Amazon SES supports DKIM signing to authenticate your messages and improve deliverability. This tutorial walks through enabling DKIM for a domain identity, publishing the required DNS records in Cloudflare (or your DNS), and validating the setup. We also cover best practices like key rotation and alignment with DMARC.
example.com).SES issues three CNAME records pointing to dkim.amazonses.com. Add them in your DNS:
selector1._domainkey.example.com. IN CNAME selector1.example.com.dkim.amazonses.com.
selector2._domainkey.example.com. IN CNAME selector2.example.com.dkim.amazonses.com.
selector3._domainkey.example.com. IN CNAME selector3.example.com.dkim.amazonses.com.
These records allow SES to serve public keys that receivers use to validate signatures.
For SPF alignment, set a custom MAIL FROM domain (e.g., mail.example.com) so the return-path aligns with your organizational domain. Publish the TXT SPF record and the required MX and (optional) TXT for bounce handling.
DKIM-Signature and Authentication-Results showing dkim=pass.d=example.com in DKIM should match the visible From: domain.p=none initially to collect aggregate reports, then move towards enforcement.d= domains that break alignment.d= domain, or use custom MAIL FROM for SPF alignment.With SES DKIM enabled and DMARC aligned, your messages will carry strong authentication and improved trust with major receivers.