Skip to content

DKIM in SES is misteriously being configured. How do i stop this from happening?

0

For about a year now, every few months I receive email notifications from AWS that a new DKIM was set up in a region for a domain that i did not do. Sometimes it will happen multiple times a day. I am the root user, I have changed the password. I do not know how this is happening. I suspect somethiung is not properly secured. How do i go about finding out who is setting up the DKIM in random regions with random domains and how do i prevent this from happening again. For now, i have manually been going to the region and deleting the domain. Any help is appreciated.

1 Answer
0

Hello.

Please check the CloudTrail event history for the region where Amazon SES was operated.
I think it's possible to identify who performed the operation from the CloudTrail event history.
Once you have identified the person who performed the operation, I recommend that you delete the relevant IAM user, etc.
https://docs.aws.amazon.com/awscloudtrail/latest/userguide/tutorial-event-history.html

EXPERT

answered a year ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.