> ## Documentation Index
> Fetch the complete documentation index at: https://spreecommerce.org/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Amazon SES

> Send Spree's transactional emails through Amazon SES over SMTP — regional endpoints, credentials that are not your IAM keys, and the sandbox to leave before launch.

[Amazon SES](https://aws.amazon.com/ses/) is AWS's email service and the cheapest option at volume. It is the natural choice for a store already running on AWS, at the cost of more setup than the other providers: credentials work differently from the rest of AWS, and every new account starts restricted.

Spree talks to SES over plain SMTP, so there is nothing to install — see [Emails](/docs/developer/providers/emails) for how the configuration works.

## Configuration

```bash theme={"theme":"night-owl"}
SMTP_HOST=email-smtp.us-east-1.amazonaws.com
SMTP_PORT=587
SMTP_USERNAME=your_ses_smtp_username
SMTP_PASSWORD=your_ses_smtp_password
SMTP_FROM_ADDRESS=orders@yourstore.com
```

The host follows the pattern `email-smtp.<region>.amazonaws.com`. Pick the region you verified your domain in — credentials are **per region**, so a key made in one region will not authenticate in another:

| Region | SMTP endpoint |
| - | - |
| `us-east-1` (N. Virginia) | `email-smtp.us-east-1.amazonaws.com` |
| `us-west-2` (Oregon) | `email-smtp.us-west-2.amazonaws.com` |
| `eu-west-1` (Ireland) | `email-smtp.eu-west-1.amazonaws.com` |
| `eu-central-1` (Frankfurt) | `email-smtp.eu-central-1.amazonaws.com` |
| `ap-southeast-2` (Sydney) | `email-smtp.ap-southeast-2.amazonaws.com` |

**Not every SES region has an SMTP endpoint.** Cape Town, Hyderabad, Jakarta, Malaysia, Milan, Zurich, Tel Aviv, Bahrain, UAE and Calgary offer the SES API but no SMTP host, so a region that works for the API may not work here — check the [SES endpoints reference](https://docs.aws.amazon.com/general/latest/gr/ses.html#ses_smtp_endpoints) before settling on one.

Use port 587 (or 25 or 2587) for STARTTLS; 465 and 2465 are implicit TLS, which Spree does not use. SES requires TLS on every connection, so there is no unencrypted option to fall back to.

## Getting SMTP credentials

<Warning>
  **SES SMTP credentials are not your AWS access keys.** As AWS puts it, "Your SMTP password is different from your AWS secret access key." Pasting an IAM secret key into `SMTP_PASSWORD` fails to authenticate — the password is derived from that secret by a signing algorithm that takes the **region** as an input. A password derived for `us-east-1` will not authenticate against `eu-west-1`, which is why credentials cannot be shared between regions. Temporary credentials from STS cannot be used at all.
</Warning>

Create them in the console rather than deriving them by hand:

1. Open the SES console and choose **SMTP settings**.
2. Choose **Create SMTP Credentials**, which opens IAM and creates a user for sending.
3. Reveal the SMTP password, then **Download .csv file**. You cannot view the password again after closing the dialog.

Repeat this for each region you send from.

## Authenticating your domain

In the SES console, go to **Identities** and create an identity for your domain. SES generates DKIM `CNAME` records to add at your DNS host, and verifying the domain also makes production access easier to obtain. Once verified, set `SMTP_FROM_ADDRESS` to an address on it.

Verifying a domain is required regardless of sandbox status: even in production, you must verify every identity used as a From, Source, Sender or Return-Path address.

## Leaving the sandbox

Every new SES account starts in the **sandbox**, per region, and the restrictions make a live store impossible:

* You can send only **to verified addresses and domains**, so real customers never receive anything.
* A maximum of **200 recipients per rolling 24-hour period** — a message to several recipients counts once for each of them.
* A maximum of **1 message per second**.

To request production access, open the SES console, go to **Account dashboard**, and choose **Request production access**. You describe your mail as transactional, give your website URL, and confirm you handle bounces and complaints. AWS responds within 24 hours. Verifying your domain first helps the request get approved faster.

<Note>
  Sending from EC2 adds one more step: EC2 throttles port 25 by default. Using port 587 as shown above avoids it.
</Note>

## Related

* [Emails](/docs/developer/providers/emails) — the SMTP variables and how to verify delivery
* [Sending out Emails](/docs/developer/deployment/emails) — what Spree sends and when
* [Deploying Spree on AWS](/docs/developer/deployment/aws)
* [SES SMTP credentials documentation](https://docs.aws.amazon.com/ses/latest/dg/smtp-credentials.html)
