AWS SES跨域名发件时附件异常及DMARC配置相关咨询
Hey there, let's break this down step by step to figure out what's going on here.
First off, DMARC not being set up isn't directly causing your attachment issue—DMARC mainly deals with email authentication alignment and tells receivers what to do with unauthenticated messages (like quarantine or reject), but it doesn't typically mangle attachments like you're seeing. So Yahoo/Outlook being "fussy" is more likely, but let's dig into the specifics of your setup.
Let's start with the core of your setup: you're sending from SES hosted on example-site.com, but setting the From: header to an address from example-site-two.com. Even though you have DKIM set up on both domains, you need to make sure the authentication is properly aligned for Yahoo/Outlook's stricter checks. Here's what to verify:
- DKIM Alignment: SES signs emails with the DKIM key of the sending domain (example-site.com by default), but your
From:is example-site-two.com. For proper alignment, you need either:- Use a domain identity in SES for example-site-two.com, so SES signs the email with that domain's DKIM key instead. This way the DKIM domain matches the
From:domain, which satisfies strict alignment requirements from Yahoo/Outlook. - Or set up relaxed DKIM alignment (though most major providers prefer strict these days). But the better fix is to use the correct domain identity in SES for your
From:address.
- Use a domain identity in SES for example-site-two.com, so SES signs the email with that domain's DKIM key instead. This way the DKIM domain matches the
- SPF Setup: Even with DKIM, SPF is another authentication layer. Make sure example-site-two.com's SPF record includes the SES sending IPs or the SES SPF token
include:amazonses.com. If SPF fails and DKIM isn't properly aligned, Yahoo/Outlook might flag the email as suspicious and strip attachments as a security measure.
Now, why does Gmail work? Gmail is a bit more lenient with authentication alignment compared to Yahoo and Outlook, especially if one authentication method passes (like DKIM even if misaligned). But Yahoo/Outlook have stricter policies for messages that don't meet alignment standards, which can lead to content modification like stripping attachments.
As for your question about adding DMARC: it won't mess things up if you set it up correctly, and it's actually recommended to protect both domains. Here's how to approach it safely:
- Start with a
p=nonepolicy for both domains first—this tells receivers to just report on unauthenticated messages without taking action. You can use theruatag to get daily reports on which messages are failing authentication. - Once you've fixed any alignment issues (like getting DKIM/SPF aligned for your cross-domain sending), you can gradually move to
p=quarantineand thenp=rejectif needed. - Make sure the DMARC record for example-site-two.com includes the correct alignment settings (
adkim=sfor strict,aspf=sfor strict if you want, orrfor relaxed if needed).
To summarize the steps you should take:
- Fix DKIM/SPF alignment for your
From:domain (example-site-two.com) in SES—use the domain identity for that domain so SES signs emails with its DKIM key. - Verify that example-site-two.com's SPF record includes Amazon SES.
- Test sending again to Yahoo/Outlook after making these changes—your attachments should come through properly.
- Add DMARC records starting with
p=noneto both domains to monitor authentication, then adjust the policy as needed once everything is working.
备注:内容来源于stack exchange,提问作者P. Gearman

