You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Cognito集成SES验证域名后注册跳转错误及邮件未发送排查求助

Cognito托管UI注册跳转错误页且无验证邮件发送排查

问题背景

  • 已为个人站点创建AWS Cognito用户池,以邮箱作为用户名,使用托管UI完成注册、登录操作
  • 用户池配置了SES已验证域名身份,发件人为no-reply@myverifieddomainidentity,该域名处于SES沙箱中;测试用个人Gmail邮箱已验证为SES邮件身份,Cognito与SES资源均部署在us-west-2区域

问题现象

  • 点击托管UI注册并提交邮箱信息后,页面重定向至/error
  • Cognito用户池中已生成该用户,但未收到邮箱确认邮件,SES控制台无邮件发送记录
  • CloudTrail仅记录Cognito页面访问事件,无失败日志

已尝试操作

  • 按AWS文档配置SES验证域名与Cognito集成,添加SES授权策略无效
  • 通过AWS CLI执行注册操作返回成功,但仍无邮件发送
  • SES模拟测试邮件可正常发送
  • 创建no-reply@myverifieddomainidentity的SES验证邮箱,确认无需配置MX记录(仅需发送邮件)
  • 使用Cognito默认邮件方案(发件人为no-reply@verificationemail.com),问题依旧:跳转错误页、用户创建成功但无邮件

Terraform配置代码

resource "aws_ses_domain_identity" "this" {
  domain = aws_route53_zone.external.name
}

resource "aws_route53_record" "ses_domain_identity_verification_record" {
  zone_id = aws_route53_zone.external.zone_id
  name    = "_ses_domain_identity_verification" # TODO: need full domain name? "_ses_verification_record.${aws_route53_zone.external.name}"
  type    = "CNAME"
  ttl     = "60"
  records = [aws_ses_domain_identity.this.verification_token]
}

resource "aws_ses_domain_dkim" "this" {
  domain = aws_ses_domain_identity.this.domain
}

resource "aws_route53_record" "ses_dkim_verification_record" {
  count = 3 # resource aws_ses_domain_dkim creates 3 tokens

  zone_id = aws_route53_zone.external.id
  name    = "${element(aws_ses_domain_dkim.this.dkim_tokens, count.index)}._domainkey"
  type    = "CNAME"
  ttl     = "1800"
  records = ["${element(aws_ses_domain_dkim.this.dkim_tokens, count.index)}.dkim.amazonses.com"]
}

resource "aws_cognito_user_pool" "this" {
  name = local.project-deployment-name

  admin_create_user_config {
    allow_admin_create_user_only = false
  }

  password_policy {
    minimum_length                   = 8
    require_lowercase                = true
    require_numbers                  = true
    require_symbols                  = true
    require_uppercase                = true
    temporary_password_validity_days = 1
  }

  username_attributes = ["email"]

  # TODO: see https://github.com/hashicorp/terraform-provider-aws/issues/26726
  #  user_attribute_update_settings {
  #    attributes_require_verification_before_update = ["email"]
  #  }

  email_configuration {
    email_sending_account = "DEVELOPER"
    from_email_address    = "no-reply@${aws_ses_domain_identity.this.domain}"
    source_arn            = aws_ses_domain_identity.this.arn
  }

  account_recovery_setting {
    recovery_mechanism {
      name     = "verified_email"
      priority = 1
    }
  }
  
  schema {
    name                = "email"
    attribute_data_type = "String"
    required            = true
    mutable             = true
  }

  schema {
    name                = "name"
    attribute_data_type = "String"
    required            = true
    mutable             = true
  }

  schema {
    name                = "birthdate"
    attribute_data_type = "String"
    required            = true
    mutable             = true
  }
}

排查建议

  • 修正SES域名验证记录:当前Terraform中ses_domain_identity_verification_record的name字段未拼接完整域名,应改为"_ses_domain_identity_verification.${aws_route53_zone.external.name}",否则SES无法识别验证记录,导致Cognito无法调用SES发送邮件。
  • 检查Cognito权限配置:给Cognito用户池关联的服务角色添加SES发送权限,策略需允许ses:SendEmail和ses:SendRawEmail操作,目标资源为SES域名ARN或具体发件邮箱ARN。
  • 开启Cognito日志记录:在Cognito控制台配置CloudWatch Logs日志组,授予Cognito写入权限,捕获注册过程中的具体错误信息(比如调用SES失败的原因)。
  • 确认用户邮箱验证状态:在Cognito控制台查看新建用户的email_verified字段状态,确认是否触发了验证流程。
  • 验证SES沙箱收发权限:确保测试用的Gmail邮箱已在SES中验证为邮件身份,沙箱环境下仅允许向已验证的收件人发送邮件,同时发件人域名需完成完整验证(包括DKIM和身份验证记录)。

内容的提问来源于stack exchange,提问作者loesak

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 20:50:30