Executive Summary: How to exit the AWS SES sandbox and configure your DNS for production email sending.
AWS SES puts all new accounts in a 'Sandbox' mode where you can only send emails to verified addresses.
### The Verification Process
1. Add your Domain in the SES Console.
2. AWS will provide CNAME records for DKIM. Add these to your DNS provider (Cloudflare, Route53, GoDaddy).
3. Add the custom MAIL FROM domain (e.g., bounce.yourdomain.com) to separate marketing bounces from your main domain.
### Requesting Production Access
You must open a support ticket with AWS to exit the sandbox. Be extremely detailed about:
- How you acquire subscribers (Double Opt-In is preferred).
- How you handle bounces and complaints.
- What type of content you are sending.
A well-written request gets approved in 24 hours.