AWS Security ChangesHomeSearch

AWS ses: Updated SES API v2 DKIM record guidance with region-specific zones

Service: ses · 2026-09-08 · Documentation medium

File: ses/latest/dg/send-email-authentication-dkim-easy-managing.md · Type: spoofing

Summary

Replaced SES API v1 with v2 commands, added SigningHostedZone field, and emphasized using region-specific DKIM domains instead of hardcoded values.

Security assessment

Ensures DKIM records are correctly configured per-region to prevent email spoofing by enforcing proper domain authentication.

Evidence

The hosted zone returned in `SigningHostedZone` varies by AWS Region and can differ between identities. Always use the `SigningHostedZone` value returned for your identity to construct the CNAME records, rather than a hardcoded hosted zone.

Diff

diff --git a/ses/latest/dg/send-email-authentication-dkim-easy-managing.md b/ses/latest/dg/send-email-authentication-dkim-easy-managing.md
index 75a247204..f6bc55872 100644
--- a//ses/latest/dg/send-email-authentication-dkim-easy-managing.md
+++ b//ses/latest/dg/send-email-authentication-dkim-easy-managing.md
@@ -36 +36 @@ The following image shows an example of the expanded **View DNS records** sectio
-You can also obtain the DKIM records for an identity by using the Amazon SES API. A common method of interacting with the API is to use the AWS CLI.
+You can also obtain the DKIM records for an identity by using the Amazon SES API v2. A common method of interacting with the API is to use the AWS CLI.
@@ -40 +40 @@ You can also obtain the DKIM records for an identity by using the Amazon SES API
-  1. At the command line, type the following command:
+  1. At the command line, enter the following command:
@@ -42 +42 @@ You can also obtain the DKIM records for an identity by using the Amazon SES API
-        aws ses get-identity-dkim-attributes --identities "example.com"
+        aws sesv2 get-email-identity --email-identity "example.com"
@@ -46 +46 @@ In the preceding example, replace `example.com` with the identity that you want
-  2. The output of this command contains a `DkimTokens` section, as shown in the following example:
+  2. The output of this command contains a `DkimAttributes` object. The `Tokens` array provides the DKIM tokens, and the `SigningHostedZone` field provides the hosted zone to use in the CNAME record values, as shown in the following example:
@@ -50,4 +50,3 @@ In the preceding example, replace `example.com` with the identity that you want
-            "example.com": {
-                "DkimEnabled": true,
-                "DkimVerificationStatus": "Success",
-                "DkimTokens": [
+            "SigningEnabled": true,
+            "Status": "SUCCESS",
+            "Tokens": [
@@ -57,2 +56,3 @@ In the preceding example, replace `example.com` with the identity that you want
-                ]
-            }
+            ],
+            "SigningAttributesOrigin": "AWS_SES",
+            "SigningHostedZone": "dkim.us-west-2.amazonses.com"
@@ -62 +62,5 @@ In the preceding example, replace `example.com` with the identity that you want
-You can use the tokens to create the CNAME records that you add to the DNS settings for your domain. To create the CNAME records, use the following template:
+###### Note
+
+The hosted zone returned in `SigningHostedZone` varies by AWS Region and can differ between identities. Always use the `SigningHostedZone` value returned for your identity to construct the CNAME records, rather than a hardcoded hosted zone.
+
+You use the tokens together with the `SigningHostedZone` value to create the CNAME records that you add to the DNS settings for your domain. To create the CNAME records, use the following template:
@@ -64,3 +68,3 @@ You can use the tokens to create the CNAME records that you add to the DNS setti
-        token1._domainkey.example.com CNAME token1.dkim.amazonses.com
-    token2._domainkey.example.com CNAME token2.dkim.amazonses.com
-    token3._domainkey.example.com CNAME token3.dkim.amazonses.com
+        token1._domainkey.example.com CNAME token1.SigningHostedZone
+    token2._domainkey.example.com CNAME token2.SigningHostedZone
+    token3._domainkey.example.com CNAME token3.SigningHostedZone
@@ -68 +72 @@ You can use the tokens to create the CNAME records that you add to the DNS setti
-Replace each instance of `token1` with the first token in the list you received when you ran the `get-identity-dkim-attributes` command, replace all instances of `token2` with the second token in the list, and replace all instances of `token3` with the third token in the list. 
+Replace each instance of `token1`, `token2`, and `token3` with the first, second, and third tokens from the `Tokens` array. Replace each instance of `SigningHostedZone` with the `SigningHostedZone` value returned for your identity.
@@ -70 +74 @@ Replace each instance of `token1` with the first token in the list you received
-For example, applying this template to the tokens shown in the preceding example produces the following records:
+For example, applying this template to the values shown in the preceding example produces the following records:
@@ -72,3 +76,3 @@ For example, applying this template to the tokens shown in the preceding example
-        hirjd4exampled5477y22yd23ettobi._domainkey.example.com CNAME hirjd4exampled5477y22yd23ettobi.dkim.amazonses.com
-    v3rnz522czcl46quexamplek3efo5o6x._domainkey.example.com CNAME v3rnz522czcl46quexamplek3efo5o6x.dkim.amazonses.com
-    y4examplexbhyhnsjcmtvzotfvqjmdqoj._domainkey.example.com CNAME y4examplexbhyhnsjcmtvzotfvqjmdqoj.dkim.amazonses.com
+        hirjd4exampled5477y22yd23ettobi._domainkey.example.com CNAME hirjd4exampled5477y22yd23ettobi.dkim.us-west-2.amazonses.com
+    v3rnz522czcl46quexamplek3efo5o6x._domainkey.example.com CNAME v3rnz522czcl46quexamplek3efo5o6x.dkim.us-west-2.amazonses.com
+    y4examplexbhyhnsjcmtvzotfvqjmdqoj._domainkey.example.com CNAME y4examplexbhyhnsjcmtvzotfvqjmdqoj.dkim.us-west-2.amazonses.com
@@ -81 +85 @@ For example, applying this template to the tokens shown in the preceding example
-Not all AWS Regions use the default SES DKIM domain, `dkim.amazonses.com`—to see if your region uses a region specific DKIM domain, check the [DKIM domains table](https://docs.aws.amazon.com/general/latest/gr/ses.html#ses_dkim_domains) in the _AWS General Reference_.
+SES uses various DKIM hosted zones that might differ per AWS Region and email identity. Always use the `SigningHostedZone` value returned by the [CreateEmailIdentity](https://docs.aws.amazon.com/ses/latest/APIReference-V2/API_CreateEmailIdentity.html) or [GetEmailIdentity](https://docs.aws.amazon.com/ses/latest/APIReference-V2/API_GetEmailIdentity.html) operation to construct your CNAME records.