How do I get Amazon SES out of the sandbox?
Every new Amazon SES account starts in the sandbox. You can use every SES feature, but you can only send to addresses you have verified. Before Broadcast can mail a real list through SES, you request production access. AWS usually answers within 24 hours.
What the sandbox limits
While your account is in the sandbox, SES lets you:
- send only to verified email addresses and domains, or to the SES mailbox simulator
- send at most 200 messages in 24 hours
- send at most 1 message per second
The sandbox is per AWS region. If you verified your domain in us-east-1 and later switch Broadcast to eu-west-1, that region needs its own production access request.
A Broadcast campaign to unverified subscribers fails while you are in the sandbox. The emails are rejected by SES, not by Broadcast.
Before you request access
AWS approves requests faster when the account already looks like a careful sender. Do these first:
- Verify your sending domain in SES, not just a single address, and publish the DKIM records SES gives you. Our DKIM checker confirms they are live.
- Publish SPF and DMARC for the domain. Check all three with the DMARC checker.
- Connect SES to Broadcast with the setup wizard. It wires up bounce and complaint notifications, so bounced and complaining addresses stop receiving mail automatically. That is the process AWS asks you to confirm you have.
- Have a website at the domain you send from, with a sign-up form or a clear description of what subscribers receive.
How to request production access
- Open the Amazon SES console and choose Account dashboard.
- In the box that says your account is in the sandbox, choose View Get set up page, then Request production access.
- Pick Marketing if most of what you send is newsletters and campaigns, or Transactional if it is mostly receipts and account email.
- Enter your website URL.
- Add up to four contact addresses for AWS to reach you.
- Tick the acknowledgement that you only send to people who asked for your email and that you handle bounces and complaints.
- Choose Submit request.
You can’t edit the request while it is under review. You can also submit it from the AWS CLI with aws sesv2 put-account-details --production-access-enabled.
What to write so it gets approved
If AWS asks for more detail, or the form gives you room for it, answer these plainly:
- How you collect addresses. For example: “Subscribers sign up through a form on example.com and confirm with double opt-in. We never buy or rent lists.”
- What you send and how often. For example: “A weekly newsletter to about 8,000 subscribers, plus welcome emails when someone signs up.”
- How you handle bounces and complaints. For example: “We send through Broadcast, which receives SES bounce and complaint notifications and stops mailing those addresses automatically.”
- How people unsubscribe. For example: “Every email has a one-click unsubscribe link and List-Unsubscribe header. Unsubscribes take effect immediately.”
Specific numbers and a real website get approved. Vague answers, a new domain with no site, or any hint of purchased lists get follow-up questions or a denial.
If your request is denied
AWS explains why in its reply. The usual reasons are a missing website, an unclear use case, or a list whose origin isn’t described. Fix what they point to and reply on the same support case with the details. Don’t open a new request right away: replying to the case keeps the history together.
After you’re approved
AWS sets your starting sending quota (emails per 24 hours) and maximum send rate, shown on the Account dashboard. Both go up as you send steadily with low bounce and complaint rates. You can also request an increase from the console.
Set your email server’s hourly limit in Broadcast (emails per hour) so it stays inside your SES quota, and warm up a new domain gradually. See how to warm up an email domain.
For the cost side, see Amazon SES pricing.