AWS Cognito集成SES验证域名后注册跳转错误及邮件未发送排查求助
Cognito托管UI注册跳转错误页且无验证邮件发送排查
问题背景
- 已为个人站点创建AWS Cognito用户池,以邮箱作为用户名,使用托管UI完成注册、登录操作
- 用户池配置了SES已验证域名身份,发件人为
no-reply@myverifieddomainidentity,该域名处于SES沙箱中;测试用个人Gmail邮箱已验证为SES邮件身份,Cognito与SES资源均部署在us-west-2区域
问题现象
- 点击托管UI注册并提交邮箱信息后,页面重定向至
/error - Cognito用户池中已生成该用户,但未收到邮箱确认邮件,SES控制台无邮件发送记录
- CloudTrail仅记录Cognito页面访问事件,无失败日志
已尝试操作
- 按AWS文档配置SES验证域名与Cognito集成,添加SES授权策略无效
- 通过AWS CLI执行注册操作返回成功,但仍无邮件发送
- SES模拟测试邮件可正常发送
- 创建
no-reply@myverifieddomainidentity的SES验证邮箱,确认无需配置MX记录(仅需发送邮件) - 使用Cognito默认邮件方案(发件人为
no-reply@verificationemail.com),问题依旧:跳转错误页、用户创建成功但无邮件
Terraform配置代码
resource "aws_ses_domain_identity" "this" { domain = aws_route53_zone.external.name } resource "aws_route53_record" "ses_domain_identity_verification_record" { zone_id = aws_route53_zone.external.zone_id name = "_ses_domain_identity_verification" # TODO: need full domain name? "_ses_verification_record.${aws_route53_zone.external.name}" type = "CNAME" ttl = "60" records = [aws_ses_domain_identity.this.verification_token] } resource "aws_ses_domain_dkim" "this" { domain = aws_ses_domain_identity.this.domain } resource "aws_route53_record" "ses_dkim_verification_record" { count = 3 # resource aws_ses_domain_dkim creates 3 tokens zone_id = aws_route53_zone.external.id name = "${element(aws_ses_domain_dkim.this.dkim_tokens, count.index)}._domainkey" type = "CNAME" ttl = "1800" records = ["${element(aws_ses_domain_dkim.this.dkim_tokens, count.index)}.dkim.amazonses.com"] } resource "aws_cognito_user_pool" "this" { name = local.project-deployment-name admin_create_user_config { allow_admin_create_user_only = false } password_policy { minimum_length = 8 require_lowercase = true require_numbers = true require_symbols = true require_uppercase = true temporary_password_validity_days = 1 } username_attributes = ["email"] # TODO: see https://github.com/hashicorp/terraform-provider-aws/issues/26726 # user_attribute_update_settings { # attributes_require_verification_before_update = ["email"] # } email_configuration { email_sending_account = "DEVELOPER" from_email_address = "no-reply@${aws_ses_domain_identity.this.domain}" source_arn = aws_ses_domain_identity.this.arn } account_recovery_setting { recovery_mechanism { name = "verified_email" priority = 1 } } schema { name = "email" attribute_data_type = "String" required = true mutable = true } schema { name = "name" attribute_data_type = "String" required = true mutable = true } schema { name = "birthdate" attribute_data_type = "String" required = true mutable = true } }
排查建议
- 修正SES域名验证记录:当前Terraform中
ses_domain_identity_verification_record的name字段未拼接完整域名,应改为"_ses_domain_identity_verification.${aws_route53_zone.external.name}",否则SES无法识别验证记录,导致Cognito无法调用SES发送邮件。 - 检查Cognito权限配置:给Cognito用户池关联的服务角色添加SES发送权限,策略需允许
ses:SendEmail和ses:SendRawEmail操作,目标资源为SES域名ARN或具体发件邮箱ARN。 - 开启Cognito日志记录:在Cognito控制台配置CloudWatch Logs日志组,授予Cognito写入权限,捕获注册过程中的具体错误信息(比如调用SES失败的原因)。
- 确认用户邮箱验证状态:在Cognito控制台查看新建用户的
email_verified字段状态,确认是否触发了验证流程。 - 验证SES沙箱收发权限:确保测试用的Gmail邮箱已在SES中验证为邮件身份,沙箱环境下仅允许向已验证的收件人发送邮件,同时发件人域名需完成完整验证(包括DKIM和身份验证记录)。
内容的提问来源于stack exchange,提问作者loesak
相关产品推荐
相关产品推荐

