Configure Amazon SES email
Configure an SES region, sending identity, and least-privilege credentials for OpsKnight.
Before you begin
Choose the AWS account and region, obtain permission to manage SES identities and IAM credentials, and prepare a controlled recipient.
Open the feature
In OpsKnight, open Settings → Notifications → Providers → Amazon SES.
Configure Amazon SES
- In the target AWS region, verify the sending domain or email identity and complete DKIM setup.
- If the account is in the SES sandbox, verify test recipients or request production access.
- Create a dedicated IAM principal allowed to send through the chosen identity and region. Record its access-key ID and secret access key.
- In OpsKnight, open Settings → Notifications → Providers → Amazon SES. Enter the region, credentials, and verified from-address; save and enable it.
- Send a controlled test, confirm the SES message ID and delivery event, and then test the real escalation route.
What OpsKnight does
OpsKnight encrypts the AWS credentials and submits selected email notifications to SES in the configured region.
Verify the result
Confirm the OpsKnight attempt, SES message ID and delivery event, and controlled inbox receipt.
Change or undo it
Rotate the IAM key by validating the replacement in OpsKnight before deactivating the old key. Move routes before disabling SES.
Troubleshooting
Check region alignment, sandbox status, identity policy, IAM permission, quotas, bounces, and complaints when delivery fails.
Next steps
Last updated for v2.0.0
Edit this page on GitHub