Official agent skill

Amazon Ses

by aws in aws/agent-toolkit-for-aws

Guides Amazon SES onboarding for domain-based email sending.

OfficialApache-2.0Auto-check passedBackend & APIs

Install Amazon Ses

skills CLI
$ npx skills add aws/agent-toolkit-for-aws --skill amazon-ses -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/agent-toolkit-for-aws amazon-ses --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/messaging-and-streaming-skills/amazon-ses .claude/skills/amazon-ses && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
amazon-ses
GitHub stars
2.8k
Token cost
~4k tokens
SKILL.md length
2,154 words
Files
3 (incl. references)
Skills in repo
138
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides Amazon SES onboarding for domain-based email sending.

  • Resuming incomplete onboarding
  • SKILL.md covers Overview, Routing, Guardrail — where this skill's… and Critical Rules, plus 4 more sections
  • Calls aws
  • Leaving the sandbox

What it does

Amazon Ses is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Guides Amazon SES onboarding for domain-based email sending. Covers identity configuration, production access, an optional first test send, and troubleshooting setup, authentication, or sending failures. Use when setting up SES, resuming incomplete onboarding, or leaving the sandbox. Does not cover inbound email or Mail Manager, SMS/voice, WhatsApp, SNS, Pinpoint, or WorkMail.

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/onboarding.md` and `references/setting-up-ses-domain-identity.md`).

It sits in Backend & APIs, covering Transactional email. It works with Amazon Web Services, WhatsApp and Model Context Protocol. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.

When your agent uses it

  • Resuming incomplete onboarding
  • Leaving the sandbox

Example prompts

  • “Use the amazon-ses skill to guide Amazon SES onboarding for domain-based email sending”
  • “/amazon-ses”

What it can do on your machine

Read from SKILL.md and the folder at commit bd49cc8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Amazon Ses loads about 4k tokens when it runs, and up to ~23k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 2,154 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~23k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/agent-toolkit-for-aws at commit bd49cc8, republished under its Apache-2.0 licence (© aws). 2,154 words, ~3,988 tokens.

Download SKILL.mdSave it as .claude/skills/amazon-ses/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
amazon-ses
description
Guides Amazon SES onboarding for domain-based email sending. Covers identity configuration, production access, an optional first test send, and troubleshooting setup, authentication, or sending failures. Use when setting up SES, resuming incomplete onboarding, or leaving the sandbox. Does not cover inbound email or Mail Manager, SMS/voice, WhatsApp, SNS, Pinpoint, or WorkMail.
version
2

Amazon SES

Overview

Recommended: Use the AWS MCP Server with SES permissions for sandboxed execution and CloudTrail audit logging. Without MCP: All operations use standard AWS CLI syntax (aws sesv2 ...).

Takes a developer who is not an email authentication expert from an empty AWS account to a real, authenticated email in their inbox, and on to production sending if AWS approves the request.

Read the account and identity state before touching anything, and complete only the parts of domain setup that are actually missing. Request production access only after domain setup is complete and the user has given explicit consent. A test send is optional: run it when the user asks for one, to a recipient the account's current state permits.

Routing

If the user wants to...Read
Get started with SES, set up email sending, send a first or test email, move out of the sandbox, or diagnose MessageRejected: Email address is not verifiedSES onboarding: zero to first delivered email
Set up a domain for sending, configure email authentication, or troubleshoot DKIMSetting up SES domain identity

Guardrail — where this skill's own files live (MCP vs local install)

This skill can be loaded two ways, and they resolve its own bundled files from different places. Determine how the skill was loaded before reading a reference:

  • Loaded through the AWS MCP retrieve_skill tool: the skill is not on the local filesystem. You MUST fetch each reference via retrieve_skill with the file parameter (e.g. file="references/onboarding.md"). Do NOT file_read these paths locally — they do not exist on disk.
  • Installed locally (e.g. ~/.kiro/skills/amazon-ses/, .kiro/skills/amazon-ses/, or ~/.claude/skills/amazon-ses/): read files from the local skill directory using the relative paths above.

This distinction applies only to the skill's own packaged files. User data and session artifacts are always read from and written to the user's working directory — never fetch or write customer data through retrieve_skill.

Critical Rules

  • MUST use the SES v2 API: aws sesv2 ..., never the v1 aws ses ... commands. A v1 command reports no error signalling the wrong API was chosen, so the mistake is silent, and the operations this journey needs — production-access requests, and DKIM plus MAIL FROM attributes in a single identity read — exist only in v2. Models trained on published CLI examples tend to default to the v1 syntax.
  • MUST NOT volunteer API version mechanics, internal limit figures, or other plumbing. Explain only what the user has to decide, consent to, pay for, or act on. Surface the rest only when they ask, when their problem turns on it, or when a reference file names the disclosure as required.
  • MUST ask for missing inputs in ONE question set rather than one at a time — and MUST NOT ask for inputs the request does not need. Scope the questions to what the user asked for: a request that already names the domain and MAIL FROM subdomain is a complete domain-setup request, so read state and execute rather than stalling for send-time or production-access inputs. If nothing is missing for the chosen scope, ask nothing.
  • MUST NOT ask which AWS CLI profile or Region to use while either can still be resolved. Honour --profile only if the user names one. Resolve the Region in this order, taking the first that yields a value: a Region the user named; AWS_REGION; AWS_DEFAULT_REGION; aws configure get region, adding --profile '{PROFILE}' when the user named a profile, since a profile can carry its own Region. That last command reads the CLI configuration files only and does not see the environment, which is why the two environment variables are checked separately and ahead of it. State the resolved Region before any mutation, because SES state is per-Region, and report the account and principal from aws sts get-caller-identity. Two cases, and only these two, are where you do ask: nothing in that chain yields a Region, because every aws sesv2 call fails without one; and aws sts get-caller-identity fails on expired or invalid credentials, in which case ask which account (profile) and Region to use once they are refreshed, because the configured defaults are no longer trustworthy. Fold either into the one question set rather than spending an extra turn on it.
  • MUST pass request payloads (change batches and message content) to the CLI as inline JSON strings, never as file:// paths — file:// is AWS-CLI-specific and does not resolve when the CLI is executed through the AWS MCP server.
  • MUST read current state before each step and skip steps already satisfied. In particular: never call create-email-identity for an identity that already exists (it returns AlreadyExistsException), and never re-run put-email-identity-dkim-signing-attributes on an identity whose DkimAttributes.Status is SUCCESS, because re-initialising can change its tokens. Gate that call on status, not on whether the published CNAMEs resolve — on a FAILED identity the records often do resolve and are simply not being honoured, which is what FAILED means, so resolving records are not a reason to withhold the recovery. The status-gated recovery paths, and the BYODKIM check that precedes them, are owned by setting-up-ses-domain-identity.md.
  • For domain setup, create a domain identity. Create an email-address identity only when the user explicitly chooses verification of that individual address.

Invariants

These hold everywhere in this skill. The reference files apply them, and may add workflow-specific detail on top of them — a reference may state how an invariant is checked at a particular step, or narrow it for that step's state. None of them may contradict or relax what is written here.

  • Domain setup complete means all three of these are true in one aws sesv2 get-email-identity response: VerifiedForSendingStatus is true, and DkimAttributes.Status is SUCCESS, and MailFromAttributes.MailFromDomainStatus is SUCCESS. Two of the three is not complete. While MailFromDomainStatus is PENDING, FAILED or TEMPORARY_FAILURE, AWS documents that SES uses the custom MAIL FROM fallback setting: with USE_DEFAULT_VALUE it sends using a subdomain of amazonses.com, so SPF validates but the envelope sender does not align with the From domain and DMARC cannot pass on its SPF leg; with REJECT_MESSAGE SES returns MailFromDomainNotVerified and does not attempt delivery. This is the gate the rest of the skill calls "domain setup complete".
  • Sandbox recipient rule. While ProductionAccessEnabled is false, AWS documents that you can only send to verified email addresses and domains, or to the Amazon SES mailbox simulator. That means, in the order this skill always presents them: (1) an address verified as its own email identity, (2) the Amazon SES mailbox simulator, or (3) any address at any verified domain in the account — not only the domain just set up. The restriction is on the recipient, not the sender: a fully verified sending domain does not lift it, and you must never attempt to work around it. Production access is governed by ProductionAccessEnabled alone — while it is false, these three options apply whatever Details.ReviewDetails.Status says. When you explain the restriction to a user, you MUST name all three recipient options that work right now, in that same numbering, before proposing production access as the remedy, and you MUST NOT describe the restriction as "each recipient must be individually verified": a verified domain covers every address at that domain.
  • The sender must be verified too, in every account state. AWS documents that after an account moves into production "you still have to verify all identities that you use as 'From', 'Source', 'Sender', or 'Return-Path' addresses." So MessageRejected: Email address is not verified has two causes: an unpermitted recipient in the sandbox, and an unverified sending identity in any state. Read the address named in the error before choosing a fix, and check that the From address is at a domain or address verified in this Region.
  • A verified sender is the SES service minimum; this skill's journey asks for more. SES itself will accept a send from an identity that is verified for sending even when DKIM has not reached SUCCESS. This skill deliberately does not stop there: its goal is a delivered, authenticated first email, so it requires DkimAttributes.Status: SUCCESS before it claims domain setup or authentication is complete, and before it sends. That stricter bar is stated once, as the send prerequisite in onboarding.md's domain-verification step, and every send path applies it. The two are not in conflict — one is what the service enforces, the other is what this journey promises the user.
  • Validate every substituted value, then quote it for its context. A value interpolated directly into a shell command is single-quoted; a value placed inside inline JSON is JSON-encoded (double quotes, per JSON rules), and only the whole JSON blob is single-quoted for the shell — never shell-quote an individual value inside JSON. This applies to every user-supplied value this skill substitutes — DOMAIN, the MAIL FROM subdomain, FROM_ADDRESS, TEST_RECIPIENT, CHOSEN_RECIPIENT, MAIL_TYPE, WEBSITE_URL, REGION, PROFILE — not only the DNS names. Reject any value containing a single or double quote, a backtick, $, ;, a backslash, or whitespace, and ask the user to re-provide it; never escape a rejected value into shape. Per-value shapes: DOMAIN and the MAIL FROM subdomain — DNS labels only, letters, digits, hyphens and dots; From address and every recipient value, TEST_RECIPIENT and CHOSEN_RECIPIENT alike — a single address with one @, and reject a comma-separated list (put multiple recipients in the ToAddresses array instead); MAIL_TYPE — exactly TRANSACTIONAL or MARKETING; WEBSITE_URL — an http/https URL of 1–1000 characters, which need not be at the verified domain, since any business site the mail relates to is acceptable to AWS, so the question set may offer https://{DOMAIN} as a suggested default only; REGION — an AWS Region code; PROFILE — a CLI profile name. A CHOSEN_RECIPIENT bound from an option the skill supplies rather than the user — the mailbox simulator address — is validated the same way. JSON-encode any user-supplied subject or body text with a serialiser rather than pasting it between quotes.
Show full SKILL.md (536 more words)Show less

IAM Permissions

Grant only the actions the workflow being run actually calls, and nothing more — never ses:* or *FullAccess. Each reference file has a Required IAM actions section listing exactly what it calls; use that list, not a wildcard.

Scope per-identity actions to the identity each call actually acts on:

  • arn:aws:ses:{region}:{account-id}:identity/{domain} for domain operations.
  • arn:aws:ses:{region}:{account-id}:identity/{address} for an email-address identity — the identity used for sandbox recipient verification, and equally the From identity when the sender is a separately verified email address rather than an address at the domain. A policy scoped only to the domain denies those calls. Reads are scoped the same way: the ses:GetEmailIdentity statement must carry the ARN of every identity actually read, which includes a recipient address identity and — for sandbox recipient option 3 — the exact identity ARN of the other verified domain the user names. A policy scoped only to the sending domain denies that read, which reads as a broken permission rather than as a missing recipient. A send is authorized by the identity that covers its From address, so scope ses:SendEmail to whichever identity that is; the three cases are listed in onboarding.md's Required IAM actions.
  • Route 53 zone actions (route53:GetHostedZone, route53:ListResourceRecordSets, route53:ChangeResourceRecordSets) to arn:aws:route53:::hostedzone/{hosted_zone_id}, using the bare zone ID — list-hosted-zones-by-name returns /hostedzone/Z123ABC, so strip that prefix before building the ARN or the result is double-prefixed and matches nothing. The zone reads are needed whenever the agent checks whether Route 53 hosts the domain; only route53:ChangeResourceRecordSets is conditional on the user approving a write.

Only genuinely account-level and list actions (sts:GetCallerIdentity, ses:GetAccount, ses:ListEmailIdentities, route53:ListHostedZonesByName, route53:TestDNSAnswer) have no resource-level scoping and must be granted on *. Grant ses:PutAccountDetails deliberately, because it changes account-wide sending posture.

Security Considerations

  • Ephemeral credentials. Use IAM roles with STS — never long-lived access keys.
  • Consent gates. Opening a production-access review and sending a real message both commit the user in ways no API can undo, and a Route 53 change can affect live traffic. Each gate — the production-access consent gate, the send confirmation, and the DNS-write permission — is owned by the reference file that performs the action; never proceed past one because this file summarises it.
  • Delivery TLS is opportunistic by default. AWS documents that SES always attempts a secure connection to the receiving mail server and sends the message unencrypted if it cannot establish one, and that requiring TLS means setting a configuration set's TlsPolicy to REQUIRE — a configuration-set workflow outside this skill's scope.
  • Validate and quote every user-supplied value before it enters a shell command or inline JSON. The rules and character sets are under Invariants above.
  • Never place message bodies or recipient lists in logs.
  • Never hardcode credentials, endpoints, or secrets in examples. Store any application credentials in AWS Secrets Manager or Parameter Store.
  • Enable CloudTrail for SES API call auditing, and alarm on repeated AccessDeniedException and unusual send volume. Encrypt the trail's log files with an AWS KMS key (SSE-KMS) and restrict access to the trail's S3 bucket and CloudWatch Logs group, and encrypt that log group with a KMS key (--kms-key-id on create-log-group) — SES CloudTrail entries carry email addresses, domain names, and account details.

Additional Resources

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/specialized-skills/messaging-and-streaming-skills/amazon-ses of aws/agent-toolkit-for-aws.

  • SKILL.md
  • references/onboarding.md
  • references/setting-up-ses-domain-identity.md

Open the folder on GitHubat commit bd49cc8

Compare with similar skills

Amazon Ses next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Amazon Ses compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Amazon Ses this skillaws/agent-toolkit-for-aws2.8k—~4kAutomated safety check: PassApache-2.0
Better Notifybetter-notify/better-notify313—~783Automated safety check: PassMIT
AWS Serverless Edazxkane/aws-skills3674 repos~3.2kAutomated safety check: PassMIT
FoundatioFoundatioFx/Foundatio2.1k—~3.9kAutomated safety check: PassApache-2.0
Cloudflare Email Servicehodgef/apiker1273 repos~2kAutomated safety check: PassMIT
Frontmcp Channelsagentfront/frontmcp146—~3.7kAutomated safety check: PassApache-2.0

Similar skills

  • Better Notify

    better-notify/better-notify

    End-to-end typed notification infrastructure for Node.js — typed catalog of email, SMS, push, web push, WhatsApp, Slack, Discord, Telegram, and GitHub notifications with provider-agnostic transports.

    313 GitHub stars~783 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • AWS Serverless Eda

    zxkane/aws-skills

    AWS serverless and event-driven architecture expert based on Well-Architected Framework.

    367 GitHub starsUsed in 4 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Foundatio

    FoundatioFx/Foundatio

    A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.

    2.1k GitHub stars~3.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Send and receive transactional emails with Cloudflare Email Service (Email Sending + Email Routing).

    127 GitHub starsUsed in 3 repos~2k tokens
    Backend & APIsAuto-check passed
  • Frontmcp Channels

    agentfront/frontmcp

    A skill your agent uses when pushing real-time notifications or events into Claude Code (or another MCP client) sessions, or building two-way chat bridges.

    146 GitHub stars~3.7k tokensUpdated today
    Backend & APIsAuto-check passed
  • Configure

    Rich627/whatsapp-claude-plugin

    Set up the WhatsApp channel — configure the phone number, review access policy, and manage auth state.

    101 GitHub stars~1.3k tokensUpdated 2 days ago
    Backend & APIsAuto-check: notes

More from aws/agent-toolkit-for-aws

All 138 skills in this repo
  • Agent Advisor

    aws/agent-toolkit-for-aws

    Official

    Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.

    2.8k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Agents Build

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.

    2.8k GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Launch With AWS

    aws/agent-toolkit-for-aws

    Official

    Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • AWS Marketplace Metering

    aws/agent-toolkit-for-aws

    Official

    Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…

    2.8k GitHub stars~18k tokensUpdated today
    Auto-check passed
  • Agents Pay

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.

    2.8k GitHub stars~6.5k tokensUpdated today
    Auto-check: notes

Categories

Questions about Amazon Ses

What does Amazon Ses do?

Guides Amazon SES onboarding for domain-based email sending. Amazon Ses is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Guides Amazon SES onboarding for domain-based email sending.

When should I use Amazon Ses?

Amazon Ses fits situations like: resuming incomplete onboarding; leaving the sandbox.

How do I install Amazon Ses in Claude Code?

Run `npx skills add aws/agent-toolkit-for-aws --skill amazon-ses -a claude-code`. Or copy the skill folder (skills/specialized-skills/messaging-and-streaming-skills/amazon-ses in aws/agent-toolkit-for-aws) into .claude/skills/amazon-ses in your project. Claude Code loads it when a task matches its description.

How do I install Amazon Ses in Codex?

Run `npx skills add aws/agent-toolkit-for-aws --skill amazon-ses -a codex`. Or copy the skill folder (skills/specialized-skills/messaging-and-streaming-skills/amazon-ses in aws/agent-toolkit-for-aws) into .agents/skills/amazon-ses in your project. Codex loads it when a task matches its description.

Can I use Amazon Ses in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill amazon-ses -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/amazon-ses, .gemini/skills/amazon-ses, .github/skills/amazon-ses and .opencode/skills/amazon-ses in your project.

What does Amazon Ses need to run?

Going by SKILL.md and its folder, Amazon Ses needs the command-line tools its instructions call (aws).

Does Amazon Ses access the network?

SKILL.md names 1 domain. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.

Is Amazon Ses safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Amazon Ses use?

Amazon Ses is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Amazon Ses use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 19k tokens, read only when the agent opens those files.

What are the alternatives to Amazon Ses?

Skills that share tags, products or a category with Amazon Ses: Better Notify (better-notify/better-notify, 313 stars), AWS Serverless Eda (zxkane/aws-skills, 367 stars), Foundatio (FoundatioFx/Foundatio, 2.1k stars) and Cloudflare Email Service (hodgef/apiker, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Amazon Ses?

aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,816 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 7, 2026.

Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.