skillZs
LIVE SKILL TAGS
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
REAL INSTALL DATA
← back to all skills
aws/agent-toolkit-for-aws961 installs

amazon-ses

Configures Amazon SES V2 for production email sending — including domain identity creation, DKIM/SPF/DMARC authentication, one-shot DNS record presentation, and Route 53 automation — for developers setting up or troubleshooting SES domain verification and deliverability. Applicable when developers need to send emails from their domain via SES, verify a domain identity, configure email authentication, troubleshoot DKIM verification issues, or ensure their sending setup follows best practices. Not for email-address-only verification, Mail Manager inbound routing, SNS, Pinpoint, or WorkMail.

How do I install this agent skill?

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill amazon-ses
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    This skill provides a standard and secure workflow for configuring Amazon SES domain identities using the AWS CLI. It follows AWS security best practices by recommending ephemeral credentials, least-privileged IAM roles, and standard email authentication protocols (DKIM, SPF, DMARC). No security issues were detected.

  • Socketpass

    No alerts

  • Snykpass

    Risk: LOW · No issues

What does this agent skill do?

Amazon SES

Recommended: Use the AWS MCP Server with SES permissions for sandboxed execution and CloudTrail audit logging. Without MCP: All operations use standard AWS CLI syntax (aws sesv2 ...).

Overview

This skill helps developers and DevOps engineers configure Amazon SES for production email sending. It targets users who are not email authentication experts — guiding them through complete domain setup following AWS best practices without requiring deep knowledge of DKIM, SPF, or DMARC.

Routing

If the user wants to...Read
Set up a domain for sending, configure email authentication, or troubleshoot DKIMSetting up SES domain identity

Security

  • Use IAM roles with ephemeral credentials (STS) — never long-lived access keys
  • Scope IAM permissions to specific SES actions per workflow (see reference files for required permissions)
  • Enable CloudTrail for SES API call auditing
  • DMARC p=none is monitoring only — plan progression to p=quarantine after confirming alignment
  • Never hardcode credentials, endpoints, or secrets in examples

Critical Rules

  • MUST create a domain identity (not email identity) for production sending
  • MUST configure custom MAIL FROM subdomain for SPF alignment
  • MUST configure DMARC TXT record (p=none minimum) for domain alignment
  • MUST present all DNS records together in one batch
  • MUST ask user for preferred MAIL FROM subdomain (do not assume a default)
  • SHOULD check if Route 53 hosts the domain and offer automatic DNS creation
  • SHOULD NOT claim 72-hour wait — verification typically completes in minutes once DNS propagates

Additional Resources

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/aws/agent-toolkit-for-aws/amazon-ses">View amazon-ses on skillZs</a>