What you will learn
- Amazon SES — transactional email at scale and how it differs from SNS email
- SES key concepts — verified identities, sending limits, and bounce handling
- Amazon Pinpoint — multi-channel customer engagement platform
- Pinpoint vs SES vs SNS — which to use for which communication pattern
- Setting up SES for a production application
- Pinpoint campaigns, journeys, and analytics
- Moving out of the SES sandbox for production sending
- Best practices to protect email sender reputation
Why this matters
At Swiggy, every order confirmation, delivery notification, and invoice is an email triggered by a backend service. That is millions of emails per day — each one transactional, triggered by a specific user action, personalised, and time-sensitive. SES handles this at $0.10 per thousand emails — fractions of a penny per email. At Hotstar, marketing wants to send personalised re-engagement campaigns to users who have not watched in 30 days — segmented by what they watched last, their subscription tier, and their preferred language. Pinpoint handles the segmentation, campaign scheduling, A/B testing, and analytics. Two different problems — transactional vs marketing — two different services.
Amazon SES — Simple Email Service
SES is AWS's email sending service. It handles the infrastructure behind sending email at scale — delivery, reputation management, bounce processing, and spam compliance — so your application just calls an API and the email goes out.
Two use patterns:
Transactional email (application-triggered): Order confirmation after purchase Password reset link Account verification email Invoice and receipt delivery Alert when something happens Bulk email (marketing): Weekly newsletter Promotional campaign to customer list Product announcementsSES handles both, but for large-scale marketing campaigns Pinpoint is the better tool.
SES vs SNS for email:
This is a common confusion. SNS has an email subscription type but it is basic — plain text, not formatted, no analytics, no bounce handling.
| SES | SNS Email | |
|---|---|---|
| Purpose | Sending email from your application | Alerting subscribers to notifications |
| Format | HTML, styled emails | Plain text only |
| Analytics | Opens, clicks, bounces, complaints | None |
| Bounce handling | Automatic — maintains sender reputation | Manual |
| Cost | $0.10 per 1,000 emails | Part of SNS pricing |
| Use for | Transactional and marketing emails | Internal alerts, ops notifications |
SES Key Concepts
Verified Identities:
Before sending, you must verify that you own the domain or email address you are sending from.
Verify a domain (recommended for production): SES → Verified identities → Create identity → Domain Add example.in → SES gives you DNS records to add Add the records in Route 53 or your DNS provider Once DNS propagates → domain is verified → can send from any @example.in address Verify an email address (for testing): SES → Verified identities → Create identity → Email address Enter your email → click the verification link received → verifiedThe SES Sandbox — new account restriction:
New AWS accounts start in the SES sandbox:
Sandbox limitations: Can only send to verified email addresses Maximum 200 emails per day Maximum 1 email per second Production (outside sandbox): Can send to any email address in the world Higher sending limits (based on your reputation) Request production access: SES → Account dashboard → Request production accessRememberIf your application sends emails in production but users are not receiving them, check whether your SES account is still in the sandbox. Sandbox emails only reach verified addresses — any unverified recipient gets silently dropped.
Sending Limits:
Sending quota: maximum emails per 24-hour periodSending rate: maximum emails per secondBoth start low and increase automatically as you build a good sending reputation. You can also request increases.
Reputation Management — Bounces and Complaints:
Email reputation determines whether your emails land in inbox or spam. Two metrics matter:
Bounce rate: percentage of emails that cannot be delivered Keep below 5% — above this, email providers mark your domain as spam Hard bounce: email address doesn't exist → remove from your list immediately Soft bounce: mailbox full → retry, but remove after many soft bounces Complaint rate: percentage of recipients who mark as spam Keep below 0.1% — higher and your reputation suffers badlySES automatically handles bounces by sending bounce notifications to your application via SNS or SQS. Your application must process these and remove bad addresses from its lists.
Configuration Sets:
A configuration set groups sending settings and enables tracking.
Attach a configuration set to your sending callsConfiguration set routes events to: SNS → bounces, complaints, deliveries, opens, clicks CloudWatch → metrics for monitoring Kinesis Firehose → archive all email events to S3Use configuration sets for every production email — you need the bounce and complaint data.
Sending Email with SES
Through the console (testing):
SES → Account dashboard → Send test emailFrom: your-verified@example.inTo: another-verified@example.in (while in sandbox)Subject and body → Send test emailThrough the AWS CLI:
aws ses send-email \ --from "orders@swiggy.com" \ --to "rahul@customer.com" \ --subject "Your order ORD-2024-001 is confirmed" \ --text "Thank you for your order. Estimated delivery: 30 minutes." \ --html "<h1>Order Confirmed</h1><p>Thank you for your order.</p>" \ --region ap-south-1Through SDK in your application (Python example):
import boto3 ses = boto3.client('ses', region_name='ap-south-1') response = ses.send_email( Source='orders@swiggy.in', Destination={'ToAddresses': ['rahul@customer.com']}, Message={ 'Subject': {'Data': 'Your order is confirmed'}, 'Body': { 'Html': { 'Data': '<h1>Order ORD-2024-001 confirmed</h1><p>Arriving in 30 minutes</p>' } } }, ConfigurationSetName='production-tracking')Amazon Pinpoint — Multi-Channel Customer Engagement
Pinpoint is the marketing and customer engagement platform. Where SES sends an email when your code tells it to, Pinpoint manages who to contact, when, through which channel, with what message — automatically.
Channels Pinpoint supports:
Email (uses SES under the hood)SMSPush notifications (iOS, Android)Voice callsIn-app messagingKey Pinpoint concepts:
Segments:
Groups of users defined by attributes. Pinpoint segments users from your data.
Segment: "Users who have not opened the app in 30 days AND have watched sports content"Segment: "Premium subscribers in Maharashtra who have used the app this week"Campaigns:
One-time or recurring messages sent to a segment.
Campaign: "Re-engagement email to 30-day inactive users"Schedule: send Tuesday at 10 AM ISTMessage: personalised subject line using first nameA/B test: 50% receive version A, 50% receive version BWinner deployed automatically based on open rateJourneys:
Multi-step automated workflows triggered by user actions.
User signs up → Day 0: welcome email Day 3: if no login → send "getting started" email Day 7: if still no login → send SMS reminder Day 14: if no activity → add to "at risk" segment for sales outreachAnalytics:
Pinpoint tracks everything automatically:
- Email: delivered, opened, clicked, bounced, unsubscribed
- SMS: delivered, failed
- Push: received, opened
- Campaign: conversion rate, revenue attributed
Pinpoint vs SES vs SNS:
| SES | SNS | Pinpoint | |
|---|---|---|---|
| Type | Email sending API | Pub-sub notification | Customer engagement platform |
| Channels | Email only | Email, SMS, push, HTTP | Email, SMS, push, voice, in-app |
| Segmentation | No | No | Yes — rich user segmentation |
| Campaigns | No | No | Yes — scheduled, triggered |
| Journeys | No | No | Yes — multi-step automation |
| Analytics | Basic (bounces, complaints) | None | Full campaign analytics |
| Best for | Transactional email from code | Internal alerts and notifications | Marketing campaigns and engagement |
RememberSES is the API your developers call to send a specific email to a specific person. Pinpoint is the platform your marketing team uses to define who gets what message when. They solve different problems. Use both — SES for transactional, Pinpoint for marketing.
Hands-on Lab — Verify SES Identity and Send Test Email
Step 1 — Verify an email identity
SES → Verified identities → Create identityIdentity type: Email addressEmail address: your-email@gmail.comCreate identity Check your inbox → click the verification linkStatus changes to: VerifiedStep 2 — Check sandbox status
SES → Account dashboardSee: Sending quota and sending rateSee: Production access status (Sandbox or Production)In Sandbox — can only send to verified addressesStep 3 — Send a test email
SES → Account dashboard → Send test emailFrom: your-verified-email@gmail.comScenario: CustomTo: your-verified-email@gmail.com (same address — sandbox restriction)Subject: Test from SESBody type: HTMLBody:<h2>Hello from Amazon SES!</h2><p>This email was sent using the AWS SES service.</p><p>Your application can send emails like this programmatically.</p>Send test email Check your inbox — email should arrive within seconds.Step 4 — Create a Configuration Set
SES → Configuration sets → Create configuration setName: production-tracking Add event destination:Destination type: CloudWatchEvent types: Sends, Deliveries, Bounces, ComplaintsCreate Now attach this configuration set name to all your email sends.Metrics appear in CloudWatch automatically.Step 5 — Request production access (do this when ready for real users)
SES → Account dashboard → Request production accessFill in: website URL, use case description, how you handle bouncesSubmit → AWS reviews within 24-48 hoursApproved → sending limits increase, can send to any email addressStep 6 — Explore Pinpoint
Amazon Pinpoint → Create a projectProject name: devops-engagementConfigure email channel → select your SES verified identityCreate project Pinpoint → Segments → Create segmentSee: segment by user attributes, behaviour, and activityThis is where marketing defines who receives each campaign No cleanup needed beyond deleting the Pinpoint project if desired.Common Mistakes to Avoid
Common MistakeStaying in the SES sandbox and deploying to production. SES sandbox emails only reach verified addresses. If your production users are not verified in SES, they never receive your emails. No error is thrown — emails are accepted by SES and silently not delivered. Request production access before going live.
Common MistakeNot processing SES bounce notifications. If your application keeps sending to bounced email addresses, your bounce rate climbs above 5% and email providers start treating your domain as a spammer. Set up an SNS topic for bounce notifications, subscribe a Lambda to it, and have Lambda remove bounced addresses from your sending list immediately.
Common MistakeUsing SNS email for transactional emails your users will read. SNS email is plain text, has no formatting, no tracking, and requires subscribers to opt in via a confirmation email. It is designed for internal alerting — not for customer-facing emails. Use SES for any email a customer will receive.
TipSet up DKIM, SPF, and DMARC for your domain in SES. These DNS records tell email providers that you are authorised to send from your domain. Without them, your emails are more likely to land in spam. SES provides these records when you verify a domain — add them to your DNS immediately. Good email deliverability starts with proper domain authentication.