Amazon SES email identities stuck in FAILED or NOT_STARTED verification
What does ZopNight detect here?
ZopNight flags an Amazon SES email identity whose `VerificationStatus` from `ses:ListEmailIdentities` is `FAILED` or `NOT_STARTED`, meaning it cannot be used to send mail. `PENDING` and `TEMPORARY_FAILURE` are left alone because they are normal mid-verification states. The finding carries no saving; it asks you to finish verification or delete the identity.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1526 |
| Category | advisory |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | VerificationStatus FAILED or NOT_STARTED |
| Source | ZopNight |
| Permissions used | ses:ListEmailIdentities · ses:GetEmailIdentity |
Where it applies
Identities that can never send
Every SES sender, whether an email address or a whole domain, is an identity that must be verified
in each Region before you can use it. The ListEmailIdentities response reports a
VerificationStatus for each, and the CLI reference
defines five values: PENDING, SUCCESS, FAILED, TEMPORARY_FAILURE and NOT_STARTED. An identity
stuck in FAILED or NOT_STARTED is dead configuration. It counts toward the per-Region identity
limit (the identities guide puts it
at 10,000) and usually means a domain move or a half-finished onboarding nobody completed.
Listing unusable identities
Run this in every Region where you use SES:
aws sesv2 list-email-identities \ --query 'EmailIdentities[?VerificationStatus==`FAILED` || VerificationStatus==`NOT_STARTED`].[IdentityName,IdentityType,VerificationStatus]' \ --output tableFor a failed domain, get-email-identity shows why, including an ErrorType such as
HOST_NOT_FOUND when the DNS records were never published:
aws sesv2 get-email-identity --email-identity example.com \ --query '{status:VerificationStatus,info:VerificationInfo}'Only terminal states count
ZopNight fires on FAILED and NOT_STARTED. It reads the status per identity in each Region, and
if the status was not collected for an identity, it does not fire.
States that are deliberately ignored
PENDING is the routine window right after creation while SES looks for your DNS records; AWS
notes that DNS changes can take up to 72 hours to propagate. TEMPORARY_FAILURE means a temporary issue is stopping SES from determining the verification status. Because the fix for this finding can delete the
identity, flagging either state would risk destroying a sender that is mid-onboarding.
The rule also does not yet look at the SendingEnabled flag, so a verified identity whose sending
AWS has paused is treated as healthy.
Risk rather than dollars
SES does not bill for an idle identity, and the finding carries no saving. The risk is operational: a team that assumes a domain is set up for sending will find messages rejected.
Completing or removing the identity
- Decide whether anyone still intends to send from this address or domain.
- To complete it, publish the DKIM records SES generated (for a domain) or resend the verification email (for an address; the link expires after 24 hours).
- To remove it:
aws sesv2 delete-email-identity --email-identity example.com.