Overview
When configuring Event Templates, one of the fields to be completed is the sender address. In order for Emersion to send email on behalf of your domain through Amazon SES, the domain must:
- be registered and verified in Amazon SES via the Cumulus user interface; and
- the appropriate DNS records added to your domain's DNS Zone configuration.
This article guides users through the steps complete this configuration.
For further information on Events please go here.
Once verified, do not delete the verification TXT or MX records for your domain / custom MAIL FROM sub domain. Amazon continually poll for the existence of these records and will revoke the verification if unable to confirm valid records.
If after 72 hours Amazon still cannot confirm the existence of the DNS records, YOU WILL NOT BE ABLE TO SEND EMAIL FROM THIS DOMAIN.
This article assumes the user has the required technical knowledge pertaining to Email Administration, DNS and DNS record configuration.
Emersion strongly recommends service providers to engage a party with proven competence and experience in the field of email and/or domain administration.
It is outside the scope of Emersion's support to provide education on these topics.
Access Control
Module permissions are used to control access this page.
Users are required to have the Events - All Access (no SMS Out) module permission to access this page.
Please see this article for guidance on module permissions.
Register The Domain
> Amazon Documentation (Domain Verification)
Registering a domain in Cumulus enables us to send email to your end users via the Amazon SES email system. You must register all domains that are used in your Event Email Templates as configured in the Sender field.
To do this:
Navigate to Events > Email Domains
A list of domains that have been configured and are currently registered for use will appear.
If you have multiple instances of Emersion (i.e Wholesale and Retail and these instances use different domains) it is recommended to configure the individual domain per instance.
Press the New Email Domain button to start the registration process.
- Enter the domain in the Domain field.
- Example: If the SENDER address in your event email templates is auto-notification@example.com the domain is example.com.
- Enter a subdomain into the MAIL FROM field. Do not enter the domain portion into the MAIL FROM field. Only enter a subdomain. Do not enter a sub-domain that you already use for mail.
If mail sent from Emersion bounces, or a complaint email is received, the MAIL FROM field will allow the mail to be redirected back to the Sender address configured in the event template.
The MAIL FROM field is a subdomain. Not an email address.
Emersion recommends the use of a simple (and unused) subdomain like "mail1". (For example: mail1.example.com)
The Mail From Field
> Amazon Documentation (Custom MAIL FROM)
The MAIL FROM field in the example below is mail1.emersion.com. This field has two purposes:
- Firstly, it is be used to redirect bounce backs and complaint messages sent to the email address as specified in your event email template as the Sender address.
- The second purpose is to ensure that emails will appear to come from a correct matching domain when delivered to the recipient's mailbox.
The MAIL FROM subdomain must not be on a domain that you currently use to receive or send email. This field is solely for the purpose of receiving complaints and bounces and setting a custom MAIL FROM email header.
An extended description an explanation as to why this is require directly from Amazon below;
When an email is sent, it has two addresses that indicate its source: a From address that's displayed to the message recipient, and a MAIL FROM address that indicates where the message originated. The MAIL FROM address is sometimes called the envelope sender, envelope from, bounce address, or Return Path address. Mail servers use the MAIL FROM address to return bounce messages and other error notifications. The MAIL FROM address is usually only viewable by recipients if they view the source code for the message.
Amazon SES sets the MAIL FROM domain for the messages that you send to a default value unless you specify your own domain. This section discusses the benefits of setting up a custom MAIL FROM domain, and includes setup procedures.
Why use a custom MAIL FROM domain?
By default, messages that you send through Amazon SES use a subdomain of amazonses.com as the MAIL FROM domain. Sender Policy Framework (SPF) authentication successfully validates these messages because the default MAIL FROM domain matches the application that sent the email - in this case, Amazon SES.
While this level of authentication is sufficient for many senders, other senders prefer to set the MAIL FROM domain to a domain that they own. By setting up a custom MAIL FROM domain, your emails can comply with Domain-based Message Authentication, Reporting and Conformance (DMARC). DMARC enables a sender's domain to indicate that emails sent from the domain are protected by one or more authentication systems.
There are two ways to achieve DMARC validation: using Sender Policy Framework (SPF), and using DomainKeys Identified Mail (DKIM). The only way to comply with DMARC through SPF is to use a custom MAIL FROM domain, because SPF validation requires the domain in the From address to match the MAIL FROM domain. By using your own MAIL FROM domain, you have the flexibility to use SPF, DKIM, or both to achieve DMARC validation.
The process of setting up a custom MAIL FROM domain requires you to add records to the DNS configuration for the domain. You have to publish an MX record so that your domain can receive the bounce and complaint notifications that email providers send you. You also have to publish an SPF record in order to prove that Amazon SES is authorized to send email from your domain.
In this example below, the entry "mail1" results in mail1.emersion.com.
When finished, press the Create button. The Email Domain screen window will be shown to the user.
Editing the Email Domain
This screen displays all the items that must be added to the domain's DNS records to ensure our the system can send mail on your behalf. These records are:
- the Domain Verification Record
- the MX Record
- the SPF record.
Service providers may need to contact their domain provider to do this on their behalf.
After the records are added, the system will attempt to verify them. Users can see the verification status on the right hand side. The example below is Pending.
After these records are added, it may take anywhere up to maximum of 72 hours to complete verification.
Once the domain and the MAIL FROM has been verified, the status will update to Success.
The event system is now able to successfully send emails via the desired from address in the event templates.
Be aware that the Domain, and the MAIL FROM are verified independently. One may be verified prior to the other. It make be up to 72 hours for the verification process to finish.
If after 72 hours either your domain or mail from verification is still Pending, please confirm the DNS records have been added correctly. If so, please contact Emersion Support by raising a ticket.
Helpful website to assist with DNS record identification
Whilst Amazon have built in mechanisms to verify DNS records have been added, service providers may use external tools to interrogate the DNS system to confirm this themselves.
Please note that the broader DNS system and its usage is beyond the scope of this article. If managing DNS records, interrogating nameservers
Example 1: MX record configured for the example mail1.emersion.com sub-domain (custom MAIL FROM address). This output is from the Linux command line application "dig".
Example 2: Using each of digwebinterface and googleapps online DNS lookup tools
Domain Verification Revoked
> Amazon Documentation (Domain Verification Revocation)
Once verified, do not delete the verification TXT records for your domain. Amazon continually poll for the existence of these records and will revoke the verification if unable to confirm valid records.
If you restore the domain verification TXT record within 72 hours, Amazon will restore the verification status.
If after 72 hours Amazon still cannot confirm the existence of the TXT record, the verification of the domain will be removed and you WILL NOT BE ABLE TO SEND EMAIL FROM THIS DOMAIN.
If this happens, you must begin the verification process from scratch. Delete the current domain in Cumulus and create New Email Domain
Have Multiple Domains?
Some companies choose to operate multiple "brands" from a single service provider account, and opt to utilise different brand domains when configuring different event templates.
For each domain that is required, simply add them by clicking new the New Email Domain button and filling out the details as per the above instructions.
Case Example
In the page below are three (3) different domains configured. This enables service providers to configure the SENDER email address on different events to each of the different domains.
For example;
| Event Type | Event Template For | Sender Email |
|---|---|---|
| Invoice Delivery | sampledomain.com accounts | somewhere@sampledomain.com |
| Invoice Delivery | otherdomain.net accounts | somewhere@otherdomain.net |
| Invoice Delivery | bestsamplebrand.com.au accounts | somewhere@bestsamplebrand.com.au |
Verification Failed
> Amazon Documentation (Domain Verification Troubleshooting)
Once you have filled out the information on this Email Domains form and submitted, Emersion will send the details onto Amazon so they can initiate their automated verification process.
If, after 3 days, Amazon have been unable to verify your domain, the Verification Status is set to Failed
For domains, the most common reason for a failed verification is a missing or incorrect value for the
_amazonses.example.comTXT record.If your DNS provider does not allow DNS record names to contain underscores, you can omit _amazonses from the Name field.
For example: The TXT record name would be example.com instead of _amazonses.example.com. To make the record easier to recognise and maintain, you can also optionally prefix the Value with
amazonses:.The value of the TXT record would therefore be
amazonses:pmBGN/7MjnfhTKUZ06Enqq1PeGUaOkw8lGhcfwefcHU=.
For the MAIL FROM sub domain the most common reason for a failed verification is a missing or mis-configured MX record.
The MX record is required to be configured against the chosen sub-domain only. Some DNS hosting providers may not allow you to add this and will automatically add additional MX records to your primary domain.
You will need to contact your hosting provider as advise them you are adding a new MX (and TXT) record to a fully qualified subdomain. They may have an alternate approach to adding custom records of this nature.
Also keep in mind that the "10" does not form part of the record's value - it is an MX preference/priority indicator.
Depending on your DNS hosting provider, it is either added with a space between the record type and the value (ie. MX 10 amazonses.blah) or it can selected from a drop-down list or added into a separate field.
The following table lists the possible statuses for the MX record verification - including what MAIL FROM domain will be used in the event it cannot verify your custom one;
| State | Email Sending Behaviour | Amazon SES Actions |
|---|---|---|
Pending | Uses custom MAIL FROM fall-back setting | Amazon SES attempts to detect the required MX record for 72 hours. If unsuccessful, the state changes to "Failed". |
Success | Uses custom MAIL FROM domain | Amazon SES continuously checks that the required MX record is in place. |
TemporaryFailure | Uses custom MAIL FROM fall-back setting | Amazon SES attempts to detect the required MX record for 72 hours. If unsuccessful, the state changes to "Failed"; if successful, the state changes to "Success". |
Failed | Uses custom MAIL FROM fall-back setting | Amazon SES no longer attempts to detect the required MX record. To use a custom MAIL FROM domain, you have to restart the setup process in Cumulus. |
Retrying Post-Failure
You have two options available when a domain verification has failed.
Retry
Simply ensure the correct records (and values) exists within your DNS zone configuration and click the Retry button.
Start Again
To start the verification process from scratch:
Click the Delete whilst viewing an email domain configuration.
Begin again by clicking the New Email Domain button.









