management tools, Amazon Simple Email Service (SES) functions as a high-performance engine powering transactional and high-volume email infrastructure.
Whereas managed providers charge a premium for out-of-the-box deliverability dashboards, dynamic email builders, and priority routing, SES cuts out the middleman to focus purely on high-speed email delivery—charging a baseline $0.10 per 1,000 emails. It provides the essential cloud pipes—via Simple Mail Transfer Protocol (SMTP) relay and Application Programming Interface (API)—for engineering teams who prefer to own their suppression lists, reputation monitoring, and deployment workflows directly within Amazon Web Services (AWS).
I actually run my own email marketing platform built directly on top of SES, and it's been brilliant. Once you get past the initial setup, it sits quietly in the background without giving me any grief, effortlessly handling bulk sends without rinsing my wallet.
Key Positioning Differences
Whether you are building custom inbound email-parsing pipelines via AWS Lambda, sending transactional order receipts, or setting up an Agentic Inbox—where SES receives incoming customer messages and handles the automated AI replies—SES offers raw SMTP and API capabilities at unmatched scale.
| Metric / Dimension | Amazon SES | Managed API Competitors (Postmark, SendGrid, Mailgun) |
| Market Segment | Bare-metal cloud infrastructure | Managed developer-first email platforms |
| Baseline Cost | ~$0.10 per 1,000 emails | ~$0.80–$2.00+ per 1,000 emails (tiered/monthly minimums) |
| Deliverability & IP Risk | Self-managed via AWS logic, Simple Notification Service (SNS), or Virtual Deliverability Manager (VDM) | Turnkey; dedicated warmup pools and managed stream separation |
| Primary Value Prop | Unmatched pricing floor at massive scale | Fast setup, visual builders, and deep developer experience features |
Real-World Use Cases: Where SES Shines
Because SES is an infrastructure component rather than an all-in-one product, you can plug it into almost any workflow:
- Email Marketing & Broadcasts: This is where I use it. By pairing SES with a self-hosted frontend (like Listmonk or Mailcoach), you get a fully functional marketing suite for a fraction of the cost of SaaS tools like Mailchimp or ConvertKit.
- Transactional Application Emails: Password reset links, signup confirmations, and invoice receipts triggered programmatically via your code.
- Inbound Document & Invoice Processing: Ingesting attachments from incoming customer emails directly into cloud storage to automatically trigger background extraction workflows.
The Features That Set Amazon SES Apart
Most email tools only worry about sending outbound messages, but SES has a few built-in features that make it much more flexible:
- Virtual Deliverability Manager: AWS gives you automated insights into bounce rates, open tracking, and deliverability recommendations directly inside the console, helping you spot Sender Policy Framework (SPF) or DomainKeys Identified Mail (DKIM) configuration mistakes early.
- Configurable Receipt Rules: You can intercept incoming mail at the domain level and automatically pipe it into other cloud resources without ever maintaining an inbox.
- IP Pool Management: For high-volume senders, you can lease dedicated Intellectual Property (IP) addresses and group them into distinct pools. This keeps your critical transactional mail completely isolated from your marketing campaigns so a temporary deliverability hiccup in one area doesn't impact password resets.
The Developer Experience: High Setup vs Raw Efficiency
It is worth addressing the elephant in the room: why do some developers initially hesitate with SES and head straight to Postmark or SendGrid?
Put simply, SES doesn't try to hold your hand. It gives you bare-metal cloud infrastructure and leaves it to you to build the application around it:
- The Sandbox Onboarding: Unlike Mailgun or SendGrid where you can send test emails instantly, new SES accounts are locked in a strict sandbox mode. You have to submit a formal production request to AWS detailing your anti-spam policies, bounce management, and opt-out flows before sending a single live email.
- No Built-in Tools or Campaign Editors: You don't get visual template builders, contact list management, or click-and-drag editors out of the box. If you want open or click tracking, you have to wire up event publishing to Amazon CloudWatch or Amazon Simple Storage Service (S3).
- Manual Suppression Pipelines: If your hard bounce rate breaches 5% or your spam complaint rate hits 0.1%, AWS will pause your sending. But SES won't clean your lists automatically—you have to build a pipeline using SNS and Lambda to catch bounce webhooks and suppress bad addresses in your database.
It takes a bit of work to set up initially, but once that pipeline is running, you get a hugely capable email system for next to nothing.

Core Architecture: Inbound vs. Outbound
SES operates across two distinct modes, making it fundamentally different from traditional Internet Message Access Protocol (IMAP) or Post Office Protocol 3 (POP3) hosts:
- Outbound Sending (API or SMTP Relay): You dispatch emails using standard SMTP credentials or the AWS Software Development Kit (SDK)—such as
SendEmailorSendRawEmail. SES handles DKIM signing, SPF verification, and delivery tracking out of the box. - Inbound Ingestion (Receipt Rules): When an email arrives at an SES-monitored domain, it doesn't save it to a mailbox. Instead, a Receipt Rule triggers serverless actions:
- S3: Stores the raw
.emlMIME payload. - Lambda: Executes code directly on the incoming message payload (ideal for parsing headers, body text, or attachments).
- SNS / EventBridge: Publishes event notifications to webhooks or microservices.
- S3: Stores the raw
Authentication & Deliverability: Setting Up SPF, DKIM, and Custom Domains
If you want your emails to land cleanly in the inbox rather than the spam folder, setting up proper authentication is non-negotiable. Because SES gives you raw infrastructure, you need to generate your authentication tokens in the SES console and publish them to your domain DNS:
- Sender Policy Framework (SPF): This tells receiving mail servers which IP addresses are authorised to dispatch emails for your domain. You add an
include:amazonses.comentry to your domain's SPF record so providers know your AWS traffic is legitimate. - DomainKeys Identified Mail (DKIM): SES provides Easy DKIM, which generates three CNAME records in the console. Once added to your DNS, SES attaches a cryptographic signature to every outgoing message, proving to inbox providers (like Gmail and Outlook) that the email hasn't been tampered with in transit.
- Custom MAIL FROM (Custom Envelope): By default, SES sends mail using its own generic envelope domain (
amazonses.com). Setting up a Custom MAIL FROM domain (likemail.yourdomain.com) inside SES aligns your envelope address with your main sender domain, which is essential for passing strict Domain-based Message Authentication, Reporting, and Conformance (DMARC) alignment checks.
You generate these records inside the SES console and publish them to your DNS manager (like Route 53 or Cloudflare) in about ten minutes, but it instantly boosts your sender reputation and keeps your deliverability rock solid.
How SES Fits into Modern Serverless Stacks
Scenario A: Building an AI Agentic Inbox Processing Pipeline
By chaining SES with native AWS primitives, you can construct an autonomous email worker:
- Inbound Email: Arrives at
agent@yourdomain.com$\rightarrow$ SES catches the stream. - Storage: SES dumps the raw
.emlstring into S3. - Compute: S3 triggers a Lambda function running a mail parser to extract clean JSON text and attachments.
- Large Language Model (LLM) Execution: Lambda sends the parsed body to an LLM (such as Amazon Bedrock or Anthropic Claude) to generate a response or extract structured data.
- Outbound Dispatch: Lambda sends the AI-generated reply back out via the SES API.
Inbound Email (agent@yourdomain.com)
└── Amazon SES (Ingests stream)
└── Amazon S3 (Saves raw .eml payload)
└── AWS Lambda (Parses MIME & executes LLM)
└── Amazon SES API (Dispatches outbound reply)Amazon SES Email Route
Scenario B: Replacing Cloudflare Email Routing for AWS Workloads
If your infrastructure already lives in AWS (Elastic Compute Cloud (EC2), Elastic Container Service (ECS), or Lambda), using SES for inbound mail routing eliminates cross-cloud latency. You can parse incoming attachments using S3 triggers without running into the tighter memory limits of Cloudflare Workers.
Pricing Structure
SES uses a pay-as-you-go pricing model with no base monthly subscription fees:
- Inbound Emails: $0.10 per 1,000 incoming chunks (where a chunk is 256 KB).
- Attachment Data Transfer: $0.12 per GB for attachments processed through S3.
- Dedicated IPs (Optional): $24.95/month per IP for standard dedicated IPs (or managed IP plans starting from $15/month).
Outbound Emails (À La Carte): $0.10 per 1,000 emails ($0.0001 per email).
If you stick to pure, unbundled API/SMTP sending without managed add-ons, your base rate remains $0.10 per 1,000 emails.
Key Hurdles & Developer Gotchas
While SES is cheap and reliable, setting it up requires navigating a few operational quirks:
- The Sandbox Limit: All new SES accounts start in the SES Sandbox. You can only send up to 200 emails per day, and only to verified email addresses. Requesting production access requires submitting a form detailing your anti-spam policies, bounce management, and opt-out workflows.
- Bounce & Complaint Rates: AWS strictly enforces deliverability standards. If your bounce rate exceeds 5% or your spam complaint rate exceeds 0.1%, your account risk level spikes and sending will be paused. Managing bounce webhooks via SNS is mandatory for production operations.
- No Native Webmail User Interface (UI): SES is purely infrastructure. There is no inbox UI, draft editor, or campaign builder out of the box. You must pair it with a client application, an open-source tool (like EmailEngine or Listmonk), or custom front-end code.
Summary Verdict
- Best For: Developers building programmatic email integrations, high-volume transactional notifications, automated agentic pipelines, self-hosted email marketing platforms, or low-cost serverless backends.
- Skip If: You need an out-of-the-box human webmail interface, visual drag-and-drop campaign editors out of the box, or zero-configuration domain setup.

Amazon Simple Email Service
