Description
A policy attached to an SES email address or domain controls who can use that identity and which SES actions are allowed. Unnecessary sending delegation can let others send mail from the address or domain. This policy is not a grant to administer IAM users or roles.
Actual sending also depends on identity verification, regional sending configuration and policy conditions. Allow only the senders and operations that are needed.
Potential impact
- If unapproved sending is allowed, the domain can be misused for spam or phishing.
- Email abuse can damage domain reputation and recipients’ trust.
Remediation
- Remove unnecessary all-principal grants and specify the actual sending accounts or roles.
- Limit actions to those needed, such as ses:SendEmail or ses:SendRawEmail, and set Resource to the attached SES identity ARN.
- Verify that intended sending succeeds and unapproved sending is denied, and remove unused delegation policies.
Examples
These excerpts show a verified SES domain’s policy. Define and verify the referenced domain separately and replace the role ARN with the actual sending role. SMTP sending requires SendRawEmail permission.
Before
resource "aws_ses_identity_policy" "ses_policy" {
identity = aws_ses_domain_identity.example.arn
name = "example"
policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Action": "*",
"Principal": {
"AWS": "*"
},
"Effect": "Allow",
"Resource": "${aws_ses_domain_identity.example.arn}"
}
]
}
EOF
}
This requests broad actions for all AWS principals. Check the actions supported by SES and the delegation actually needed.
After
resource "aws_ses_identity_policy" "ses_policy" {
identity = aws_ses_domain_identity.example.arn
name = "example"
policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Action": "ses:SendEmail",
"Principal": {
"AWS": "arn:aws:iam::987654321145:role/email-service"
},
"Effect": "Allow",
"Resource": "${aws_ses_domain_identity.example.arn}"
}
]
}
EOF
}
This limits SendEmail on the same identity to the specified role. Match the permissions to the actual API or SMTP method and sending conditions.