Skip to content

About SES DKIM records

1

There are 3 CNAME records in the SES DKIM settings, why do I need 3 settings? Is it ok to set only one of the three CNAME records to the domain's DNS settings?

2 Answers
1

SES requires 3 CNAME records for DKIM. When sending email only one of the DKIM keys are active and used for sending messages SES will rotate the key in use for you

https://docs.aws.amazon.com/ses/latest/dg/send-email-authentication-dkim-easy.html#send-email-authentication-dkim-easy-setup-domain

If you would like to use just one record you can use BYODKIM and create just one record https://docs.aws.amazon.com/ses/latest/dg/send-email-authentication-dkim-bring-your-own.html

AWS
SUPPORT ENGINEER
answered 3 years ago
  • AWS, any idea why two of three CNAME are not resolving correctly? Getting error of "No DKIM Record found (I'm using maxtoolbox.com). One record replied with "DKIM Record found" and passed "DKIM Syntax Check"

0

Only one DKIM is in use at any one time. It is normal for only one to resolve correctly while the other two do not resolve

AWS
SUPPORT ENGINEER
answered 7 months ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.