使用Node.js的@aws-sdk/client-ses SDK发送邮件时遇到SignatureDoesNotMatch错误
Let's break down why you're hitting this signature mismatch error and walk through potential fixes for your code.
First off, your core code structure looks valid—you're initializing the SES client correctly and calling sendEmail with all the required parameters. The SignatureDoesNotMatch error almost always ties to authentication, permission, or regional configuration issues rather than syntax mistakes in your request. Here are the key areas to investigate:
1. Validate Your IAM Credentials
- Double-check that your
accessKeyIdandsecretAccessKeyare 100% accurate—no extra spaces, typos, or accidental character escapes. It's surprisingly easy to miss a character when copying these values. - Make sure the IAM user linked to these credentials has the necessary SES permissions. At minimum, they need the
ses:SendEmailaction assigned via an IAM policy. A basic policy for this would look like:{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "ses:SendEmail", "Resource": "*" } ] }
2. Confirm Regional Consistency
- SES requires that your verified sender email (the
Sourcevalue in your code) is validated in the same region you're using (eu-west-3). If you verified the email in another region (likeus-east-1), the request will fail even with correct credentials. - Double-check that your SES client is definitely pointing to
eu-west-3—mixing up region codes (e.g.,eu-west-2instead ofeu-west-3) will trigger signature mismatches.
3. Update Your AWS SDK Package
Outdated versions of the @aws-sdk/client-ses package can have compatibility issues with AWS's signature algorithms. Update to the latest version using:
npm update @aws-sdk/client-ses
4. Avoid Hardcoding Credentials (Best Practice + Debugging)
Hardcoding credentials can lead to accidental errors. Try loading them from environment variables instead—this is also AWS's recommended practice:
const aws = require("@aws-sdk/client-ses"); async function main() { // Credentials auto-load from AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY environment variables const ses = new aws.SES({ region: "eu-west-3" }); await ses.sendEmail({ Destination: { ToAddresses: ["REDACTED@REDACTED.com"] }, Message: { Subject: { Charset: "UTF-8", Data: "Test email" }, Body: { Text: { Charset: "UTF-8", Data: "This is the message body in text format." } } }, Source: "REDACTED@REDACTED.com" }); } main().catch(console.error);
Quick Debugging Test
To rule out code-specific issues, try sending an email via the AWS CLI with the same credentials and region:
aws ses send-email \ --from "REDACTED@REDACTED.com" \ --to "REDACTED@REDACTED.com" \ --subject "Test CLI Email" \ --text "This is a test from the CLI" \ --region eu-west-3
If this works, the problem is likely in how your code handles credentials (e.g., typos in hardcoded values). If it fails, your credentials or permissions are the root cause.
内容的提问来源于stack exchange,提问作者Thomas Lulé

