Guide/Sending From Your Own Domain

Sending From Your Own Domain

Connect your own Amazon SES account, verify a domain, and route marketing and transactional email to different senders.

By default Growth sends every organization's email through the platform's own provider account. That works from day one, but it also means you share sending reputation with every other organization and cannot see your delivery data anywhere but in Growth.

Connecting your own provider account changes three things: you own your sending reputation, your delivery statistics live alongside the rest of your provider data, and you pay your provider's price rather than a share of ours.

Nothing is forced. An organization with no provider configured keeps sending exactly as before.

The Three Streams

Every email Growth sends belongs to one of three streams. The stream decides which sender carries it and — more importantly — what an unsubscribe blocks.

StreamWhat goes through itUnsubscribe behavior
marketingCampaigns and nurture sequencesBlocked by an unsubscribe
transactionalEmails your own application triggers through the APINever blocked by a marketing unsubscribe
systemGrowth's own mail: sign-in links, platform alertsAlways sent by the platform, never through your account

Only a hard bounce or a spam complaint blocks every stream. That is the one case where the address is genuinely dead or hostile.

Note. A customer who unsubscribes from your newsletter keeps receiving the receipts, password resets and delivery notices they are paying for. Before streams existed, one unsubscribe silently cut off both.

1. Connect Your Amazon SES Account

In AWS, create an IAM user with ses:SendEmail, ses:GetAccount, ses:CreateEmailIdentity, ses:GetEmailIdentity, ses:PutEmailIdentityMailFromAttributes and ses:DeleteEmailIdentity.

Then open Email marketing → Settings → Sending in Growth, click New application, choose AWS SES, and enter the region, access key ID and secret access key. Add your configuration set name — without one, Amazon reports no delivery, bounce or complaint events at all.

Press Test on the saved application. Growth calls GetAccount and reports the quota, the per-second send rate, whether sending is enabled and whether the account is still in the sandbox.

Watch out. Leaving the SES sandbox is requested once per AWS account and per region. Verifying a domain is a separate, automatic step with no human review. These two are commonly confused: a verified domain in a sandboxed account can still only send to addresses you have verified.

2. Verify Your Domain

Open Email marketing → Settings → Domains, enter your domain, pick the SES application you just created, and optionally a MAIL FROM subdomain such as mail.yourdomain.com.

Growth calls CreateEmailIdentity with Easy DKIM (RSA 2048) and shows the records to publish:

  • three CNAME records of the form <token>._domainkey.<domain> → <token>.dkim.amazonses.com;
  • if you asked for a MAIL FROM domain, an MX record pointing to feedback-smtp.<region>.amazonses.com with priority 10, and a TXT record containing v=spf1 include:amazonses.com ~all.

Each record shows its own state — pending, success or failed — so a single missing CNAME is visible rather than hidden behind a global "not verified".

Watch out. On Cloudflare, the DKIM CNAME records must stay DNS only (grey cloud). A proxied record answers with Cloudflare's own value instead of Amazon's, and verification never completes. This is the single most common cause of a domain that stays pending forever.

Amazon verifies continuously once the records resolve. Growth re-checks pending domains every hour, and Check verification forces a refresh.

3. Add A Sender And Route Your Streams

A sending identity is one address bound to one provider account. Several identities can share the same account, so two domains need one set of credentials, not two.

Open Email marketing → Settings → Senders, add Acme <[email protected]>, and pick the SES application.

The first identity you create becomes your default route. If that is all you need, you are done — everything sends from that address.

To split streams, set Marketing and Transactional to different identities. Resolution order is: the stream's identity, then the default identity, then the platform sender.

4. Receive Delivery Events

Growth needs SNS to learn about deliveries, bounces and complaints.

  1. On your configuration set, add an SNS event destination capturing Send, Delivery, Bounce, Complaint, Reject, Rendering failure — plus Open and Click if Amazon SES handles your tracking (see below).
  2. Open the SES application in Growth, save a webhook secret, and copy the endpoint shown there: https://<your-convex-site>/email/webhooks/ses/<connectionId>?secret=<secret>.
  3. Subscribe your SNS topic to that HTTPS endpoint. Growth confirms the subscription automatically.

The secret travels in the query string because SNS cannot send custom headers. Every event is additionally checked against its SNS signature, and the signing certificate is only ever fetched from sns.<region>.amazonaws.com.

Events land in the same pipeline as every other provider, so your statistics, bot-open classification and top-links reports work identically whether a message went through SES or Resend.

Open And Click Tracking

An SES identity uses Amazon's own tracking by default. It costs less (Growth serves no pixel and no redirect) and follows the message AWS actually sent. The two mechanisms never run together — that would count every open twice.

Two optional settings on the SES application:

  • Untracked configuration set — a second configuration set with tracking disabled, used for contacts who withdrew consent to open tracking. Without it, Growth still discards their open and click events, but AWS will have placed its pixel.
  • Custom tracking domain — set it as CustomRedirectDomain on the configuration set with HttpsPolicy: REQUIRE.

Watch out. A plain CNAME from your tracking domain to r.<region>.awstrack.me serves no valid certificate for your domain, and links silently fall back to http://. Put a TLS proxy in front — a proxied Cloudflare record works.

If an SES application has no configuration set, Growth keeps its own tracking rather than losing every statistic.

Watch Your Reputation

The Sending settings page shows the bounce and complaint rate of the last 30 days per provider account.

Amazon places an account under review past 5% bounces or 0.1% complaints, and suspends sending if it does not improve. Those limits apply to your whole AWS account, not to one domain or one configuration set — which is also why Growth never shares an SES identity between organizations.

Send Limits

SendBulkEmail only works with templates registered in AWS, and Growth campaigns carry a distinct body per recipient, so campaigns go out through a loop bounded by your account's MaxSendRate with a safety margin. Raise the rate in AWS and press Test to pick up the new value.

Throttling and 5xx responses are retried once. A rejected address or an unverified identity is not — retrying those burns quota and reputation without ever succeeding.