Amazon SES with Gmail after “Send mail as” ends
About 30 minutes, plus up to a day for AWS review · Checked October 11, 2026
The usual recipe for SES and Gmail is: create SES SMTP credentials, then add them to Gmail under Settings → See all settings → Accounts and Import → Send mail as. That last step stops working in January 2027. Your SES setup doesn't need to change; only the place where you press Send does. This guide covers both halves, using AWS's and Google's own documentation.
What changes, and what doesn't
Google's help page: “Starting January 2027, Gmail will no longer support the “Send as” feature for third-party email addresses, such as @yahoo.com or @outlook.com.” Its change notice adds that before then “Gmail may restrict new configurations”, so a fresh “Send mail as” + SES setup may not be accepted even today.
Everything on the AWS side carries over: your verified domain, its DKIM records, your production access and your sending reputation. Forwarding mail into Gmail also keeps working; Google's FAQ answers “Can I still receive email forwarded from a third-party account?” with “Yes.”
Step 1: Verify your domain in SES
Skip this if your domain already shows Verified under Identities in the region you use.
- Open the SES console and pick a region. Identities, sandbox status and SMTP credentials are all per region, so use the same one throughout.
- Go to Configuration → Identities → Create identity, choose Domain and enter
yourdomain.com(withoutwww.). Leave Easy DKIM at the default 2048-bit key. - Publish the three CNAME records SES shows in your DNS. Names look like
abc123._domainkey.yourdomain.com; don't add an extra leading underscore. - Wait for Identity status: Verified. AWS says DNS changes “can take up to 72 hours to propagate”.
A verified domain lets you send from any address on it: per AWS, if you verify example.com “you don't need to create separate identities for … user@example.com”. Because Easy DKIM signs with your domain, DMARC can pass on DKIM alone. A custom MAIL FROM subdomain is optional; it must be a subdomain such as mail.yourdomain.com, so it doesn't touch the MX records your forwarder uses on the root domain.
Step 2: Leave the sandbox
New SES accounts start in the sandbox. AWS lists its limits in Request production access: you can only send to verified addresses and domains, “a maximum of 200 messages per 24-hour period” and “a maximum of 1 message per second”. To write to anyone, request production access from Account dashboard → View Get set up page → Request production access. For personal and one-to-one business mail, Transactional is the closer fit. AWS says it gives “an initial response to your request within 24 hours”, and may ask for more detail.
Step 3: Keep receiving in Gmail
SES sending doesn't put mail into Gmail. Keep the forwarder you already have, or set one up: Cloudflare Email Routing is free (our Cloudflare guide walks through it), and ImprovMX's free plan forwards one domain. SES's own DKIM records live under _domainkey, so they don't conflict with the forwarder's MX and SPF records.
Step 4: Choose where you press Send
Option A: A desktop mail client with SES SMTP
Google recommends a desktop client with “IMAP/SMTP support” for anyone who relies on “Send as” for business. Read Gmail in Thunderbird, Apple Mail or Outlook over IMAP, and add you@yourdomain.com as a second identity that sends through SES:
| Setting | Value |
|---|---|
| Server | email-smtp.us-east-1.amazonaws.com (use your region; full list in SES endpoints) |
| Port and security | 587 with STARTTLS, or 465 with SSL/TLS |
| Username and password | Your SES SMTP credentials from SMTP settings → Create SMTP credentials |
If you set up “Send mail as” with SES before, you can reuse the same SMTP credentials here. Per AWS, they're “unique to each AWS Region”, and the SMTP password “is different from your AWS secret access key”. Ports are from Connecting to an SES SMTP endpoint.
Better when: you want a free setup with nothing added to your browser. Trade-off: you work outside Gmail's web interface.
Option B: Gmail on the web with an SES access key
To keep writing in Gmail itself, a browser extension can send your draft through the SES API instead of SMTP. Google cautions about such tools on its change notice (“they often require access to your email credentials or OAuth tokens”), so check what any extension asks for.
CustomFrom is ours. It doesn't use your Google password or a Google OAuth token. It needs an AWS access key that can only send email, which it keeps in your browser and uses to call SES directly. It reads the draft you choose to send from the Gmail page. Setup:
- In the IAM console, create a user (for example
customfrom-sender) and attach this policy, which is AWS's own “email-sending actions only” example:{ "Version": "2012-10-17", "Statement": [{ "Effect": "Allow", "Action": ["ses:SendEmail", "ses:SendRawEmail"], "Resource": "*" }] }To limit it further, replace*with your domain identity's ARN. - Under that user's Security credentials, create an access key and copy the access key ID and secret access key. SES SMTP credentials won't work here, because the SMTP password isn't the secret key.
- Install CustomFrom, open its settings and add an address with the full form: provider Amazon SES, your address and name, the secret access key in the key field (labelled “Secret access key”), the access key ID, and your SES region (for example
us-east-1). - Click Send test email, then compose in Gmail: your address is in the new From bar. Attachments, pasted images and threaded replies go through SES, and a copy is BCC'd back to your Gmail.
Price: $15 once, after a 7-day trial that starts with your first message; the first 100 buyers pay $9 with code EARLY100. Trade-off: Gmail on desktop Chrome and Edge only, not the Gmail mobile apps.
What SES costs for personal mail
From the SES pricing page: “$0.10 / 1,000 emails” plus “$0.12 per GB of attachment data sent”. A thousand messages a month with a few attachments costs well under a dollar. New AWS customers also get “up to $200 in AWS Free Tier credits” usable on SES.
If the sandbox review is the part you'd rather skip, Resend's free plan (3,000 emails a month, 100 a day) needs no review and works with both options above; see the Cloudflare + Resend guide.
If something goes wrong
- “Email address is not verified” to an outside recipient: the account is still in the sandbox in that region, or the domain is verified in a different region from the one you're sending through.
- SMTP authentication fails: the credentials belong to another region, or you used the IAM secret access key instead of the SMTP password.
- CustomFrom says SES rejected the credentials: the access key ID and secret are swapped or cut off, or the region doesn't match.
- Access denied: the IAM user is missing the sending policy above.
- First messages land in spam: common for a new domain. Check that DKIM shows Successful and add a DMARC record such as
_dmarc TXT "v=DMARC1; p=none;".
Sources
- Google, Send emails from a different address or alias: support.google.com/mail/answer/22370
- Google, Learn about changes to third-party email account support in Gmail: support.google.com/mail/answer/17101213
- AWS, Creating and verifying identities: docs.aws.amazon.com/ses/latest/dg/creating-identities.html
- AWS, Request production access: docs.aws.amazon.com/ses/latest/dg/request-production-access.html
- AWS, Obtaining SES SMTP credentials: docs.aws.amazon.com/ses/latest/dg/smtp-credentials.html; Connecting to an SMTP endpoint: smtp-connect.html; endpoints: docs.aws.amazon.com/general/latest/gr/ses.html
- AWS, Identity and access management in SES: docs.aws.amazon.com/ses/latest/dg/control-user-access.html
- AWS, Using a custom MAIL FROM domain: docs.aws.amazon.com/ses/latest/dg/mail-from.html
- Amazon SES pricing: aws.amazon.com/ses/pricing
- Cloudflare Email Routing: developers.cloudflare.com/email-routing; ImprovMX pricing: improvmx.com/pricing; Resend pricing: resend.com/pricing
AWS consoles and prices change. If a step here no longer matches, email support@steadytabs.com and we'll fix it. Amazon Web Services and Amazon SES are trademarks of Amazon.com, Inc.; SteadyTabs isn't affiliated with Amazon.
More guides: Custom domain in Gmail without WorkspaceCloudflare + Resend setup“Send mail as” is ending