AWS ses: Updated SES API v2 DKIM record guidance with region-specific zones
Summary
Replaced SES API v1 with v2 commands, added SigningHostedZone field, and emphasized using region-specific DKIM domains instead of hardcoded values.
Security assessment
Ensures DKIM records are correctly configured per-region to prevent email spoofing by enforcing proper domain authentication.
Evidence
The hosted zone returned in `SigningHostedZone` varies by AWS Region and can differ between identities. Always use the `SigningHostedZone` value returned for your identity to construct the CNAME records, rather than a hardcoded hosted zone.
Diff
diff --git a/ses/latest/dg/send-email-authentication-dkim-easy-managing.md b/ses/latest/dg/send-email-authentication-dkim-easy-managing.md index 75a247204..f6bc55872 100644 --- a//ses/latest/dg/send-email-authentication-dkim-easy-managing.md +++ b//ses/latest/dg/send-email-authentication-dkim-easy-managing.md @@ -36 +36 @@ The following image shows an example of the expanded **View DNS records** sectio -You can also obtain the DKIM records for an identity by using the Amazon SES API. A common method of interacting with the API is to use the AWS CLI. +You can also obtain the DKIM records for an identity by using the Amazon SES API v2. A common method of interacting with the API is to use the AWS CLI. @@ -40 +40 @@ You can also obtain the DKIM records for an identity by using the Amazon SES API - 1. At the command line, type the following command: + 1. At the command line, enter the following command: @@ -42 +42 @@ You can also obtain the DKIM records for an identity by using the Amazon SES API - aws ses get-identity-dkim-attributes --identities "example.com" + aws sesv2 get-email-identity --email-identity "example.com" @@ -46 +46 @@ In the preceding example, replace `example.com` with the identity that you want - 2. The output of this command contains a `DkimTokens` section, as shown in the following example: + 2. The output of this command contains a `DkimAttributes` object. The `Tokens` array provides the DKIM tokens, and the `SigningHostedZone` field provides the hosted zone to use in the CNAME record values, as shown in the following example: @@ -50,4 +50,3 @@ In the preceding example, replace `example.com` with the identity that you want - "example.com": { - "DkimEnabled": true, - "DkimVerificationStatus": "Success", - "DkimTokens": [ + "SigningEnabled": true, + "Status": "SUCCESS", + "Tokens": [ @@ -57,2 +56,3 @@ In the preceding example, replace `example.com` with the identity that you want - ] - } + ], + "SigningAttributesOrigin": "AWS_SES", + "SigningHostedZone": "dkim.us-west-2.amazonses.com" @@ -62 +62,5 @@ In the preceding example, replace `example.com` with the identity that you want -You can use the tokens to create the CNAME records that you add to the DNS settings for your domain. To create the CNAME records, use the following template: +###### Note + +The hosted zone returned in `SigningHostedZone` varies by AWS Region and can differ between identities. Always use the `SigningHostedZone` value returned for your identity to construct the CNAME records, rather than a hardcoded hosted zone. + +You use the tokens together with the `SigningHostedZone` value to create the CNAME records that you add to the DNS settings for your domain. To create the CNAME records, use the following template: @@ -64,3 +68,3 @@ You can use the tokens to create the CNAME records that you add to the DNS setti - token1._domainkey.example.com CNAME token1.dkim.amazonses.com - token2._domainkey.example.com CNAME token2.dkim.amazonses.com - token3._domainkey.example.com CNAME token3.dkim.amazonses.com + token1._domainkey.example.com CNAME token1.SigningHostedZone + token2._domainkey.example.com CNAME token2.SigningHostedZone + token3._domainkey.example.com CNAME token3.SigningHostedZone @@ -68 +72 @@ You can use the tokens to create the CNAME records that you add to the DNS setti -Replace each instance of `token1` with the first token in the list you received when you ran the `get-identity-dkim-attributes` command, replace all instances of `token2` with the second token in the list, and replace all instances of `token3` with the third token in the list. +Replace each instance of `token1`, `token2`, and `token3` with the first, second, and third tokens from the `Tokens` array. Replace each instance of `SigningHostedZone` with the `SigningHostedZone` value returned for your identity. @@ -70 +74 @@ Replace each instance of `token1` with the first token in the list you received -For example, applying this template to the tokens shown in the preceding example produces the following records: +For example, applying this template to the values shown in the preceding example produces the following records: @@ -72,3 +76,3 @@ For example, applying this template to the tokens shown in the preceding example - hirjd4exampled5477y22yd23ettobi._domainkey.example.com CNAME hirjd4exampled5477y22yd23ettobi.dkim.amazonses.com - v3rnz522czcl46quexamplek3efo5o6x._domainkey.example.com CNAME v3rnz522czcl46quexamplek3efo5o6x.dkim.amazonses.com - y4examplexbhyhnsjcmtvzotfvqjmdqoj._domainkey.example.com CNAME y4examplexbhyhnsjcmtvzotfvqjmdqoj.dkim.amazonses.com + hirjd4exampled5477y22yd23ettobi._domainkey.example.com CNAME hirjd4exampled5477y22yd23ettobi.dkim.us-west-2.amazonses.com + v3rnz522czcl46quexamplek3efo5o6x._domainkey.example.com CNAME v3rnz522czcl46quexamplek3efo5o6x.dkim.us-west-2.amazonses.com + y4examplexbhyhnsjcmtvzotfvqjmdqoj._domainkey.example.com CNAME y4examplexbhyhnsjcmtvzotfvqjmdqoj.dkim.us-west-2.amazonses.com @@ -81 +85 @@ For example, applying this template to the tokens shown in the preceding example -Not all AWS Regions use the default SES DKIM domain, `dkim.amazonses.com`—to see if your region uses a region specific DKIM domain, check the [DKIM domains table](https://docs.aws.amazon.com/general/latest/gr/ses.html#ses_dkim_domains) in the _AWS General Reference_. +SES uses various DKIM hosted zones that might differ per AWS Region and email identity. Always use the `SigningHostedZone` value returned by the [CreateEmailIdentity](https://docs.aws.amazon.com/ses/latest/APIReference-V2/API_CreateEmailIdentity.html) or [GetEmailIdentity](https://docs.aws.amazon.com/ses/latest/APIReference-V2/API_GetEmailIdentity.html) operation to construct your CNAME records.