554 Message rejected: Email address is not verified
Amazon SES refused to send because the From address, or its domain, has not been verified in the SES console for the region you are using. In a sandbox account the recipient must be verified too, and the same message names whichever side failed. SES is the sending side here: this is the reply your application receives when it submits mail.
What the server replies
554 Message rejected: Email address is not verified. The following identities failed the check in region EU-CENTRAL-1: hello@example.com
- Sent by
- Amazon SES
- Type
- PermanentRetry fails
- About
- Receiver policy
- Enhanced code
- None sent
Who sends it
The SES SMTP interface and the SendEmail API, at submission, in any account whose verified identities do not cover the addresses in use. Region matters: identities are verified per region.
Why it happens
- The domain was verified in one region but the code is sending through an endpoint in another.
- The account is still in the SES sandbox and the recipient address is not verified.
- The From address uses a subdomain that is not covered by the verified domain identity.
- Verification of the domain expired or failed because the DKIM CNAME records were removed from DNS.
How to fix it
Check the region in the reply
The message names the region. Open the SES console in that region and look at Verified identities; the From domain must show as Verified there.
Verify the domain, not single addresses
Add the domain as an identity and publish the three DKIM CNAME records SES generates. A verified domain covers every address and subdomain under it.
Leave the sandbox
Request production access in the SES console. Until then SES only delivers to verified recipients and caps sending at 200 messages a day.
Match the endpoint to the identity
Use the SMTP endpoint for the region where the identity lives, for example email-smtp.eu-central-1.amazonaws.com.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
Related codes
- 454 Throttling failure: Maximum sending rate exceededYour application is submitting to SES faster than the account's per-second sending rate, or has used its 24-hour quota (the wording is then "Daily message quota exceeded").
- 535 5.7.8 Authentication credentials invalid / Username and Password not acceptedThe server rejected the login.
- 550 5.4.5 Daily sending quota exceededThis one comes back when you send through Gmail, not to it.
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.