AWS Security ChangesHomeSearch

AWS ses: Clarified DKIM troubleshooting with region-specific hosted zones

Service: ses · 2026-09-08 · Documentation medium

File: ses/latest/dg/troubleshoot-verification.md · Type: spoofing

Summary

Updated troubleshooting example to use SigningHostedZone value instead of hardcoded domain, matching API changes.

Security assessment

Prevents misconfiguration during DKIM verification that could lead to email authentication failures and potential spoofing risks.

Evidence

The hosted zone portion of this value is the `SigningHostedZone` returned for your identity and varies by AWS Region.

Diff

diff --git a/ses/latest/dg/troubleshoot-verification.md b/ses/latest/dg/troubleshoot-verification.md
index e52bcf772..4a7c381ce 100644
--- a//ses/latest/dg/troubleshoot-verification.md
+++ b//ses/latest/dg/troubleshoot-verification.md
@@ -80 +80 @@ In our _ses-example.com_ example, if a name server that we found in step 1 was c
-In our example, we are looking for a CNAME record under `4hzwn5lmznmmjyl2pqf2agr3uzzzzxyz` __domainkey.ses-example.com_ with a value of `4hzwn5lmznmmjyl2pqf2agr3uzzzzxyz.dkim.amazonses.com`. If the record is correctly published, we would expect the command to have the following output:
+In our example, we are looking for a CNAME record under `4hzwn5lmznmmjyl2pqf2agr3uzzzzxyz` __domainkey.ses-example.com_ with a value that matches the CNAME value shown for the domain in the Identities list of the Amazon SES console. The hosted zone portion of this value is the `SigningHostedZone` returned for your identity and varies by AWS Region. If the record is correctly published, and the hosted zone for our identity is `dkim.us-west-2.amazonses.com`, we would expect the command to have the following output:
@@ -82 +82 @@ In our example, we are looking for a CNAME record under `4hzwn5lmznmmjyl2pqf2agr
-                4hzwn5lmznmmjyl2pqf2agr3uzzzzxyz_domainkey.ses-example.com canonical name = "4hzwn5lmznmmjyl2pqf2agr3uzzzzxyz.dkim.amazonses.com"
+                4hzwn5lmznmmjyl2pqf2agr3uzzzzxyz_domainkey.ses-example.com canonical name = "4hzwn5lmznmmjyl2pqf2agr3uzzzzxyz.dkim.us-west-2.amazonses.com"