AWS Security ChangesHomeSearch

AWS ses: Clarify DKIM record setup using SigningHostedZone

Service: ses · 2026-09-08 · Documentation medium

File: ses/latest/dg/regions.md · Type: authentication

Summary

Updated guidance to use SigningHostedZone value for DKIM CNAME records

Security assessment

Ensures proper DKIM configuration to prevent email spoofing

Evidence

+SES uses various DKIM hosted zones that might differ per AWS Region and email identity. Always use the `SigningHostedZone` value returned by the [CreateEmailIdentity](https://docs.aws.amazon.com/ses/latest/APIReference-V2/API_CreateEmailIdentity.html) or [GetEmailIdentity](https://docs.aws.amazon.com/ses/latest/APIReference-V2/API_GetEmailIdentity.html) operation to construct your CNAME records.

Diff

diff --git a/ses/latest/dg/regions.md b/ses/latest/dg/regions.md
index 3291882a8..52bfd1e77 100644
--- a//ses/latest/dg/regions.md
+++ b//ses/latest/dg/regions.md
@@ -77 +77 @@ You have to perform the Easy DKIM setup process for each AWS Region where you wa
-Not all AWS Regions use the default SES DKIM domain, `dkim.amazonses.com`—to see if your region uses a region specific DKIM domain, check the [DKIM domains table](https://docs.aws.amazon.com/general/latest/gr/ses.html#ses_dkim_domains) in the _AWS General Reference_.
+SES uses various DKIM hosted zones that might differ per AWS Region and email identity. Always use the `SigningHostedZone` value returned by the [CreateEmailIdentity](https://docs.aws.amazon.com/ses/latest/APIReference-V2/API_CreateEmailIdentity.html) or [GetEmailIdentity](https://docs.aws.amazon.com/ses/latest/APIReference-V2/API_GetEmailIdentity.html) operation to construct your CNAME records. For more information, see [Managing Easy DKIM and BYODKIM](./send-email-authentication-dkim-easy-managing.html).