Silo

Guide

Setting up Amazon SES

Amazon SES is the lowest-cost way to send with Silo: AWS lists outbound email at about $0.10 per 1,000 messages, billed to your own AWS account. Setup takes about half an hour of your time, plus waiting for DNS and for AWS to approve production access.

1. Pick a region

Sign in to the AWS console and choose the region you'll send from, for example us-east-1 (N. Virginia). SES identities, sandbox status and sending limits are per region, so do every step below in the same one, and enter that region in Silo.

2. Verify your sending domain

  1. In the SES console, open Configuration > Identities and choose Create identity.
  2. Choose Domain and enter the domain you send from (the part after @ in your From address), for example yourcompany.com.
  3. Leave Easy DKIM on (RSA 2048-bit). SES gives you three CNAME records shaped like abc123._domainkey.yourcompany.com → abc123.dkim.amazonses.com.
  4. Add all three at your DNS host exactly as shown. SES usually verifies within an hour of them appearing; the identity status changes to Verified.

3. SPF with a custom MAIL FROM domain (recommended)

By default SES uses an amazonses.com bounce address, so SPF passes for Amazon's domain, not yours. To make SPF align with your domain for DMARC:

  1. On your verified identity, edit Custom MAIL FROM domain and enter a subdomain you don't use for anything else, such as mail.yourcompany.com.
  2. Add the two records SES shows: an MX record pointing to feedback-smtp.<region>.amazonses.com (priority 10), and a TXT record v=spf1 include:amazonses.com ~all, both on that subdomain.

4. DMARC

Gmail and Yahoo require a DMARC record from bulk senders. Add a TXT record at _dmarc.yourcompany.com. A safe starting point that only reports and doesn't reject anything:

v=DMARC1; p=none; rua=mailto:dmarc-reports@yourcompany.com

Once reports show your legitimate mail passing, you can tighten the policy to p=quarantine or p=reject. Silo's Deliverability page checks SPF, DKIM and DMARC for your domain and shows what is missing.

5. Create an IAM user for Silo

  1. In IAM, create a user (for example silo-sending) with no console access.
  2. Attach the policy shown in Silo under Sending > IAM permissions your access key needs. It covers sending, the credential check and the bounce setup, and nothing else.
  3. Create an access key for the user and copy the key ID and secret.

In Silo, open Sending, choose Amazon SES, paste the keys, enter your region and save. Silo encrypts the keys and makes a real call to SES before accepting them.

6. Turn on bounce and complaint handling

On the Sending page, click Set up bounce & complaint handling for me. Using your saved keys, Silo creates an SNS topic in your account, subscribes a private Silo endpoint for your account to it, and adds an event destination for bounces and complaints on your configuration set. Every hard bounce and complaint then suppresses that address for your account. It's safe to run again: it reuses what exists and adds only what is missing.

Prefer to do it by hand? The same page lists the steps and your endpoint URL.

7. Request production access (leave the sandbox)

This step is between you and AWS. Silo can't request production access for you or speed up the review.

New SES accounts are in the sandbox in each region: you can send only to addresses and domains you have verified, up to 200 messages per 24 hours and one per second. That's enough to test Silo, not to mail your list.

  1. In the SES console, open Account dashboard and choose Request production access.
  2. Mail type: Marketing. Website URL: your company's site.
  3. In the use case, be specific: how people join your list (for example, a signup form with double opt-in), how often you send, and that bounces and complaints are processed automatically through SNS and suppressed, and that every email has an unsubscribe link.

AWS usually responds within about a day. They may ask follow-up questions or approve a lower starting quota; quotas rise as you build a sending history.

Checklist

  • Domain identity verified, three DKIM CNAMEs published
  • Custom MAIL FROM with MX and SPF records (recommended)
  • DMARC TXT record at _dmarc
  • IAM user with Silo's policy, keys saved in Silo
  • Bounce and complaint handling set up
  • Production access granted in your sending region
  • A link domain for signup pages and tracking

AWS console labels change from time to time. If a menu name here doesn't match, the SES documentation on verifying identities and requesting production access is the reference.