- Newest
- Most votes
- Most comments
It appears there may be some misunderstanding or unexpected behavior in your SES setup. Let's clarify a few points:
-
SES should not report bounces or complaints for email addresses that were not actually sent to. This is not normal behavior.
-
The suppression list is designed to include email addresses that have previously caused hard bounces or complaints. If addresses are being added without you sending to them, this suggests there might be unauthorized use of your SES account or a misconfiguration.
-
SES showing send activity when there was none from your LightSail instance is concerning. This could indicate that someone else might be using your SMTP credentials.
-
Changing the SMTP access key is a good first step, but if the issue persists, there might be a deeper problem.
To address these issues:
- Review your AWS account for any signs of unauthorized access or use.
- Check your SES console for any unexpected configuration changes or additional authorized senders.
- Verify that no other applications or services within your organization are using the SES credentials.
- Consider enabling SES sending events logging to Amazon CloudWatch Logs for more detailed tracking of email sending activities.
- Contact AWS Support for a thorough investigation of your account activity and SES configuration.
Remember, SES is designed to accurately report on actual sending activity and maintain the suppression list based on real bounces and complaints. If you're seeing discrepancies, it's crucial to investigate further to ensure the security and proper functioning of your email sending infrastructure.
Sources
Understanding email deliverability in Amazon SES - Amazon Simple Email Service
Amazon SES and deliverability - Amazon Simple Email Service
Relevant content
- AWS OFFICIALUpdated 5 months ago
- AWS OFFICIALUpdated 3 months ago
- AWS OFFICIALUpdated 7 months ago

I strongly recommend rotating the SMTP user access key and the derived SMTP credential used by your lightsail application. If you are sending messages that you did not intend, it could mean that your SMTP user credential is compromised.
Set up condition keys on the SMTP user IAM policy, to ensure least privileged access: https://docs.aws.amazon.com/service-authorization/latest/reference/list_amazonses.html#amazonses-policy-keys
Automate the Creation & Rotation of Amazon Simple Email Service SMTP Credentials: https://aws.amazon.com/blogs/messaging-and-targeting/automate-the-creation-rotation-of-amazon-simple-email-service-smtp-credentials/
Archive outbound messages to see what you are unintentionally sending: https://aws.amazon.com/about-aws/whats-new/2025/02/ses-outbound-delivers-mail-manager-archives/