# Enabling the Amazon SES email channel in Kustomer

> Kustomer  is moving from Postmark as the primary email provider to Amazon Simple Email Service SES Amazon SES meets SOC 2 PCI and FedRAMP security standards

Source: https://help.kustomer.com/en_us/enabling-the-amazon-ses-email-channel-in-kustomer-B1fw0fJGMl

Last updated: 2026-06-30T20:37:05.200Z

Kustomer is moving from Postmark as the primary email provider to Amazon Simple Email Service (SES). Amazon SES meets SOC 2 and PCI security standards, and it is HIPAA compliant. These qualities make it the ideal choice for supporting our customers' email channel needs.

If you need to migrate from Postmark to Amazon SES, this guide will walk you through the migration and setup process — from selecting domains to updating DNS records and completing the cutover.

This tool is designed to simplify migration while minimizing downtime and preserving existing sending workflows.

### In this article

*   [Before You Begin](#before-you-begin)
    *   [Prompting the Optimize Automations skill to check workflows and business rules](#prompting-the-optimize-automations-skill-to-check-workflows-and-business-rules)
    *   [Why checking workflows and business rules post migration matters](#why-checking-workflows-and-business-rules-post-migration-matters)
*   [Starting the Migration](#starting-the-migration)
    *   [Prepare stage](#prepare-stage)
    *   [Review Eligible Domains](#review-eligible-domains)
    *   [Update DNS Records](#update-dns-records)
    *   [Verify DNS Status](#verify-dns-status)
    *   [Complete the Migration](#complete-the-migration)
*   [Migrating from Gmail](#migrating-from-gmail)
*   [Hiding Email Entries from the Draft Editor](#hiding-emails)
*   [Additional Notes](#additional-notes)

### Before You Begin

Before starting the migration, there are a few important considerations:

*   The migration process will move your inbound and outbound email delivery from Postmark to Amazon SES.
*   Workflows or business rules that utilize a migrated email address may be affected by these changes.
*   DNS access is required in order to complete domain verification.
*   Some DNS verification steps may take time to propagate depending on your DNS provider.

Use Kustomer Architect's **Optimize Automations** skill to check for business rule or workflow conflicts or errors and use AI to correct for these changes.

#### Prompting the Optimize Automations skill to check workflows and business rules

The key is to be **specific about the email address(es)** and **explicit about the migration direction**. Here's a template:

_"We are migrating `support@COMPANY.mail.com` from **Postmark** to **Amazon SES**. Please:_

_1\. Find every workflow that uses this email as a `from`, `to`, `bcc`, or `recipient` parameter_  
_2\. Find every workflow triggered by `kustomer.app.postmark.message.receive` that processes mail to this address — these will need to switch to `kustomer.app.amazon_ses.message.receive`_  
_3\. Find every business rule that references this email in its criteria (e.g., `message_recipients contains` or `customer_email equals`)_  
_4\. Flag any bounce/complaint/open tracking workflows that are Postmark-specific (e.g., `kustomer.app.postmark.message.bounce`) that will need SES equivalents_  
_5\. Give me a prioritized migration checklist — what to update first to avoid workflow gaps or duplicate conversations"_

Business rules often use `draft` actions to send emails using a specific `from` address. These can be easy to miss:

```
"Also check business rules that use [email] as the 'from' address
in draft/auto-reply actions"
```

*   **If you have multiple addresses**, list them all upfront: `"We're migrating support@, billing@, and returns@..."`
*   **Ask about the BCC pattern** specifically — Postmark and SES both have separate BCC-receive workflows (`postmark-bcc-receive` / `amazon_ses-bcc-receive`) that are easy to forget
*   **Ask about message status workflows** — bounce/complaint/open tracking events are provider-specific and will stop working if not remapped
*   **Ask "what would break today"** vs. "what needs updating" — some workflows may have conditions that already gracefully handle the gap

#### Why checking workflows and business rules post migration matters

This matters because trigger events are **provider-specific**:

**Old Provider**

**Old Trigger**

**New Trigger (SES)**

Postmark

`kustomer.app.postmark.message.receive`

`kustomer.app.amazon_ses.message.receive`

Gmail

`kustomer.app.gmail.message.receive`

`kustomer.app.amazon_ses.message.receive`

### Starting the Migration

If migration is needed, a banner at the top of **Channels > Email** will direct you to:

1.  Install the **Amazon SES** application from the Kustomer **Application Store**
    1.  Click **Application Store** from the left navigation panel.
    2.  Search for **Amazon SES.**
    3.  Click **Upgrade/Install**.
2.  **Start migration** once you have installed the Amazon SES application.

  

![](https://cdn.kustomerhostedcontent.com/media/570fad9d9001bc1000163b28/691414dc6ce187f1cd2abdb7b762520b.png)

To begin, click **Start migration.** Migration follows 5 steps:

1.  **Prepare**, which explains all you need to know before you start.
2.  **Review**, where you select a domain to migrate and can view domain migrations in progress.
3.  **Update DNS Records**, where you copy the **DNS record data** necessary to authorize Kustomer to use your domain. Kustomer managed domains are auto verified.
4.  **Verify DNS status**, where you can review the domain status for the selected domain.
5.  **Go live**, where you are ready to begin using your new Amazon SES email address with Kustomer.

#### Prepare stage

Prepare gives you all the information you need to know prior to beginning the migration. Specifically:

1.  Your domain is being moved to Amazon SES.
2.  You will need access to your DNS settings to complete the migration.
3.  Review all resources that send email from your domain. Resources include:
    1.  Workflows
    2.  Business rules
    3.  Email templates
    4.  Shortcuts
4.  Postmark sending is disabled at the cut-over. Completion of the migration is the final step.

See [Prompting the Optimize Automations skill to check workflows and business rules](#prompting-the-optimize-automations-skill-to-check-workflows-and-business-rules).

#### Review Eligible Domains

During the review step, Kustomer displays domains currently configured for outbound email sending that are eligible for migration in a table. This table displays:

*   Email address
*   Name used in Kustomer
*   Current migration status for each domain.

Admins can select a domain to migrate, ensuring only the intended domain is moved to Amazon SES.

#### Update DNS Records

After selecting domains, the wizard generates the DNS records required for Amazon SES verification. Click **Show Record** to show each of these records.

These records typically include:

*   DKIM CNAME records
*   Domain verification records
*   Additional SES authentication entries

Admins must copy these records into their DNS provider. Click **Copy All Records** to copy all records to paste in bulk.

In the right pane, find guidance for common DNS providers. DNS propagation may take up to 72 hours to propagate.

Once these records are changed on your provider side, tick the box labeled **Yes, these records have been updated in the DNS settings** and then click **Continue** to proceed.

#### Verify DNS Status

Once DNS records are added, the migration tool checks whether records have propagated successfully.

Verified records are marked automatically within the wizard. If records are still pending or unverified, admins can continue checking status after propagation completes. Click **Refresh Status** to run a new verification check.

This validation step helps ensure Amazon SES is fully configured before email traffic is switched over.

If records remain unverified after 72 hours, check your DNS settings to confirm there are no duplicate or invalid records (such as [kbounces.example.com.example.com](http://kbounces.example.com.example.com)). If you find duplicate or invalid records, retry entering your domain settings and re-run the verification check.

#### Complete the Migration

After verification succeeds, the final step allows admins to complete the migration.

At this stage:

*   Outbound email sending is routed through Amazon SES
*   Existing Kustomer workflows continue operating normally
*   Customer-facing addresses remain unchanged

The tool also provides optional forwarding guidance for inbound mail handling during transition.

### Migrating from Gmail

Migrating from Gmail is as simple as creating a new customer email within Kustomer. 

First, create a new email using a custom domain:

1.  Go to **Apps> Email**.
2.  Select **Add Email Address** and click **Custom Domain**. 
3.  Create an **Email alias** and configure basic setup. See [**Receive email in Kustomer**](https://help.kustomer.com/en_us/receive-email-in-kustomer-rJWnIhva) for more details.

Next, delete your Gmail connection:

1.  Click **Settings > Channels >** **Email.** 
2.  From the **Email Settings** page, locate your Gmail address and then click the **Trash can** icon to delete. 
3.  Click **Yes** to confirm deletion. 

Once deleted, your migration from Gmail to Amazon SES is completed. 

### Hiding Email Entries from the Draft Editor

Amazon SES allows customers to hide email entries from the draft editor, allowing you to receive emails to an inbox, but prevent agents from sending emails from that email address. This setting is on by default for all email addresses.

To toggle this setting on, follow these steps:

1.  Navigate to the email controls under Settings > Channels > Email
2.  Click the edit icon next to an Amazon SES email address
3.  Toggle the "Show this address in the composer's from list" setting off

Once the setting is toggled off, agents will no longer be able to select a hidden address from the draft editor.

### Additional Notes

DNS propagation timing varies by provider. If verification does not complete immediately, wait for DNS updates to propagate and retry verification within the migration wizard.

For production migrations, ensure all DNS records are copied exactly as provided by the tool before completing the final cutover.

Once migrated to Amazon SES, you are able to manage your suppression list from **Settings>Administration>Spam Filters**. Click the Suppression List tab to review email addresses added to this list for removal. See [Manage spam filters](https://help.kustomer.com/en_us/create-spam-filters-B1jA02xGL).
