惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cyberwarzone
Cyberwarzone
Vercel News
Vercel News
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
aimingoo的专栏
aimingoo的专栏
B
Blog RSS Feed
A
About on SuperTechFans
T
The Blog of Author Tim Ferriss
爱范儿
爱范儿
腾讯CDC
S
SegmentFault 最新的问题
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
The Hacker News
The Hacker News
J
Java Code Geeks
大猫的无限游戏
大猫的无限游戏
B
Blog
IT之家
IT之家
Spread Privacy
Spread Privacy
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
C
Cisco Blogs
Recent Announcements
Recent Announcements
H
Hacker News: Front Page
AI
AI
I
InfoQ
H
Heimdal Security Blog
T
Threatpost
Cisco Talos Blog
Cisco Talos Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
I
Intezer
W
WeLiveSecurity
SecWiki News
SecWiki News
MongoDB | Blog
MongoDB | Blog
宝玉的分享
宝玉的分享
博客园 - 【当耐特】
云风的 BLOG
云风的 BLOG
T
Threat Research - Cisco Blogs
V2EX - 技术
V2EX - 技术
N
News and Events Feed by Topic
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
O
OpenAI News
阮一峰的网络日志
阮一峰的网络日志
T
Troy Hunt's Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
博客园 - 司徒正美
Apple Machine Learning Research
Apple Machine Learning Research
雷峰网
雷峰网
T
Tor Project blog
有赞技术团队
有赞技术团队
Schneier on Security
Schneier on Security
Last Week in AI
Last Week in AI

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Your AWS Cognito Emails Are Going to Spam — Here Is How to Fix It Step by Step
Tanseer · 2026-04-28 · via DEV Community

A beginner-friendly guide to setting up SPF, DKIM, DMARC, Amazon SES, and custom email templates so your emails actually reach the inbox

Who This Guide Is For

If you are building an app on AWS and using Cognito to handle user sign-up and login, you have probably noticed that Cognito sends emails automatically — a verification email when someone signs up, and a password reset email when they forget their password.

But if those emails are landing in spam, or not arriving at all, this guide is for you.

We are going to fix that problem from scratch. No prior knowledge of email infrastructure is assumed. Every term will be explained.


What Is the Problem, Exactly?

When your app sends an email from something like no-reply@yourdomain.com, the email does not go directly from your laptop to the user's inbox. It travels through mail servers, and along the way, the receiving server (Gmail, Outlook, etc.) checks a simple question:

"Can I trust that this email actually came from this domain?"

If the answer is unclear or no, the email gets flagged as spam — or silently dropped.

To answer that question, three things need to be in place on your domain: SPF, DKIM, and DMARC. These are DNS records (small pieces of configuration stored on your domain) that prove your emails are legitimate.

We will set all of them up in this guide.


The Stack We Are Working With

Here is what this guide assumes:

  • You have an AWS account
  • You have a Cognito User Pool set up (or are planning to set one up)
  • Your domain is managed in Route 53 (AWS's DNS service)
  • You want Cognito to send emails from your custom domain, like no-reply@yourdomain.com

If your domain is with GoDaddy, Namecheap, or another provider, the DNS steps will look slightly different in their interface, but the records you need to add are identical.


Step 1: Understand What Amazon SES Is

Before we do anything, let us understand a key service: Amazon SES.

SES stands for Simple Email Service. It is AWS's service for sending emails. By default, Cognito uses its own basic email system, which has very low sending limits and no support for custom domains. That is why emails look generic and often end up in spam.

The fix is to connect Cognito to SES, and configure SES properly with your domain. SES is free for low volumes, and the setup is a one-time thing.


Step 2: Verify Your Domain in Amazon SES

Before SES can send emails on behalf of your domain, it needs to confirm that you actually own it. This is called domain verification.

Here is how to do it:

  1. Log in to the AWS Console and search for "Amazon SES" in the top search bar.
  2. In the left sidebar, click "Verified identities".
  3. Click "Create identity".
  4. Choose "Domain" and type your domain name (for example, mydomain.com).
  5. If your domain is in Route 53, check the option that says "Use Route 53 to publish DNS records automatically." AWS will handle the DNS setup for you.
  6. Click "Create identity".

If you are not using Route 53, SES will show you a CNAME record that you need to manually add in your DNS provider's dashboard. Copy it exactly as shown and add it there.

Once AWS detects the record, the status will change to "Verified". This can take anywhere from a few minutes to a couple of hours.


Step 3: Set Up DKIM

DKIM stands for DomainKeys Identified Mail. Think of it like a wax seal on a letter — it proves the email came from you and was not tampered with in transit.

Every email sent through SES gets a digital signature. The receiving server checks that signature against a public key stored in your DNS. If they match, the email is trusted.

When you verified your domain in the previous step, SES automatically generated DKIM keys for you. You just need to add the DNS records.

SES will show you three CNAME records under the "DKIM signatures" section of your verified identity. If you used Route 53 automatic publishing, these are already added. If not, copy all three and add them as CNAME records in your DNS provider.

Once AWS confirms the records are live, DKIM status will show "Verified."


Step 4: Set Up SPF

SPF stands for Sender Policy Framework. It is a DNS record that tells the world which servers are allowed to send email from your domain.

Without SPF, anyone could send an email claiming to be from your domain. Receiving servers know this, which is why they check for it.

Here is how to add it:

  1. Go to Route 53 in the AWS Console.
  2. Click "Hosted zones" and open your domain.
  3. Click "Create record".
  4. Set the record type to "TXT".
  5. Leave the record name empty (or use @ if required).
  6. In the value field, paste this exactly:
"v=spf1 include:amazonses.com ~all"

Enter fullscreen mode Exit fullscreen mode

  1. Click "Create records".

What this record says: emails from this domain are allowed to come from Amazon SES servers. The ~all at the end means "treat anything else with suspicion but do not block it outright." This is the safe starting point.


Step 5: Set Up DMARC

DMARC stands for Domain-based Message Authentication, Reporting and Conformance. It is the policy that ties SPF and DKIM together.

DMARC tells receiving servers: "Here is what to do if my emails fail the SPF or DKIM check." Without DMARC, servers make their own decisions, and those decisions often mean spam folder.

Here is how to add it:

  1. In Route 53, go to your hosted zone again.
  2. Create another TXT record.
  3. Set the record name to _dmarc (Route 53 will automatically append your domain, making it _dmarc.yourdomain.com).
  4. In the value field, paste this:
"v=DMARC1; p=quarantine; rua=mailto:youremail@yourdomain.com"

Enter fullscreen mode Exit fullscreen mode

  1. Replace the email address with one you actually check.
  2. Click "Create records".

What each part means:

  • v=DMARC1 — this is a DMARC record
  • p=quarantine — if authentication fails, send the email to spam (safer than p=reject when you are just starting, which would block emails entirely)
  • rua=mailto:... — where AWS should send weekly reports about your email activity

Once you are confident your setup is working correctly, you can upgrade to p=reject to fully block unauthenticated emails.


Step 6: Exit the SES Sandbox

Every new AWS account starts in something called the SES sandbox. In sandbox mode, you can only send emails to addresses you have manually verified. This is a security measure AWS uses to prevent spam from new accounts.

The problem is, your real users have not verified their emails with AWS. So if you are still in sandbox mode, your emails will fail silently.

To exit the sandbox:

  1. Go to Amazon SES in the AWS Console.
  2. Click "Account dashboard" in the left sidebar.
  3. Under "Sending limits", you will see a message about sandbox mode. Click "Request production access".
  4. Fill in the short form. Select "Transactional" as the mail type (since you are sending verification and password reset emails, not marketing).
  5. Describe your use case clearly: something like "Sending user verification and password reset emails for a web application."
  6. Submit the request.

AWS typically approves this within a few hours to one business day. You will get an email confirmation once approved.


Step 7: Connect Cognito to SES

Now that SES is properly configured, you need to tell Cognito to use it instead of its default email system.

  1. Go to the AWS Console and open "Amazon Cognito".
  2. Click on your User Pool.
  3. Go to the "Messaging" tab.
  4. Under "Email", click "Edit".
  5. Change the "Email provider" from "Send email with Cognito" to "Send email with Amazon SES".
  6. Under "SES Region", choose the same region where you set up your SES identity.
  7. Under "FROM email address", enter no-reply@yourdomain.com (or whatever address you want to send from, as long as the domain is verified in SES).
  8. Optionally, set a "FROM sender name" like "MyApp Support". This is what appears as the sender name in the user's inbox.
  9. Save the changes.

From this point on, all Cognito emails — verifications and password resets — will go through your verified SES identity with proper authentication.


Step 8: Customize Your Email Templates

This step is optional but strongly recommended, especially for beginner projects. Cognito's default email messages are very generic, and a branded email builds trust with users (and also looks less like spam to mail filters).

In the same "Messaging" section of your Cognito User Pool:

  1. Click on "Message templates".
  2. You will see options for "Verification message" and "Password reset message".
  3. Click edit on each one.
  4. You can write a plain text or HTML message. Here is a simple example for the verification email:
Subject: Verify your email for MyApp

Hi,

Thank you for signing up. Please verify your email address by entering the code below in the app:

Your verification code: {####}

If you did not sign up for MyApp, you can ignore this email.

Regards,
The MyApp Team

Enter fullscreen mode Exit fullscreen mode

The {####} placeholder is automatically replaced by Cognito with the actual verification code or link.

Keep the message clear, short, and professional. Avoid using words like "free", "click here", or excessive capitalization, as these can trigger spam filters even when authentication is correct.


How to Confirm Everything Is Working

After setting everything up, use a free tool called MXToolbox to verify your DNS records:

  • Go to MXToolbox and run an "SPF Lookup" for your domain. You should see the SES include statement in the result.
  • Run a "DMARC Lookup" for your domain. You should see your DMARC policy.
  • For DKIM, you can run a "DKIM Lookup" using the selector that SES provided.

To test the full email delivery, use Mail Tester. It gives you a temporary email address. Trigger a verification email from your Cognito signup flow to that address, then check your score. A score of 8 or higher means your setup is solid.


Quick Checklist Before You Go Live

Before launching your app to real users, confirm the following:

  • Domain is verified in Amazon SES
  • DKIM records (3 CNAMEs) are added and verified
  • SPF TXT record is added to your domain
  • DMARC TXT record is added to _dmarc.yourdomain.com
  • SES sandbox mode has been exited (production access approved)
  • Cognito is configured to use SES as the email provider
  • Custom email templates are set up with a clear sender name and message

Conclusion

Email deliverability is one of those things that most developers only think about after something breaks. Verification emails going to spam, users not completing sign-up, support tickets about missing password reset emails — these are all symptoms of the same root cause: an unauthenticated domain.

The good news is that fixing it is straightforward. SPF, DKIM, and DMARC are one-time DNS configurations. Connecting Cognito to SES takes less than ten minutes. And once it is done, your emails will reliably reach inboxes.

If you are building something on AWS and handling user authentication, getting this right early will save you a lot of headaches later.


Need Help?

If you run into any issues with the setup — whether it is a DNS record that does not verify, SES sandbox approval, or connecting things in Cognito — feel free to reach out. I am happy to walk you through it.

Email me at khantanseer43@gmail.com


AWS #AmazonSES #Cognito #EmailDeliverability #SPF #DKIM #DMARC #Route53 #Serverless #AWSCommunity #CloudComputing #BackendDevelopment #AWSBuilder #EmailAuthentication #LearnAWS #WebDevelopment