You've decided to use AWS SES for cold email. Maybe you heard it's cheap. Maybe you thought it was a smart infrastructure play. Then you started reading the docs and realized AWS treats email like an afterthought compared to their core services.
Here's the reality: AWS SES works for cold email, but only if you understand what you're doing and set it up correctly. Get it wrong, and you'll land in spam consistently or hit sending limits you didn't know existed.
This guide covers what actually matters - the setup decisions that impact deliverability, the costs you'll actually pay, and the specific configurations that work for cold email campaigns at scale.
Why AWS SES for Cold Email (and When You Shouldn't)
AWS SES costs less than most alternatives - roughly $0.10 per 1,000 emails sent, plus a small charge for bounce handling. If you're running campaigns for a service business sending 50,000 emails per month, that's about $5 in sending costs alone. Sendgrid or Mailchimp cost 10-50x more at similar volumes.
The tradeoff: AWS SES requires more manual infrastructure work. You'll handle DNS setup yourself, manage bounce rates yourself, and troubleshoot deliverability issues without customer support that knows cold email.
Use AWS SES if you're technical enough to debug SMTP issues and patient enough to deal with their documentation. Don't use it if you need hand-holding or if you're sending from a brand new domain - the extra setup complexity isn't worth it when you're just starting.
The DNS Setup That Actually Impacts Deliverability
Three DNS records matter for cold email with SES: SPF, DKIM, and DMARC. Miss one, and inbox placement suffers. Here's what you need to know.
SPF Setup
Add this SPF record to your domain's DNS:
v=spf1 include:amazonses.com ~all
That's it. The "~all" at the end means soft fail - if mail comes from somewhere else, it won't hard reject. Use this for cold email domains because you might send from multiple sources and you want maximum flexibility.
DKIM Setup
AWS SES requires you to verify each sending domain with DKIM. In the SES console, go to Verified Identities, select your domain, and click "Generate DKIM Settings." AWS gives you three CNAME records to add to your DNS. Add all three - they're redundant on purpose.
Wait 24 hours after adding them. Check the status in the SES console. You'll see "DKIM Verification: Success" when it's working. Don't start sending until this shows success.
DMARC Setup
Create a DMARC record. The minimal version:
v=DMARC1; p=none; rua=mailto:[email protected]
The "p=none" policy tells mailbox providers not to block anything - just monitor. You're building reputation, not enforcing yet. Add this as a TXT record on a subdomain called "_dmarc".
Actually check DMARC reports after a few weeks. Go to postmaster.google.com and authenticate with a Gmail account from your domain. You'll see exactly how Gmail sees your sending reputation and if anything is breaking authentication.
Configuration That Prevents You From Landing in Spam
The DNS records are table stakes. The configuration determines whether people actually see your emails.
Dedicated IP vs Shared IP
AWS gives you a shared IP by default - you're sending alongside thousands of other accounts. This is terrible for cold email. Someone else on your shared IP sending spam destroys your reputation instantly.
Request a dedicated IP. Cost: about $24.95 per month in 2026. You get one IP address that only you use. Your reputation is yours alone.
Warm up the IP slowly. In week one, send 100 emails. Week two, send 500. Week three, 2,000. Week four, ramp to your target volume. This isn't marketing advice - this is how ISPs detect and block spammers. Sudden volume spikes from new IPs trigger immediate filters.
Configuration Set (Critical for Bounce Handling)
Create a Configuration Set in SES. This lets you track bounces and complaints programmatically. You need this to maintain list health.
Here's why: every time someone marks your email as spam or it hard bounces, AWS tracks it. If your bounce rate exceeds 5% or complaint rate exceeds 0.1%, AWS automatically throttles or suspends your account. You won't get an email notification - it just happens. Set up Event Publishing to SNS so you actually know when this is happening.
Specifically, configure notifications for "Bounces" and "Complaints." Point them to an SNS topic. Write a script that pulls these events and automatically removes bounced addresses from future sends. This is non-negotiable - it's how you stay under AWS's thresholds.
The Actual Sending Process and Rate Limits
AWS SES has a sending rate limit. Out of the box, you can send 1 email per second. That's 86,400 emails per day maximum. Want to send faster? Request a limit increase. AWS typically approves increases after 2-4 weeks of clean sending history.
Most cold email agencies need 3-5 emails per second to scale campaigns efficiently. Request this in advance. AWS requires you to show clean metrics - low bounce rates, low complaint rates, good authentication. Don't request it on day one.
Connect via SMTP, not the API. Use a tool like Klaviyo, Mailgun, or a custom script. Most cold email platforms (like Apollo, Hunter, Lemlist) integrate directly with SES via SMTP. Point your SMTP settings to:
Host: email-smtp.us-east-1.amazonaws.com Port: 587 Security: TLS Authentication: Use SMTP credentials from SES console
That example uses US-East-1. Pick the region closest to your location or your targets' locations - latency doesn't matter much, but consistency does.
Costs You'll Actually Pay in 2026
Sending: $0.10 per 1,000 emails. 50,000 emails = $5. Dedicated IP: $24.95 per month. Data transfer out (if you're using SES through an intermediary service): $0.09 per GB. Usually negligible for email. Total for 50,000 emails per month with dedicated IP: roughly $30-35. For comparison, Mailchimp charges $350+ per month at similar volumes. You're saving money, but only if you handle the infrastructure yourself.
Common Mistakes That Kill Deliverability
Sending too fast too soon. Don't ramp to 5 emails per second on day one. You'll trigger abuse filters.
Ignoring bounce rates. Let bounces accumulate and AWS suspends your account. This happens to roughly 10% of people who set up SES and don't monitor it actively.
Not cleaning your email list before importing. Remove invalid addresses and known spam traps first. One spam trap in a list of 10,000 can reset your reputation.
Using generic headers and footers. AWS SES doesn't automatically add unsubscribe links like Mailchimp does. You have to add them manually. If you're not including an unsubscribe header, mailbox providers treat you as spam.
Sending from a brand new domain without proper warm-up. New domains start with zero reputation. Build it slowly or you'll land in spam immediately.
Monitoring and Maintenance
Check your SES dashboard weekly. Look at bounce rate, complaint rate, and send volume. If bounce rate climbs above 3%, slow down and audit your list. If you're getting spam complaints, your messaging is off - not your infrastructure.
Monitor your sender reputation at Google Postmaster Tools. It shows you exactly how Gmail sees your domain. Red flags here are early warnings that something's breaking.
Set up CloudWatch alerts for any SES metrics trending badly. This prevents surprises - you catch problems before AWS throttles your account.
When to Consider Other Options
If you're sending under 10,000 emails per month, the effort isn't worth the savings. Use a simpler tool.
If you don't have technical capacity to debug SMTP, handle bounces programmatically, or troubleshoot DNS issues, AWS SES will frustrate you. The cost savings disappear when you're spending 20 hours learning the platform.
If you need white-glove support for deliverability issues, AWS doesn't offer that. They have forums and documentation, not dedicated support for email senders.
The Gap Between Knowing This and Running It at Scale
You can set up AWS SES. The setup itself is straightforward - DNS records, configuration, SMTP credentials. But running cold email campaigns at 50,000+ emails per month requires continuous monitoring, list management, infrastructure tweaks, and active reply handling that most people underestimate.
This is the gap between technical knowledge and operational execution. You can know exactly how AWS SES works and still spend 10+ hours per week managing infrastructure instead of focusing on your actual business. If you'd rather have someone else handle the setup, optimization, list cleaning, and ongoing monitoring while you focus on closing deals, that's what we do at BEC Growth.
Related Guides
- Cold Email Infrastructure Setup Guide: The Unsexy Foundation That Actually Gets Replies
- Cold Email Sender Reputation Guide: Stop Landing in Spam
- Cold Email Deliverability Complete Guide: Why Your Emails Aren't Landing in Inboxes
- Cold Email Sending Limits: What You Actually Need to Know
- B2B Cold Email Complete Guide 2026: What Actually Works