Chapter: Connect Amazon SES

Integrations

Connect Amazon SES

This workspace’s emails go out via your SES account and your sender address.

Where to connect

In VentionDesk under Workspace › Sources › “Add source”, category Mail, then Amazon SES. Only the owner may connect, edit and remove.

Step by step

  1. Open the AWS console in the region you want to send from (e.g. eu-central-1) › Amazon SES › Configuration › Identities › “Create identity” › Domain. Choose “Easy DKIM” (RSA 2048) and set the three CNAME records until the identity shows “Verified”.
  2. For SPF alignment, create a “Custom MAIL FROM domain” such as bounce.your-domain.com with the MX and TXT records from the console. DKIM alone is enough for DMARC; without your own MAIL FROM domain, amazonses.com appears in the Return-Path.
  3. New accounts are in the sandbox and only send to verified addresses: request it under Account dashboard “Request production access”.
  4. In IAM › Users, create a separate user just for VentionDesk and give it an inline policy with exactly ses:SendEmail, ses:SendRawEmail and ses:GetEmailIdentity — Resource: the ARN of your identity (arn:aws:ses:<region>:<account-id>:identity/your-domain.com). Create the key under Security credentials › “Create access key” (use case “Application running outside AWS”).
  5. Enter the access key ID, secret, region and sender address. When saving, VentionDesk uses GetEmailIdentity to ask whether the domain (or the address itself) is verified for sending.
  6. Your customers’ replies still go to your VentionDesk mailbox (Reply-To) and land in the ticket. Bounces and complaints are only visible in your account with the provider — VentionDesk learns nothing about them. If sending fails, the reason is shown on this connection and the email counts as not sent; VentionDesk never silently falls back to another sender.
Guide at the provider(opens in a new tab)

What the dialog asks for

FieldEntryWhere from
Access key IDRequired | secretIAM › Users › a separate user just for sending › Security credentials › “Create access key”.
Secret access keyRequired | secretOnly shown once, when the key is created.
RegionRequiredThe region in which your identity is verified, e.g. eu-central-1 for Frankfurt.
Sender addressRequiredThe address your emails come from, e.g. invoice@your-domain.com — on the domain you verified with the provider. VentionDesk takes the name in front of it from “Settings › Email sender”.

VentionDesk stores secret entries encrypted and never shows them again. They are only saved once the provider confirms the access; if you edit a connection and leave a secret field empty, the previous value is kept.

All providers at a glance: IntegrationsWebhook URLs: Webhooks

Connect Amazon SES | VentionDesk Docs