554 Message rejected: Email address is not verified

Amazon SES refused to send because the From address, or its domain, has not been verified in the SES console for the region you are using. In a sandbox account the recipient must be verified too, and the same message names whichever side failed. SES is the sending side here: this is the reply your application receives when it submits mail.

What the server replies

554 Message rejected: Email address is not verified. The following identities failed the check in region EU-CENTRAL-1: hello@example.com

Sent by
Amazon SES
Type
PermanentRetry fails
About
Receiver policy
Enhanced code
None sent

Who sends it

The SES SMTP interface and the SendEmail API, at submission, in any account whose verified identities do not cover the addresses in use. Region matters: identities are verified per region.

Why it happens

  • The domain was verified in one region but the code is sending through an endpoint in another.
  • The account is still in the SES sandbox and the recipient address is not verified.
  • The From address uses a subdomain that is not covered by the verified domain identity.
  • Verification of the domain expired or failed because the DKIM CNAME records were removed from DNS.

How to fix it

  1. Check the region in the reply

    The message names the region. Open the SES console in that region and look at Verified identities; the From domain must show as Verified there.

  2. Verify the domain, not single addresses

    Add the domain as an identity and publish the three DKIM CNAME records SES generates. A verified domain covers every address and subdomain under it.

  3. Leave the sandbox

    Request production access in the SES console. Until then SES only delivers to verified recipients and caps sending at 200 messages a day.

  4. Match the endpoint to the identity

    Use the SMTP endpoint for the region where the identity lives, for example email-smtp.eu-central-1.amazonaws.com.

Check it yourself

These free tools show the records and connections behind this code for your own domain or server.

Related codes

Sources

Fewer bounces to look up.

Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.

Send with Faivelo

Free tier included. No card needed.