Home › Blog

Amazon SES Warm Up for Cold Email

By BobWork04 Oct 202612 min read
Diagram of Amazon SES SMTP warm-up with verified identities, DNS records, receiving inbox and daily sending ramp

Warm up Amazon SES only after production access, verified identities and SMTP credentials are ready; then start at about 3 warm-up emails per day and ramp slowly. If you skip the receiving inbox or confuse IP warm-up with mailbox warm-up, you can build SES volume while still landing in spam. This guide gives the safe setup path, numbers and checks.

Amazon SES is an email infrastructure service, not a normal inbox. That matters for cold email. SES can send as a verified identity, but it does not give you an inbox where replies, spam placement and engagement live. For a day-by-day ramp, keep the sending schedule separate from your SES quota. You can compare the pattern with our email warm-up schedule before you connect anything.

This guide assumes you want to send low-volume cold outreach from a real address, such as alex@example.com, through SES SMTP. If you send transactional mail, use a separate identity, subdomain and reputation track. Do not mix password resets, invoices and cold outreach in one stream.

Plan your Amazon SES warm up

Your first job is to decide what you are warming. There are three layers, and they are not interchangeable.

The SES account and Region control whether AWS allows you to send. Sandbox status, account-level sending quotas and enforcement live here. You must follow AWS rules before any warm-up tool can send real messages.

The domain and identity control authentication and reputation. This includes SPF, DKIM, DMARC, custom MAIL FROM and the visible From address. A verified identity with broken DNS is not ready for cold email.

The mailbox controls replies, spam placement and engagement. This is the part many SES setups miss. If alex@example.com sends through SES, that same address should also be able to receive mail in a real mailbox. Warm-up needs that receiving side.

For cold email, treat warm-up as mailbox behaviour, not just SMTP throughput. Sending 1,000 messages through a newly approved SES account is not warm-up. It is volume. Warm-up means sending gradually, receiving replies, rescuing only warm-up messages from spam, and watching placement over time.

Use a separate subdomain if your main domain handles critical product mail. For example, keep app mail on example.com and outreach on hello.example.com or another controlled domain. This reduces blast radius if a campaign performs badly. It does not make bad lists safe.

Get SES ready first

Start in the AWS console. SES configuration is Region-specific, so choose the same AWS Region you will use for SMTP sending.

Go to Amazon SES → Configuration → Verified identities → Create identity. Choose Domain for domain-level sending. AWS will give you DNS records for verification and DKIM. Add them at your DNS host exactly as shown.

AWS documents identity setup in its verified identities documentation. Use that as the source of truth if the console wording changes.

Do not start cold outreach from a single verified email address if you can verify the domain. Domain verification gives you cleaner control over DKIM and future senders. You still need the mailbox itself to exist.

Next, check authentication.

SPF authorises the mail path. With SES, this may involve a custom MAIL FROM domain if you want SPF alignment. DKIM signs the message with your domain. DMARC tells receivers what to do when SPF or DKIM alignment fails.

At minimum, use DKIM and DMARC before cold email. A relaxed DMARC policy such as p=none is common while you test. Move slowly before stricter enforcement. If you need quick checks, use our SPF checker, DKIM checker and DMARC checker.

Then request production access. In the AWS console, go to Amazon SES → Account dashboard and request production access for the Region. AWS explains the sandbox model in its moving out of the sandbox documentation.

While in the sandbox, AWS says you can only send to verified identities and the mailbox simulator. Sandbox quotas are also restricted. That is not enough for normal mailbox warm-up because your peers must be real receiving inboxes.

When you request production access, be specific. Explain the mail type, expected volume, bounce handling, complaint handling, opt-out process and authentication. Do not describe cold email as transactional mail. AWS can review and enforce sending behaviour.

Create SES SMTP credentials

SES SMTP credentials are not the same as a normal mailbox password. They are generated credentials used to authenticate to the SES SMTP endpoint.

In the AWS console, go to Amazon SES → SMTP settings → Create SMTP credentials. AWS creates an IAM user and gives you an SMTP username and password. Store them securely. You may not be able to view the password again.

AWS documents this process in its SES SMTP credentials guide. Use the endpoint for your Region, such as email-smtp.us-east-1.amazonaws.com for US East (N. Virginia). Your exact hostname depends on the Region.

Use TLS. Port 587 with STARTTLS is a common default. Port 465 with TLS wrapper is also supported by SES. Check the AWS documentation and your sending tool’s settings before you save.

A typical SES SMTP setup looks like this:

SettingTypical valueWhat to check
SMTP hostemail-smtp.<region>.amazonaws.comSame Region as your verified identity
Port587 or 465STARTTLS for 587, TLS wrapper for 465
UsernameSES SMTP usernameNot your AWS login email
PasswordSES SMTP passwordNot your AWS console password
From addressVerified identity addressMailbox must also receive replies
Return-pathSES default or custom MAIL FROMPrefer alignment when configured correctly

Send a test message to an inbox you control. Check the full headers. Look for spf=pass, dkim=pass and dmarc=pass or the equivalent verdict shown by the receiving provider.

If the message sends but authentication fails, stop. Fix DNS first. Warm-up cannot compensate for broken SPF, DKIM or DMARC.

Separate IP and mailbox warm-up

SES has its own concept of dedicated IP warm-up. That is different from mailbox warm-up.

Dedicated IP warm-up is about gradually building reputation for a new sending IP. AWS describes this in its dedicated IP warm-up documentation. Depending on your SES configuration, AWS may gradually shift traffic to a new dedicated IP. Check the current AWS settings for your account.

Mailbox warm-up is about the identity that recipients see and interact with. It includes replies, thread depth, spam-folder recovery for warm-up mail, and steady sending from the same address.

You may need both. For example, a new SES dedicated IP with a new outreach mailbox has no meaningful sending history at either layer. IP warm-up helps the infrastructure. Mailbox warm-up helps the sender identity.

You may also need only mailbox warm-up. If you send through SES shared IPs, you still need a cautious ramp for a new mailbox or domain. Shared infrastructure does not give your address a clean history.

Do not use SES quota as your cold email target. A higher SES quota only means AWS permits more sending. It does not mean Gmail, Yahoo, Outlook, Zoho or corporate filters will like your campaign.

Also separate streams. Keep cold outreach away from transactional mail. Use different identities, tags, configuration sets or subdomains where practical. That makes bounces, complaints and reputation easier to interpret.

Connect the receiving inbox

This is the part that decides whether SES can be warmed like a mailbox.

A warm-up system must send and receive. SES handles the send side through SMTP. The receive side should be a real inbox reachable over IMAP, such as the mailbox behind alex@example.com.

If your From address cannot receive mail, fix that before warm-up. Replies to cold email should not disappear. Spam placement cannot be measured properly without a receiving mailbox. Threaded warm-up also needs somewhere to land.

For example, your setup might be:

RoleExampleWhy it matters
Sending serviceAmazon SES SMTPSends authenticated mail
Visible Fromalex@example.comBuilds sender identity reputation
Receiving inboxIMAP mailbox for alex@example.comReceives replies and warm-up mail
DNS identityexample.com or subdomainHolds SPF, DKIM and DMARC
Warm-up peersOther mailboxes you controlExchange realistic messages

The receiving inbox does not have to be hosted by AWS. It can be with a provider that supports IMAP access. What matters is that the mailbox matches the sender address and can be checked safely.

BobWork Email Warm-up supports Amazon SES by using SES SMTP credentials for sending and the receiving inbox over IMAP. The free pool does this step automatically once the mailbox is connected (it warms with the shared network by default, or only with your own mailboxes if you switch the account to a private pool), so each mailbox can send, receive, reply and report spam placement inside your own private pool.

The private-pool detail matters for sensitive addresses. In a private pool, only your own mailboxes write to each other. A public warm-up network exchanges mail with other users’ inboxes. If you want the trade-offs, read private warm-up pools versus public networks.

Use a safe ramp

Start lower than your SES quota. New cold email mailboxes should build slowly, even if AWS production access gives you more room.

For an existing domain, warm for at least 14 days before meaningful outbound. For a new domain, use three to four weeks. During active campaigns, keep warm-up running at about 10–15 messages per day per mailbox. Keep real cold outreach around 30–50 emails per mailbox per day.

Use more mailboxes instead of forcing one identity to carry too much volume. A slow, boring ramp is safer than a sudden jump.

NumberApplies toUse it this way
200 messages per 24 hoursSES sandbox quotaAWS sandbox limit; request production access before normal warm-up
1 message per secondSES sandbox rateAWS sandbox rate; do not treat it as a target
3 emails/dayFirst warm-up daySafe starting point for a mailbox
+2 emails/dayDaily rampIncrease gradually, not in jumps
30 emails/dayNormal warm-up capEnough for mailbox history in most cold setups
30% weekend volumeSaturday and SundayAvoid a seven-day robotic pattern
14+ daysExisting domainMinimum before calling a mailbox ready
3–4 weeksNew domainBetter for new domains or new sending identities
10–15/dayWarm-up during campaignsKeep background activity steady
30–50/dayReal outreach per mailboxTypical cold email range; add mailboxes for more volume
5% spam ratePause thresholdPause a few days if warm-up spam rate rises above this

In BobWork, the engine starts at 3 emails per day, adds 2 per day, and caps at 30 per day by default. The cap is editable per mailbox up to 100, but higher is not automatically better. Sends are spread between 09:00 and 18:00 in the mailbox’s own time zone, with randomness every 15 minutes.

A pair never writes to each other twice within three hours. Peers on a different domain or provider are picked twice as often. About 40% of received warm-up mail gets a reply, and threads end after three messages. That is enough to create normal-looking conversations without building endless artificial threads.

Do not add links, images or heavy formatting to warm-up content. Plain office-style text is enough. Save links and attachments for real campaigns after the mailbox has history.

Monitor the right signals

SES gives useful sending signals, but it does not tell the whole inbox-placement story.

Watch SES bounces, complaints, rejections and sending pauses. Set up notifications or event publishing if you are running more than a few mailboxes. If AWS pauses sending or warns about reputation, stop cold outreach and fix the cause.

Then watch mailbox-level placement. The question is simple: when this identity sends, do receiving inboxes place the message in Inbox or Spam?

A warm-up tool should measure spam landings directly inside receiving mailboxes. Seed-list tests can be useful for snapshots, but direct warm-up placement is better for the mailboxes in the pool. BobWork measures spam rate as the share of a sender’s warm-up mail found in Spam by receiving mailboxes over seven days.

Use these operating rules:

Readiness should have a threshold. In BobWork, a mailbox is ready for outbound after 14 or more days warming, a seven-day spam rate of 3% or lower, and at least 30 warm-up emails received. That does not guarantee inbox placement. It means the mailbox has enough warm-up evidence to start carefully.

For broader diagnosis, use why emails go to spam as a checklist. For provider-specific SES setup, keep the practical guide at Amazon SES warm-up open while you configure credentials.

Do this now

Use this table before you send the first cold campaign through SES.

StepActionHow to verify
1Choose one AWS Region for sendingSES console shows the verified identity in that Region
2Verify the sending domain in SESIdentity status is verified in Verified identities
3Add DKIM records from AWSReceiving headers show dkim=pass
4Publish SPF and DMARCDNS lookup returns the expected TXT records
5Request SES production accessAccount dashboard no longer shows sandbox restrictions
6Create SES SMTP credentialsTest send works through the SES SMTP endpoint
7Create or confirm the receiving inboxThe From address receives normal replies
8Enable IMAP or app-password accessYour warm-up tool can read the receiving inbox
9Start at 3 warm-up emails/dayFirst day sends are visible in sent mail or logs
10Keep real outreach paused at firstNo campaign tool sends from the mailbox yet
11Review spam placement after 7 daysWarm-up spam rate is trending down, not up
12Start cold outreach slowlyReal sends stay near 30–50 per mailbox per day

If you want to do this without paying for a warm-up seat, use BobWork Email Warm-up. It is free, needs no credit card, and supports up to 20 mailboxes per account. For SES, connect the SES SMTP credentials for sending and the matching receiving inbox over IMAP. One sender plus its receiving inbox is enough on the shared network; keep the ramp modest, and remember that Outlook and Microsoft 365 are not supported yet.

Frequently asked questions

Can I warm up Amazon SES while still in the sandbox?

Only in a limited way. In the SES sandbox, AWS restricts sending to verified recipients and the mailbox simulator, with sandbox quotas. For real warm-up conversations with normal inboxes, request production access first.

Do I need a mailbox if Amazon SES sends the email?

Yes, for mailbox warm-up. SES sends through SMTP, but a warm-up system also needs a receiving inbox over IMAP to detect spam placement, move warm-up mail, and receive replies.

Is SES dedicated IP warm-up the same as email warm-up?

No. Dedicated IP warm-up builds sending history for the IP address. Email warm-up builds mailbox, domain, engagement and placement history. Cold email needs both if you use a new dedicated IP.

How many cold emails should I send from Amazon SES?

For mailbox-based outreach, keep real outreach to about 30–50 emails per mailbox per day. Add more mailboxes instead of pushing one identity too hard. Check your current SES quota separately.

Which SES SMTP port should I use?

AWS documents SES SMTP over ports such as 587 with STARTTLS and 465 with TLS wrapper. Use the SMTP endpoint for the same AWS Region where your SES identity is verified.

Does BobWork support Amazon SES warm-up?

Yes. BobWork Email Warm-up supports Amazon SES using the platform’s SMTP credentials for sending plus a receiving inbox over IMAP. Outlook and Microsoft 365 are not supported yet.

Warm up your mailboxes free

Connect Gmail, Google Workspace, Zoho or Lark. Your mailboxes warm on a shared network, or in a private pool of your own, starting today.

Start free