Skip to main content
advisory · aws

Amazon SES email identities stuck in FAILED or NOT_STARTED verification

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags an Amazon SES email identity whose `VerificationStatus` from `ses:ListEmailIdentities` is `FAILED` or `NOT_STARTED`, meaning it cannot be used to send mail. `PENDING` and `TEMPORARY_FAILURE` are left alone because they are normal mid-verification states. The finding carries no saving; it asks you to finish verification or delete the identity.

Signal and threshold

How ZopNight evaluates Amazon SES email identities stuck in FAILED or NOT_STARTED verification.
Field Value
Rule IDsRC-1526
Categoryadvisory
Severitylow
Metricnone — pure configuration read
ThresholdVerificationStatus FAILED or NOT_STARTED
SourceZopNight
Permissions usedses:ListEmailIdentities · ses:GetEmailIdentity

Identities that can never send

Every SES sender, whether an email address or a whole domain, is an identity that must be verified in each Region before you can use it. The ListEmailIdentities response reports a VerificationStatus for each, and the CLI reference defines five values: PENDING, SUCCESS, FAILED, TEMPORARY_FAILURE and NOT_STARTED. An identity stuck in FAILED or NOT_STARTED is dead configuration. It counts toward the per-Region identity limit (the identities guide puts it at 10,000) and usually means a domain move or a half-finished onboarding nobody completed.

Listing unusable identities

Run this in every Region where you use SES:

Terminal window
aws sesv2 list-email-identities \
--query 'EmailIdentities[?VerificationStatus==`FAILED` || VerificationStatus==`NOT_STARTED`].[IdentityName,IdentityType,VerificationStatus]' \
--output table

For a failed domain, get-email-identity shows why, including an ErrorType such as HOST_NOT_FOUND when the DNS records were never published:

Terminal window
aws sesv2 get-email-identity --email-identity example.com \
--query '{status:VerificationStatus,info:VerificationInfo}'

Only terminal states count

ZopNight fires on FAILED and NOT_STARTED. It reads the status per identity in each Region, and if the status was not collected for an identity, it does not fire.

States that are deliberately ignored

PENDING is the routine window right after creation while SES looks for your DNS records; AWS notes that DNS changes can take up to 72 hours to propagate. TEMPORARY_FAILURE means a temporary issue is stopping SES from determining the verification status. Because the fix for this finding can delete the identity, flagging either state would risk destroying a sender that is mid-onboarding.

The rule also does not yet look at the SendingEnabled flag, so a verified identity whose sending AWS has paused is treated as healthy.

Risk rather than dollars

SES does not bill for an idle identity, and the finding carries no saving. The risk is operational: a team that assumes a domain is set up for sending will find messages rejected.

Completing or removing the identity

  1. Decide whether anyone still intends to send from this address or domain.
  2. To complete it, publish the DKIM records SES generated (for a domain) or resend the verification email (for an address; the link expires after 24 hours).
  3. To remove it: aws sesv2 delete-email-identity --email-identity example.com.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·