Skip to main content
Amazon SES is AWS’s email service and the cheapest option at volume. It is the natural choice for a store already running on AWS, at the cost of more setup than the other providers: credentials work differently from the rest of AWS, and every new account starts restricted. Spree talks to SES over plain SMTP, so there is nothing to install — see Emails for how the configuration works.

Configuration

The host follows the pattern email-smtp.<region>.amazonaws.com. Pick the region you verified your domain in — credentials are per region, so a key made in one region will not authenticate in another: Not every SES region has an SMTP endpoint. Cape Town, Hyderabad, Jakarta, Malaysia, Milan, Zurich, Tel Aviv, Bahrain, UAE and Calgary offer the SES API but no SMTP host, so a region that works for the API may not work here — check the SES endpoints reference before settling on one. Use port 587 (or 25 or 2587) for STARTTLS; 465 and 2465 are implicit TLS, which Spree does not use. SES requires TLS on every connection, so there is no unencrypted option to fall back to.

Getting SMTP credentials

SES SMTP credentials are not your AWS access keys. As AWS puts it, “Your SMTP password is different from your AWS secret access key.” Pasting an IAM secret key into SMTP_PASSWORD fails to authenticate — the password is derived from that secret by a signing algorithm that takes the region as an input. A password derived for us-east-1 will not authenticate against eu-west-1, which is why credentials cannot be shared between regions. Temporary credentials from STS cannot be used at all.
Create them in the console rather than deriving them by hand:
  1. Open the SES console and choose SMTP settings.
  2. Choose Create SMTP Credentials, which opens IAM and creates a user for sending.
  3. Reveal the SMTP password, then Download .csv file. You cannot view the password again after closing the dialog.
Repeat this for each region you send from.

Authenticating your domain

In the SES console, go to Identities and create an identity for your domain. SES generates DKIM CNAME records to add at your DNS host, and verifying the domain also makes production access easier to obtain. Once verified, set SMTP_FROM_ADDRESS to an address on it. Verifying a domain is required regardless of sandbox status: even in production, you must verify every identity used as a From, Source, Sender or Return-Path address.

Leaving the sandbox

Every new SES account starts in the sandbox, per region, and the restrictions make a live store impossible:
  • You can send only to verified addresses and domains, so real customers never receive anything.
  • A maximum of 200 recipients per rolling 24-hour period — a message to several recipients counts once for each of them.
  • A maximum of 1 message per second.
To request production access, open the SES console, go to Account dashboard, and choose Request production access. You describe your mail as transactional, give your website URL, and confirm you handle bounces and complaints. AWS responds within 24 hours. Verifying your domain first helps the request get approved faster.
Sending from EC2 adds one more step: EC2 throttles port 25 by default. Using port 587 as shown above avoids it.