Sending From Your Own Domain
Connect your own Amazon SES account, verify a domain, and route marketing and transactional email to different senders.
By default Growth sends every organization's email through the platform's own provider account. That works from day one, but it also means you share sending reputation with every other organization and cannot see your delivery data anywhere but in Growth.
Connecting your own provider account changes three things: you own your sending reputation, your delivery statistics live alongside the rest of your provider data, and you pay your provider's price rather than a share of ours.
Nothing is forced. An organization with no provider configured keeps sending exactly as before.
The Three Streams
Every email Growth sends belongs to one of three streams. The stream decides which sender carries it and — more importantly — what an unsubscribe blocks.
| Stream | What goes through it | Unsubscribe behavior |
|---|---|---|
marketing | Campaigns and nurture sequences | Blocked by an unsubscribe |
transactional | Emails your own application triggers through the API | Never blocked by a marketing unsubscribe |
system | Growth's own mail: sign-in links, platform alerts | Always sent by the platform, never through your account |
Only a hard bounce or a spam complaint blocks every stream. That is the one case where the address is genuinely dead or hostile.
Note. A customer who unsubscribes from your newsletter keeps receiving the receipts, password resets and delivery notices they are paying for. Before streams existed, one unsubscribe silently cut off both.
1. Connect Your Amazon SES Account
In AWS, create an IAM user with ses:SendEmail, ses:GetAccount,
ses:CreateEmailIdentity, ses:GetEmailIdentity,
ses:PutEmailIdentityMailFromAttributes and ses:DeleteEmailIdentity.
Then open Email marketing → Settings → Sending in Growth, click New application, choose AWS SES, and enter the region, access key ID and secret access key. Add your configuration set name — without one, Amazon reports no delivery, bounce or complaint events at all.
Press Test on the saved application. Growth calls GetAccount and reports
the quota, the per-second send rate, whether sending is enabled and whether the
account is still in the sandbox.
Watch out. Leaving the SES sandbox is requested once per AWS account and per region. Verifying a domain is a separate, automatic step with no human review. These two are commonly confused: a verified domain in a sandboxed account can still only send to addresses you have verified.
2. Verify Your Domain
Open Email marketing → Settings → Domains, enter your domain, pick the SES
application you just created, and optionally a MAIL FROM subdomain such as
mail.yourdomain.com.
Growth calls CreateEmailIdentity with Easy DKIM (RSA 2048) and shows the
records to publish:
- three CNAME records of the form
<token>._domainkey.<domain>→<token>.dkim.amazonses.com; - if you asked for a MAIL FROM domain, an MX record pointing to
feedback-smtp.<region>.amazonses.comwith priority 10, and a TXT record containingv=spf1 include:amazonses.com ~all.
Each record shows its own state — pending, success or failed — so a single
missing CNAME is visible rather than hidden behind a global "not verified".
Watch out. On Cloudflare, the DKIM CNAME records must stay DNS only (grey cloud). A proxied record answers with Cloudflare's own value instead of Amazon's, and verification never completes. This is the single most common cause of a domain that stays pending forever.
Amazon verifies continuously once the records resolve. Growth re-checks pending domains every hour, and Check verification forces a refresh.
3. Add A Sender And Route Your Streams
A sending identity is one address bound to one provider account. Several identities can share the same account, so two domains need one set of credentials, not two.
Open Email marketing → Settings → Senders, add
Acme <[email protected]>, and pick the SES application.
The first identity you create becomes your default route. If that is all you need, you are done — everything sends from that address.
To split streams, set Marketing and Transactional to different identities. Resolution order is: the stream's identity, then the default identity, then the platform sender.
4. Receive Delivery Events
Growth needs SNS to learn about deliveries, bounces and complaints.
- On your configuration set, add an SNS event destination capturing
Send,Delivery,Bounce,Complaint,Reject,Rendering failure— plusOpenandClickif Amazon SES handles your tracking (see below). - Open the SES application in Growth, save a webhook secret, and copy the
endpoint shown there:
https://<your-convex-site>/email/webhooks/ses/<connectionId>?secret=<secret>. - Subscribe your SNS topic to that HTTPS endpoint. Growth confirms the subscription automatically.
The secret travels in the query string because SNS cannot send custom headers.
Every event is additionally checked against its SNS signature, and the
signing certificate is only ever fetched from sns.<region>.amazonaws.com.
Events land in the same pipeline as every other provider, so your statistics, bot-open classification and top-links reports work identically whether a message went through SES or Resend.
Open And Click Tracking
An SES identity uses Amazon's own tracking by default. It costs less (Growth serves no pixel and no redirect) and follows the message AWS actually sent. The two mechanisms never run together — that would count every open twice.
Two optional settings on the SES application:
- Untracked configuration set — a second configuration set with tracking disabled, used for contacts who withdrew consent to open tracking. Without it, Growth still discards their open and click events, but AWS will have placed its pixel.
- Custom tracking domain — set it as
CustomRedirectDomainon the configuration set withHttpsPolicy: REQUIRE.
Watch out. A plain CNAME from your tracking domain to r.<region>.awstrack.me serves no valid certificate for your domain, and links silently fall back to http://. Put a TLS proxy in front — a proxied Cloudflare record works.
If an SES application has no configuration set, Growth keeps its own tracking rather than losing every statistic.
Watch Your Reputation
The Sending settings page shows the bounce and complaint rate of the last 30 days per provider account.
Amazon places an account under review past 5% bounces or 0.1% complaints, and suspends sending if it does not improve. Those limits apply to your whole AWS account, not to one domain or one configuration set — which is also why Growth never shares an SES identity between organizations.
Send Limits
SendBulkEmail only works with templates registered in AWS, and Growth
campaigns carry a distinct body per recipient, so campaigns go out through a
loop bounded by your account's MaxSendRate with a safety margin. Raise the
rate in AWS and press Test to pick up the new value.
Throttling and 5xx responses are retried once. A rejected address or an unverified identity is not — retrying those burns quota and reputation without ever succeeding.