Description
An SES identity policy controls permissions for an email address or domain. Granting broad actions to principals that do not need them can permit unwanted sending or identity-management operations. Separate required sending and management actions, and review the policy's principals, resources and conditions together.
An action wildcard in an SES policy does not by itself grant IAM service administration. Actual permissions depend on a valid policy and the related access controls.
Potential impact
- Unintended sending permissions can enable unwanted email and harm domain reputation.
- Unnecessary identity-management permissions can affect configuration or normal mail processing.
Remediation
- Inspect the actual identity policy and specify required SES actions and approved principals. Remove unnecessary action and principal wildcards.
- Set
Resourceto the SES identity's ARN. Where needed, use supported conditions to limit sender addresses or recipients. An account ARN ending in:rootdelegates to the account, not only its root user. - Apply the policy with a supported module, read back the actual policy, and test that required operations succeed while unintended operations are denied.
Examples
Set ses_identity to an email address or domain verified in the specified account and Region. aws_account_id and aws_region identify that owner and Region; sender_account_id is the approved sending account. Actual sending also requires appropriate authentication, permissions and SES prerequisites for that account.
Before
- name: add sending authorization policy to email identity
community.aws.ses_identity_policy:
identity: "{{ ses_identity }}"
policy_name: ExamplePolicy
policy: >
{
"Version": "2012-10-17",
"Statement": [
{
"Action": "*",
"Principal": {
"AWS": "*"
},
"Effect": "Allow",
"Resource": "arn:aws:ses:{{ aws_region }}:{{ aws_account_id }}:identity/{{ ses_identity }}",
"Sid": ""
}
]
}
state: present
All actions are broadly allowed to principals. Review whether this exceeds the identity's required access.
After
- name: add sending authorization policy to email identity
community.aws.ses_identity_policy:
identity: "{{ ses_identity }}"
policy_name: ExamplePolicy
policy: >
{
"Version": "2012-10-17",
"Statement": [
{
"Action": ["ses:SendEmail", "ses:SendRawEmail"],
"Principal": {
"AWS": "arn:aws:iam::{{ sender_account_id }}:root"
},
"Effect": "Allow",
"Resource": "arn:aws:ses:{{ aws_region }}:{{ aws_account_id }}:identity/{{ ses_identity }}",
"Sid": ""
}
]
}
state: present
Two sending actions are delegated to the approved account. Keep only the actions actually needed and check who in that account can use the delegated permissions. Add required sender and recipient conditions too.