AWS SES接收规则中“Require TLS”选项工作机制及规则集问题咨询
Let’s break down exactly how the "Require TLS" setting in AWS SES receipt rules functions, and why you saw the contrasting behavior in your two test cases:
Core Principle
First, a critical clarification: The Require TLS option only applies to the initial SMTP connection between the external sending server and SES's inbound SMTP endpoint. It has no impact on how SES routes or processes emails internally between rule actions (like passing from Lambda to S3). SES handles all internal email transfers securely by default—you don’t need extra configuration for this part.
Rule Matching Logic for TLS Enforcement
When an incoming email matches multiple receipt rules, SES determines whether to enforce TLS based on the combined settings of all matching rules:
- If every rule that matches the email has Require TLS = true: SES will reject the email if the sending server didn’t use a TLS-encrypted connection. This is exactly why your first case resulted in a bounce.
- If at least one matching rule has Require TLS = false: SES will accept the email regardless of whether the sending server used TLS. This is why your second case worked without issues.
Deep Dive Into Your Test Cases
Case 1 (Both rules require TLS):
Your receipt ruleset had two rules matching the incoming email, both enforcing TLS. SES checked the incoming SMTP connection and found it wasn’t using TLS (even if you assumed it was—double-check the sending server’s SMTP configuration!), so it rejected the email with the550 5.7.1 TLS requirederror.Case 2 (One rule allows non-TLS):
By setting the second rule’s Require TLS to false, you gave SES permission to accept the email even if the incoming connection wasn’t encrypted. Since at least one matching rule relaxed the TLS requirement, SES processed the email normally through both the Lambda and S3 actions.
Quick Checks If You Believe the Sending Server Used TLS
If you’re certain the sending server had TLS enabled, verify these details:
- Ensure the sending server uses TLS 1.0, 1.1, or 1.2 (SES doesn’t support older TLS versions or SSL-only connections).
- Confirm the test emails in both cases matched exactly the same rule conditions (e.g., same recipient address, subject keywords, etc.). A condition mismatch could explain the differing behavior.
内容的提问来源于stack exchange,提问作者Arshal Jain

