AWS ses: Clarify DKIM record setup using SigningHostedZone
Summary
Updated guidance to use SigningHostedZone value for DKIM CNAME records
Security assessment
Ensures proper DKIM configuration to prevent email spoofing
Evidence
+SES uses various DKIM hosted zones that might differ per AWS Region and email identity. Always use the `SigningHostedZone` value returned by the [CreateEmailIdentity](https://docs.aws.amazon.com/ses/latest/APIReference-V2/API_CreateEmailIdentity.html) or [GetEmailIdentity](https://docs.aws.amazon.com/ses/latest/APIReference-V2/API_GetEmailIdentity.html) operation to construct your CNAME records.
Diff
diff --git a/ses/latest/dg/regions.md b/ses/latest/dg/regions.md index 3291882a8..52bfd1e77 100644 --- a//ses/latest/dg/regions.md +++ b//ses/latest/dg/regions.md @@ -77 +77 @@ You have to perform the Easy DKIM setup process for each AWS Region where you wa -Not all AWS Regions use the default SES DKIM domain, `dkim.amazonses.com`—to see if your region uses a region specific DKIM domain, check the [DKIM domains table](https://docs.aws.amazon.com/general/latest/gr/ses.html#ses_dkim_domains) in the _AWS General Reference_. +SES uses various DKIM hosted zones that might differ per AWS Region and email identity. Always use the `SigningHostedZone` value returned by the [CreateEmailIdentity](https://docs.aws.amazon.com/ses/latest/APIReference-V2/API_CreateEmailIdentity.html) or [GetEmailIdentity](https://docs.aws.amazon.com/ses/latest/APIReference-V2/API_GetEmailIdentity.html) operation to construct your CNAME records. For more information, see [Managing Easy DKIM and BYODKIM](./send-email-authentication-dkim-easy-managing.html).