Simple Email Service
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for Simple Email Service rules that match the service but not a specific eventName. | N | N |
| Create | Creates a new email identity (domain or email address) and begins the verification process. | Y | Y |
| Delete | Deletes an email identity (domain or email address) previously created in SES v2. | Y | Y |
| Delete | Deletes the specified email address or domain identity from the list of verified identities in Amazon SES. | Y | Y |
| Put | Enables or disables the ability to send email from the AWS account globally. | N | Y |
| Put | Enables or disables email sending for a specific configuration set. | Y | Y |
| Update | Enables or disables email sending for an Amazon SES account. | Y | Y |
| Update | Enables or disables email sending for a configuration set (SES v1 API). | Y | Y |
| Verify | Returns a set of DKIM tokens for a domain identity and begins the DKIM verification process. | Y | Y |
| Verify | Adds a domain to the list of identities and initiates domain ownership verification. | Y | Y |
| Verify | Adds an email address to the list of identities and attempts to verify it by sending a verification email. | Y | Y |
| Delete | DeleteSuppressedDestination recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Describe | DescribeActiveReceiptRuleSet recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | Y | N |
| Describe | DescribeReceiptRuleSet recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetAccount recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetConfigurationSet recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetConfigurationSetEventDestinations recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetDedicatedIps recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetEmailIdentity recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetEmailIdentityPolicies recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetEmailTemplate recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetIdentityDkimAttributes recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetIdentityMailFromDomainAttributes recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetIdentityVerificationAttributes recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | Y |
| Get | GetSendQuota recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | Y |
| List | ListConfigurationSets recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListContactLists recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListCustomVerificationEmailTemplates recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListDedicatedIpPools recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListEmailIdentities recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListEmailTemplates recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListExportJobs recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListIdentities recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | Y | N |
| List | ListImportJobs recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListIngressPoints recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListMultiRegionEndpoints recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListReceiptFilters recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListReceiptRuleSets recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListRecommendations recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListRuleSets recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListSuppressedDestinations recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListTrafficPolicies recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | Returns the email sending status of the Amazon SES account for the current Region. | N | Y |
| Batch | Retrieves batches of metric data collected based on your sending activity. | N | N |
| Cancel | Cancels an export job. | N | N |
| Clone | Creates a receipt rule set by cloning an existing one. | N | N |
| Create | Create a configuration set. | N | N |
| Create | Create an event destination. | N | N |
| Create | Creates an association between a configuration set and a custom domain for open and click event tracking. | N | N |
| Create | Creates a contact, which is an end-user who is receiving the email, and adds them to a contact list. | N | N |
| Create | Creates a contact list. | N | N |
| Create | Creates a new custom verification email template. | N | N |
| Create | Create a new pool of dedicated IP addresses. | N | N |
| Create | Create a new predictive inbox placement test. | N | N |
| Create | Creates the specified sending authorization policy for the given identity (an email address or a domain). | N | N |
| Create | Creates an email template. | N | N |
| Create | Creates an export job for a data source and destination. | N | N |
| Create | Creates an import job for a data destination. | N | N |
| Create | Creates a multi-region endpoint (global-endpoint). | N | N |
| Create | Creates a new IP address filter. | N | N |
| Create | Creates a receipt rule. | N | N |
| Create | Creates an empty receipt rule set. | N | N |
| Create | Creates an email template. | N | N |
| Create | Create a tenant. | N | N |
| Create | Associate a resource with a tenant. | N | N |
| Delete | Delete an existing configuration set. | N | N |
| Delete | Delete an event destination. | N | N |
| Delete | Deletes an association between a configuration set and a custom domain for open and click event tracking. | N | N |
| Delete | Removes a contact from a contact list. | N | N |
| Delete | Deletes a contact list and all of the contacts on that list. | N | N |
| Delete | Deletes an existing custom verification email template. | N | N |
| Delete | Delete a dedicated IP pool. | N | N |
| Delete | Deletes the specified sending authorization policy for the given identity (an email address or a domain). | N | N |
| Delete | Deletes an email template. | N | N |
| Delete | Deletes the specified sending authorization policy for the given identity (an email address or a domain). | N | N |
| Delete | Deletes a multi-region endpoint (global-endpoint). | N | N |
| Delete | Deletes the specified IP address filter. | N | N |
| Delete | Deletes the specified receipt rule. | N | N |
| Delete | Deletes the specified receipt rule set and all of the receipt rules it contains. | N | N |
| Delete | Deletes an email template. | N | N |
| Delete | Delete an existing tenant. | N | N |
| Delete | Delete an association between a tenant and a resource. | N | N |
| Delete | Deprecated. | N | N |
| Describe | Returns the details of the specified configuration set. | N | N |
| Describe | Returns the details of the specified receipt rule. | N | N |
| Get | Retrieve a list of the blacklists that your dedicated IP addresses appear on. | N | N |
| Get | Returns a contact from a contact list. | N | N |
| Get | Returns contact list metadata. | N | N |
| Get | Returns the custom email verification template for the template name you specify. | N | N |
| Get | Get information about a dedicated IP address, including the name of the dedicated IP pool that it's associated with, as well information about the automatic warm-up process for the address. | N | N |
| Get | Retrieve information about the dedicated pool. | N | N |
| Get | Retrieve information about the status of the Deliverability dashboard for your Amazon Pinpoint account. | N | N |
| Get | Retrieve the results of a predictive inbox placement test. | N | N |
| Get | Retrieve all the deliverability data for a specific campaign. | N | N |
| Get | Retrieve inbox placement and engagement rates for the domains that you use to send email. | N | N |
| Get | Provides validation insights about a specific email address, including syntax validation, DNS record checks, mailbox existence, and other deliverability factors. | N | N |
| Get | Provides information about an export job. | N | N |
| Get | Given a list of verified identities (email addresses and/or domains), returns a structure describing identity notification attributes. | N | N |
| Get | Returns the requested sending authorization policies for the given identity (an email address or a domain). | N | N |
| Get | Provides information about an import job. | N | N |
| Get | Provides information about a specific message, including the from address, the subject, the recipient address, email tags, as well as events associated with the message. | N | N |
| Get | Displays the multi-region endpoint (global-endpoint) configuration. | N | N |
| Get | Retrieve information about a specific reputation entity, including its reputation management policy, customer-managed status, Amazon Web Services Amazon SES-managed status, and aggregate sending status. | N | N |
| Get | Provides sending statistics for the current Amazon Web Services Region. | N | N |
| Get | Retrieves information about a specific email address that's on the suppression list for your account or for a specific tenant. | N | N |
| Get | Displays the template object (which includes the Subject line, HTML part and text part) for the template you specify. | N | N |
| Get | Get information about a specific tenant, including the tenant's name, ID, ARN, creation timestamp, tags, sending status, and suppression attributes. | N | N |
| List | Lists the contacts present in a specific contact list. | N | N |
| List | Show a list of the predictive inbox placement tests that you've performed, regardless of their statuses. | N | N |
| List | Retrieve deliverability data for all the campaigns that used a specific domain to send email during a specified time range. | N | N |
| List | Returns a list of sending authorization policies that are attached to the given identity (an email address or a domain). | N | N |
| List | List reputation entities in your Amazon SES account in the current Amazon Web Services Region. | N | N |
| List | List all tenants associated with a specific resource. | N | N |
| List | Retrieve a list of the tags (keys and values) that are associated with a specified resource. | N | N |
| List | Lists the email templates present in your Amazon SES account in the current Amazon Web Services Region. | N | N |
| List | List all resources associated with a specific tenant. | N | N |
| List | List all tenants associated with your account in the current Amazon Web Services Region. | N | N |
| List | Deprecated. | N | N |
| Put | Enable or disable the automatic warm-up feature for dedicated IP addresses. | N | N |
| Put | Update your Amazon SES account details. | N | N |
| Put | Change the settings for the account-level suppression list. | N | N |
| Put | Update your Amazon SES account VDM attributes. | N | N |
| Put | Associate the configuration set with a MailManager archive. | N | N |
| Put | Associate a configuration set with a dedicated IP pool. | N | N |
| Put | Enable or disable collection of reputation metrics for emails that you send using a particular configuration set in a specific AWS Region. | N | N |
| Put | Specify the suppression list preferences for a configuration set. | N | N |
| Put | Specify a custom domain to use for open and click tracking elements in email that you send using Amazon Pinpoint. | N | N |
| Put | Specify VDM preferences for email that you send using the configuration set. | N | N |
| Put | Move a dedicated IP address to an existing dedicated IP pool. | N | N |
| Put | Used to convert a dedicated IP pool to a different scaling mode. | N | N |
| Put | PutDedicatedIpWarmupAttributes API operation for Amazon Simple Email Service. | N | N |
| Put | Enable or disable the Deliverability dashboard for your Amazon Pinpoint account. | N | N |
| Put | Used to associate a configuration set with an email identity. | N | N |
| Put | Used to enable or disable DKIM authentication for an email identity. | N | N |
| Put | Used to configure or change the DKIM authentication settings for an email domain identity. | N | N |
| Put | Used to enable or disable feedback forwarding for an identity. | N | N |
| Put | Used to enable or disable the custom Mail-From domain configuration for an email identity. | N | N |
| Put | Adds or updates a sending authorization policy for the specified identity (an email address or a domain). | N | N |
| Put | Adds an email address to the suppression list for your account or for a specific tenant. | N | N |
| Put | Configure the suppression list preferences for a tenant. | N | N |
| Reorder | Reorders the receipt rules within a receipt rule set. | N | N |
| Send | Generates and sends a bounce message to the sender of an email you received through Amazon SES. | N | N |
| Send | Composes an email message to multiple destinations. | N | N |
| Send | Composes an email message to multiple destinations. | N | N |
| Send | Adds an email address to the list of identities for your Amazon SES account in the current Amazon Web Services Region and attempts to verify it. | N | N |
| Send | Sends an email message. | N | N |
| Send | Composes an email message and immediately queues it for sending. | N | N |
| Send | Composes an email message using an email template and immediately queues it for sending. | N | N |
| Set | Sets the specified receipt rule set as the active receipt rule set. | N | N |
| Set | Enables or disables Easy DKIM signing of email sent from an identity. | N | N |
| Set | Given an identity (an email address or a domain), enables or disables whether Amazon SES forwards bounce and complaint notifications as email. | N | N |
| Set | Given an identity (an email address or a domain), sets whether Amazon SES includes the original email headers in the Amazon Simple Notification Service (Amazon SNS) notifications of a specified type. | N | N |
| Set | Enables or disables the custom MAIL FROM domain setup for a verified identity (an email address or a domain). | N | N |
| Set | Sets an Amazon Simple Notification Service (Amazon SNS) topic to use when delivering notifications. | N | N |
| Set | Sets the position of the specified receipt rule in the receipt rule set. | N | N |
| Tag | Add one or more tags (keys and values) to a specified resource. | N | N |
| Test | Creates a preview of the MIME content of an email when provided with a template and a set of replacement data. | N | N |
| Test | Creates a preview of the MIME content of an email when provided with a template and a set of replacement data. | N | N |
| Untag | Remove one or more tags (keys and values) from a specified resource. | N | N |
| Update | Update the configuration of an event destination for a configuration set. | N | N |
| Update | Enables or disables the publishing of reputation metrics for emails sent using a specific configuration set in a given Amazon Web Services Region. | N | N |
| Update | Modifies an association between a configuration set and a custom domain for open and click event tracking. | N | N |
| Update | Updates a contact's preferences for a list. | N | N |
| Update | Updates contact list metadata. | N | N |
| Update | Updates an existing custom verification email template. | N | N |
| Update | Updates the specified sending authorization policy for the given identity (an email address or a domain). | N | N |
| Update | Updates an email template. | N | N |
| Update | Updates a receipt rule. | N | N |
| Update | Update the customer-managed sending status for a reputation entity. | N | N |
| Update | Update the reputation management policy for a reputation entity. | N | N |
| Update | Updates an email template. | N | N |
| Verify | Deprecated. | N | N |
| Put | Set the pricing plan for your Amazon SES account. | N | N |
any: Simple Email Service (catch-all)
#Description
Catch-all entry for Simple Email Service rules that match the service but not a specific eventName.
CreateEmailIdentity
#Description
Creates a new email identity (domain or email address) and begins the verification process.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "5ea8bf6c-d18f-4e8b-987c-c7e1e0f785bc",
"eventName": "CreateEmailIdentity",
"eventSource": "ses.amazonaws.com",
"eventTime": "2026-06-29T19:25:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c01cbc4c-b20b-4ff2-85d5-283952327ba0",
"requestParameters": {
"emailIdentity": "dwfix2@example.com"
},
"responseElements": {
"identityType": "EMAIL_ADDRESS",
"verifiedForSendingStatus": false
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "email.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1496↳ also matches DeleteEmailIdentity, PutAccountSendingAttributes, PutConfigurationSetSendingOptions, UpdateAccountSendingEnabled, UpdateConfigurationSetSendingEnabled, VerifyDomainDkim, VerifyDomainIdentity, VerifyEmailIdentity
DeleteEmailIdentity
#Description
Deletes an email identity (domain or email address) previously created in SES v2.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "2d766db2-585c-4594-b465-0073a38e47de",
"eventName": "DeleteEmailIdentity",
"eventSource": "ses.amazonaws.com",
"eventTime": "2026-06-29T19:25:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f98cb016-4b4d-494a-80ad-d0a9af89ac1d",
"requestParameters": {
"emailIdentity": "dwfix2@example.com"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "email.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1496↳ also matches CreateEmailIdentity, PutAccountSendingAttributes, PutConfigurationSetSendingOptions, UpdateAccountSendingEnabled, UpdateConfigurationSetSendingEnabled, VerifyDomainDkim, VerifyDomainIdentity, VerifyEmailIdentity
DeleteIdentity
#Description
Deletes the specified email address or domain identity from the list of verified identities in Amazon SES.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "56133045-444a-423f-a63f-1b25a0a5a8f0",
"eventName": "DeleteIdentity",
"eventSource": "ses.amazonaws.com",
"eventTime": "2026-06-29T19:25:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d0f38f11-9503-4b28-a3ff-5c053b5cdd0d",
"requestParameters": {
"identity": "dwfix@example.com"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "email.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1070
PutAccountSendingAttributes
#Description
Enables or disables the ability to send email from the AWS account globally.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1496↳ also matches CreateEmailIdentity, DeleteEmailIdentity, PutConfigurationSetSendingOptions, UpdateAccountSendingEnabled, UpdateConfigurationSetSendingEnabled, VerifyDomainDkim, VerifyDomainIdentity, VerifyEmailIdentity
PutConfigurationSetSendingOptions
#Description
Enables or disables email sending for a specific configuration set.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "749d7d0e-7ad5-414f-a22d-913ffef9bd93",
"eventName": "PutConfigurationSetSendingOptions",
"eventSource": "ses.amazonaws.com",
"eventTime": "2026-06-29T19:25:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "71d6fb61-d709-4b10-8a8e-218301f47952",
"requestParameters": {
"configurationSetName": "dwfix-cs",
"sendingEnabled": true
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "email.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1496↳ also matches CreateEmailIdentity, DeleteEmailIdentity, PutAccountSendingAttributes, UpdateAccountSendingEnabled, UpdateConfigurationSetSendingEnabled, VerifyDomainDkim, VerifyDomainIdentity, VerifyEmailIdentity
UpdateAccountSendingEnabled
#Description
Enables or disables email sending for an Amazon SES account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::123456789012:user/TrailDiscover is not authorized to perform: ses:UpdateAccountSendingEnabled because no identity-based policy allows the ses:UpdateAccountSendingEnabled action",
"eventCategory": "Management",
"eventID": "d234aba0-2ad3-4956-89ac-9c0e31e34cf7",
"eventName": "UpdateAccountSendingEnabled",
"eventSource": "ses.amazonaws.com",
"eventTime": "2024-08-18T16:21:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6d503bfc-74ce-495e-bce8-54ab5c19d2f7",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "0.0.0.0",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "email.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_8e0a4769-3fe9-43b1-9892-845f4bfc1864 cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#ses.update-account-sending-enabled",
"userIdentity": {
"accessKeyId": "AKIA****************",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/TrailDiscover",
"principalId": "AROA****************:User",
"type": "IAMUser",
"userName": "TrailDiscover"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1496↳ also matches CreateEmailIdentity, DeleteEmailIdentity, PutAccountSendingAttributes, PutConfigurationSetSendingOptions, UpdateConfigurationSetSendingEnabled, VerifyDomainDkim, VerifyDomainIdentity, VerifyEmailIdentity
References #
UpdateConfigurationSetSendingEnabled
#Description
Enables or disables email sending for a configuration set (SES v1 API).
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "ThrottlingException",
"errorMessage": "Update conflict when updating configuration set <dw-probe>.",
"eventCategory": "Management",
"eventID": "2cfbd256-ff4b-441e-9342-47874ae0881f",
"eventName": "UpdateConfigurationSetSendingEnabled",
"eventSource": "ses.amazonaws.com",
"eventTime": "2026-06-29T19:26:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "aa5687e2-1f84-413a-9051-78a8ccebdee7",
"requestParameters": {
"configurationSetName": "dw-probe",
"enabled": false
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "email.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1496↳ also matches CreateEmailIdentity, DeleteEmailIdentity, PutAccountSendingAttributes, PutConfigurationSetSendingOptions, UpdateAccountSendingEnabled, VerifyDomainDkim, VerifyDomainIdentity, VerifyEmailIdentity
VerifyDomainDkim
#Description
Returns a set of DKIM tokens for a domain identity and begins the DKIM verification process.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "453e5986-beee-4cad-a83f-0baabf774d6f",
"eventName": "VerifyDomainDkim",
"eventSource": "ses.amazonaws.com",
"eventTime": "2026-06-29T19:25:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "751e0e7b-5bb6-49fc-9a70-8c898303e6ba",
"requestParameters": {
"domain": "dwfix.example.com"
},
"responseElements": {
"dkimTokens": [
"fdv636i5jpjsoshs7g7jothf22heh4jx",
"qyxoh4wzvv3flwhhsh4rs63t2x2zixyk",
"4bn3r4lmr3f2ukidlfvt45roljxgno7b"
]
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "email.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1496↳ also matches CreateEmailIdentity, DeleteEmailIdentity, PutAccountSendingAttributes, PutConfigurationSetSendingOptions, UpdateAccountSendingEnabled, UpdateConfigurationSetSendingEnabled, VerifyDomainIdentity, VerifyEmailIdentity
VerifyDomainIdentity
#Description
Adds a domain to the list of identities and initiates domain ownership verification.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "2c7ff554-7e58-4da6-b09f-5de82686de7a",
"eventName": "VerifyDomainIdentity",
"eventSource": "ses.amazonaws.com",
"eventTime": "2026-06-29T19:25:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7c36f914-a46d-4df6-a90e-b8f430470fcb",
"requestParameters": {
"disableEmailNotifications": false,
"domain": "dwfix.example.com"
},
"responseElements": {
"verificationToken": "Hw1ecktdYs9Q15bCML+ASEnSzgGjS9xSkHQY8t+EkuQ="
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "email.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1496↳ also matches CreateEmailIdentity, DeleteEmailIdentity, PutAccountSendingAttributes, PutConfigurationSetSendingOptions, UpdateAccountSendingEnabled, UpdateConfigurationSetSendingEnabled, VerifyDomainDkim, VerifyEmailIdentity
VerifyEmailIdentity
#Description
Adds an email address to the list of identities and attempts to verify it by sending a verification email.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "d9d9b64d-6010-47ad-859c-7ab7c2d28dea",
"eventName": "VerifyEmailIdentity",
"eventSource": "ses.amazonaws.com",
"eventTime": "2026-06-29T19:25:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b98b4f56-f909-49e2-973f-8fa4b82eab43",
"requestParameters": {
"emailAddress": "dwfix@example.com"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "email.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1496↳ also matches CreateEmailIdentity, DeleteEmailIdentity, PutAccountSendingAttributes, PutConfigurationSetSendingOptions, UpdateAccountSendingEnabled, UpdateConfigurationSetSendingEnabled, VerifyDomainDkim, VerifyDomainIdentity
DeleteSuppressedDestination
#Description
DeleteSuppressedDestination recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "1750d0f7-811e-4db7-8025-ed82a70f22de",
"eventSource": "ses.amazonaws.com",
"eventName": "DeleteSuppressedDestination",
"awsRegion": "ap-southeast-2",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "f616d718-6fd8-4129-b0d6-a770ca36bb28",
"userAgent": "Boto3/1.43.54 md/Botocore#1.43.54 ua/2.1 os/linux#6.8.0-1061-aws md/arch#aarch64 lang/python#3.11.15 md/pyimpl#CPython m/0,b,Z,D cfg/retry-mode#legacy Botocore/1.43.54",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.ap-southeast-2.amazonaws.com"
}
}
DescribeActiveReceiptRuleSet
#Description
DescribeActiveReceiptRuleSet recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
{
"additionalEventData": {
"SignatureVersion": "4"
},
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "636dd6b4-98a4-4774-96b8-84445fc4da63",
"eventName": "DescribeActiveReceiptRuleSet",
"eventSource": "ses.amazonaws.com",
"eventTime": "2021-04-13T11:35:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "111111111111",
"requestID": "dce43587-af21-4cf5-b916-6b3b43e4106f",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "95.90.195.80",
"userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:user/cloudsploit",
"principalId": "AIDAYTOGP2RLMDEPWZWMJ",
"type": "IAMUser",
"userName": "cloudsploit"
}
}
References #
DescribeReceiptRuleSet
#Description
DescribeReceiptRuleSet recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "51c4bfdb-5f8c-406c-bfb4-8fca0bc81f35",
"eventSource": "ses.amazonaws.com",
"eventName": "DescribeReceiptRuleSet",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "982284e7-1d16-4cba-9a65-ee915fd15a06",
"userAgent": "config.amazonaws.com"
}
GetAccount
#Description
GetAccount recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "d858db9f-c03a-4135-b9a4-b5d4b7b481c7",
"eventSource": "ses.amazonaws.com",
"eventName": "GetAccount",
"awsRegion": "ap-northeast-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "cd3d3ade-d119-4d0d-93dd-1070456d71f6",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sesv2#1.60.3 m/E,i",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.ap-northeast-2.amazonaws.com"
}
}
GetConfigurationSet
#Description
GetConfigurationSet recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "8e3fa9c9-a699-4b86-bbc0-2e77d469ca64",
"eventSource": "ses.amazonaws.com",
"eventName": "GetConfigurationSet",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "5797ab90-70e0-44a1-83ea-2f962cf09254",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sesv2#1.60.3 m/E",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
}
}
GetConfigurationSetEventDestinations
#Description
GetConfigurationSetEventDestinations recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "bf1188f9-ead2-4526-8949-a7b2ad2da5c5",
"eventSource": "ses.amazonaws.com",
"eventName": "GetConfigurationSetEventDestinations",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "63243c64-beb8-4724-af5f-b5bee9035918",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sesv2#1.60.3 m/E,i",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
}
}
GetDedicatedIps
#Description
GetDedicatedIps recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "8f422a52-f380-498e-8551-1e506feb35dc",
"eventSource": "ses.amazonaws.com",
"eventName": "GetDedicatedIps",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "767ec84f-d18d-4ab4-aa19-3847c98a68a3",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sesv2#1.60.3 m/C,E,i",
"errorCode": "BadRequestException",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
}
}
GetEmailIdentity
#Description
GetEmailIdentity recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "35a2b0ef-6ae6-4f87-b82d-f16eac59b4c1",
"eventSource": "ses.amazonaws.com",
"eventName": "GetEmailIdentity",
"awsRegion": "us-east-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "9bc124c9-56f7-4e3b-92f9-94a764318fe6",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sesv2#1.60.3 m/E,i",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.us-east-2.amazonaws.com"
}
}
GetEmailIdentityPolicies
#Description
GetEmailIdentityPolicies recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "9f6ab7f2-e8fe-49e4-9c08-d163fb025446",
"eventSource": "ses.amazonaws.com",
"eventName": "GetEmailIdentityPolicies",
"awsRegion": "eu-west-3",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "eb69aa84-ac88-418f-93b7-89bf377de675",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.eu-west-3.amazonaws.com"
}
}
GetEmailTemplate
#Description
GetEmailTemplate recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "83288fc6-9ca0-4c25-8dbb-545167ed39a8",
"eventSource": "ses.amazonaws.com",
"eventName": "GetEmailTemplate",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "6a4708fb-eb0d-47da-a6b7-3989051ce121",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
}
}
GetIdentityDkimAttributes
#Description
GetIdentityDkimAttributes recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "94435a7f-db3c-44f5-92bd-6354491b2d0b",
"eventSource": "ses.amazonaws.com",
"eventName": "GetIdentityDkimAttributes",
"awsRegion": "eu-west-3",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "4f5a0995-df4d-42aa-8eb9-5f3bfc94ef68",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/ses#1.35.2 m/g",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.eu-west-3.amazonaws.com"
}
}
GetIdentityMailFromDomainAttributes
#Description
GetIdentityMailFromDomainAttributes recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "8bec9851-0d16-4570-a0b5-4e0953650d17",
"eventSource": "ses.amazonaws.com",
"eventName": "GetIdentityMailFromDomainAttributes",
"awsRegion": "eu-west-3",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "d6a6feef-36fc-462e-876a-bf83b2ec0d0d",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/ses#1.35.2 m/g",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.eu-west-3.amazonaws.com"
}
}
GetIdentityVerificationAttributes
#Description
GetIdentityVerificationAttributes recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "7f9b4319-99e6-4332-b531-f6cb17042ae2",
"eventSource": "ses.amazonaws.com",
"eventName": "GetIdentityVerificationAttributes",
"awsRegion": "eu-west-3",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "a5b8617d-667b-48de-ae53-04c6475002a7",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/ses#1.35.2 m/g",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.eu-west-3.amazonaws.com"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
GetSendQuota
#Description
GetSendQuota recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "4e0c1f91-44f1-43ef-8760-11b4097efaf0",
"eventSource": "ses.amazonaws.com",
"eventName": "GetSendQuota",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "55b1e113-81af-4958-b5c5-f81d808d4acb",
"userAgent": "trustedadvisor.amazonaws.com"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
ListConfigurationSets
#Description
ListConfigurationSets recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "b514052a-7de4-4d53-9738-e3c54c3757dc",
"eventSource": "ses.amazonaws.com",
"eventName": "ListConfigurationSets",
"awsRegion": "us-west-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "22c0a863-9c77-4e92-9d9f-e9fc95d9ad84",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sesv2#1.60.3 m/C,E",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.us-west-2.amazonaws.com"
}
}
ListContactLists
#Description
ListContactLists recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "a24005eb-7afb-4e03-a16d-21710910df61",
"eventSource": "ses.amazonaws.com",
"eventName": "ListContactLists",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "cdfe1fac-f9c6-4940-9827-1dcf77d95b42",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
}
}
ListCustomVerificationEmailTemplates
#Description
ListCustomVerificationEmailTemplates recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "08af0a1a-8c33-44ba-b2b1-b02378dd2422",
"eventSource": "ses.amazonaws.com",
"eventName": "ListCustomVerificationEmailTemplates",
"awsRegion": "ca-central-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "42aced4c-5282-4cc7-b1b4-2f49dd3a2846",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.ca-central-1.amazonaws.com"
}
}
ListDedicatedIpPools
#Description
ListDedicatedIpPools recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "59533c1b-9906-4b0c-a057-1c784a4b6843",
"eventSource": "ses.amazonaws.com",
"eventName": "ListDedicatedIpPools",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "7c60c047-1924-4f52-8bce-0ba81a4e4b71",
"userAgent": "config.amazonaws.com"
}
ListEmailIdentities
#Description
ListEmailIdentities recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "a26a3f33-2cbf-4bff-9698-a1ec363a7a80",
"eventSource": "ses.amazonaws.com",
"eventName": "ListEmailIdentities",
"awsRegion": "us-west-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "d6ba18c7-9384-41ee-ab86-4c8f16de53a4",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sesv2#1.60.3 m/C,E,i",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.us-west-1.amazonaws.com"
}
}
ListEmailTemplates
#Description
ListEmailTemplates recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "fece5409-ffe6-4363-8818-fbfc2f3f9417",
"eventSource": "ses.amazonaws.com",
"eventName": "ListEmailTemplates",
"awsRegion": "ap-southeast-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "d2843cf8-a234-4ddf-9c76-016b0a2847e0",
"userAgent": "config.amazonaws.com"
}
ListExportJobs
#Description
ListExportJobs recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "fce41dbe-17ea-40ae-ae0b-f7a2d4e31193",
"eventSource": "ses.amazonaws.com",
"eventName": "ListExportJobs",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "173e2d54-aa7e-4b3f-bf6e-c1fede26e5d8",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
}
}
ListIdentities
#Description
ListIdentities recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::731544447609:user/cloudsploit is not authorized to perform: ses:ListIdentities",
"eventCategory": "Management",
"eventID": "d43e5d54-2d54-4312-83f1-cce597ec0237",
"eventName": "ListIdentities",
"eventSource": "ses.amazonaws.com",
"eventTime": "2021-04-13T11:35:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "731544447609",
"requestID": "efe55a33-5d29-4e6b-8e90-eaf118538cd1",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "34.12.134.20",
"userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
"accountId": "731544447609",
"arn": "arn:aws:iam::731544447609:user/cloudsploit",
"principalId": "AIDAYTOGP2RLMDEPWZWMJ",
"type": "IAMUser",
"userName": "cloudsploit"
}
}
References #
ListImportJobs
#Description
ListImportJobs recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "25757cb3-ca45-4caa-9072-b0445471bda8",
"eventSource": "ses.amazonaws.com",
"eventName": "ListImportJobs",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "d8b23733-dec9-4e8b-a038-3775a3ebcf9a",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"errorCode": "BadRequestException",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
}
}
ListIngressPoints
#Description
ListIngressPoints recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "e268d834-e340-448f-b045-e73d3a323385",
"eventSource": "ses.amazonaws.com",
"eventName": "ListIngressPoints",
"awsRegion": "us-east-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "83479ce0-3117-4d2f-b6f8-1a8ab1c0d772",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/mailmanager#1.19.5 m/C,E",
"tlsDetails": {
"clientProvidedHostHeader": "example.us-east-2.amazonaws.com"
}
}
ListMultiRegionEndpoints
#Description
ListMultiRegionEndpoints recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "f8b9f098-43f1-4d1a-9404-5d5ba0ed74f0",
"eventSource": "ses.amazonaws.com",
"eventName": "ListMultiRegionEndpoints",
"awsRegion": "ap-northeast-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "1e5fc7e6-9dd7-4ef4-9cde-508355b8e361",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.ap-northeast-1.amazonaws.com"
}
}
ListReceiptFilters
#Description
ListReceiptFilters recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "63a9cb26-573d-4df9-84b5-e1a9ea4bb1ae",
"eventSource": "ses.amazonaws.com",
"eventName": "ListReceiptFilters",
"awsRegion": "ap-southeast-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "4e17413a-86a7-4411-9b8c-6e77c22d5e0d",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/ses#1.30.5 m/E,i",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.ap-southeast-2.amazonaws.com"
}
}
ListReceiptRuleSets
#Description
ListReceiptRuleSets recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "1bf81b05-d193-4e22-8fba-bb0f102eb971",
"eventSource": "ses.amazonaws.com",
"eventName": "ListReceiptRuleSets",
"awsRegion": "us-east-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "99bdb602-dca1-4c11-a57e-745c524ac92b",
"userAgent": "config.amazonaws.com"
}
ListRecommendations
#Description
ListRecommendations recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "fb2da2ce-98f6-43d3-acf9-5c1150346daf",
"eventSource": "ses.amazonaws.com",
"eventName": "ListRecommendations",
"awsRegion": "ap-northeast-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "bfe3bb4a-6cfc-459c-bb63-d597b9e9c540",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.ap-northeast-2.amazonaws.com"
}
}
ListRuleSets
#Description
ListRuleSets recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "1acdbd70-e0cc-4b39-adf1-c8677c7c26f9",
"eventSource": "ses.amazonaws.com",
"eventName": "ListRuleSets",
"awsRegion": "eu-west-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "0270ecbf-f3b1-42e7-a7bc-1afe77144d6d",
"userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/mailmanager#1.19.5 m/C,E",
"tlsDetails": {
"clientProvidedHostHeader": "example.eu-west-2.amazonaws.com"
}
}
ListSuppressedDestinations
#Description
ListSuppressedDestinations recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "d1806f5e-937c-4ec2-8b30-12872af1d119",
"eventSource": "ses.amazonaws.com",
"eventName": "ListSuppressedDestinations",
"awsRegion": "eu-west-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "26c3deb3-7f2f-40c2-b2f3-878abb672198",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
}
}
ListTrafficPolicies
#Description
ListTrafficPolicies recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "d2f14f3d-b450-435b-b071-ece2b47fd252",
"eventSource": "ses.amazonaws.com",
"eventName": "ListTrafficPolicies",
"awsRegion": "eu-west-3",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "56456ee5-1cc5-43aa-bf9b-a1ac32f9c3af",
"userAgent": "config.amazonaws.com"
}
GetAccountSendingEnabled
#Description
Returns the email sending status of the Amazon SES account for the current Region.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
BatchGetMetricData
#Description
Retrieves batches of metric data collected based on your sending activity.
CancelExportJob
#Description
Cancels an export job.
CloneReceiptRuleSet
#Description
Creates a receipt rule set by cloning an existing one.
CreateConfigurationSet
#Description
Create a configuration set.
CreateConfigurationSetEventDestination
#Description
Create an event destination.
CreateConfigurationSetTrackingOptions
#Description
Creates an association between a configuration set and a custom domain for open and click event tracking.
CreateContact
#Description
Creates a contact, which is an end-user who is receiving the email, and adds them to a contact list.
CreateContactList
#Description
Creates a contact list.
CreateCustomVerificationEmailTemplate
#Description
Creates a new custom verification email template.
CreateDedicatedIpPool
#Description
Create a new pool of dedicated IP addresses.
CreateDeliverabilityTestReport
#Description
Create a new predictive inbox placement test.
CreateEmailIdentityPolicy
#Description
Creates the specified sending authorization policy for the given identity (an email address or a domain).
CreateEmailTemplate
#Description
Creates an email template.
CreateExportJob
#Description
Creates an export job for a data source and destination.
CreateImportJob
#Description
Creates an import job for a data destination.
CreateMultiRegionEndpoint
#Description
Creates a multi-region endpoint (global-endpoint).
CreateReceiptFilter
#Description
Creates a new IP address filter.
CreateReceiptRule
#Description
Creates a receipt rule.
CreateReceiptRuleSet
#Description
Creates an empty receipt rule set.
CreateTemplate
#Description
Creates an email template.
CreateTenant
#Description
Create a tenant.
CreateTenantResourceAssociation
#Description
Associate a resource with a tenant.
DeleteConfigurationSet
#Description
Delete an existing configuration set.
DeleteConfigurationSetEventDestination
#Description
Delete an event destination.
DeleteConfigurationSetTrackingOptions
#Description
Deletes an association between a configuration set and a custom domain for open and click event tracking.
DeleteContact
#Description
Removes a contact from a contact list.
DeleteContactList
#Description
Deletes a contact list and all of the contacts on that list.
DeleteCustomVerificationEmailTemplate
#Description
Deletes an existing custom verification email template.
DeleteDedicatedIpPool
#Description
Delete a dedicated IP pool.
DeleteEmailIdentityPolicy
#Description
Deletes the specified sending authorization policy for the given identity (an email address or a domain).
DeleteEmailTemplate
#Description
Deletes an email template.
DeleteIdentityPolicy
#Description
Deletes the specified sending authorization policy for the given identity (an email address or a domain).
DeleteMultiRegionEndpoint
#Description
Deletes a multi-region endpoint (global-endpoint).
DeleteReceiptFilter
#Description
Deletes the specified IP address filter.
DeleteReceiptRule
#Description
Deletes the specified receipt rule.
DeleteReceiptRuleSet
#Description
Deletes the specified receipt rule set and all of the receipt rules it contains.
DeleteTemplate
#Description
Deletes an email template.
DeleteTenant
#Description
Delete an existing tenant.
DeleteTenantResourceAssociation
#Description
Delete an association between a tenant and a resource.
DeleteVerifiedEmailAddress
#Description
Deprecated.
DescribeConfigurationSet
#Description
Returns the details of the specified configuration set.
DescribeReceiptRule
#Description
Returns the details of the specified receipt rule.
GetBlacklistReports
#Description
Retrieve a list of the blacklists that your dedicated IP addresses appear on.
GetContact
#Description
Returns a contact from a contact list.
GetContactList
#Description
Returns contact list metadata.
GetCustomVerificationEmailTemplate
#Description
Returns the custom email verification template for the template name you specify.
GetDedicatedIp
#Description
Get information about a dedicated IP address, including the name of the dedicated IP pool that it's associated with, as well information about the automatic warm-up process for the address.
GetDedicatedIpPool
#Description
Retrieve information about the dedicated pool.
GetDeliverabilityDashboardOptions
#Description
Retrieve information about the status of the Deliverability dashboard for your Amazon Pinpoint account.
GetDeliverabilityTestReport
#Description
Retrieve the results of a predictive inbox placement test.
GetDomainDeliverabilityCampaign
#Description
Retrieve all the deliverability data for a specific campaign.
GetDomainStatisticsReport
#Description
Retrieve inbox placement and engagement rates for the domains that you use to send email.
GetEmailAddressInsights
#Description
Provides validation insights about a specific email address, including syntax validation, DNS record checks, mailbox existence, and other deliverability factors.
GetExportJob
#Description
Provides information about an export job.
GetIdentityNotificationAttributes
#Description
Given a list of verified identities (email addresses and/or domains), returns a structure describing identity notification attributes.
GetIdentityPolicies
#Description
Returns the requested sending authorization policies for the given identity (an email address or a domain).
GetImportJob
#Description
Provides information about an import job.
GetMessageInsights
#Description
Provides information about a specific message, including the from address, the subject, the recipient address, email tags, as well as events associated with the message.
GetMultiRegionEndpoint
#Description
Displays the multi-region endpoint (global-endpoint) configuration.
GetReputationEntity
#Description
Retrieve information about a specific reputation entity, including its reputation management policy, customer-managed status, Amazon Web Services Amazon SES-managed status, and aggregate sending status.
GetSendStatistics
#Description
Provides sending statistics for the current Amazon Web Services Region.
GetSuppressedDestination
#Description
Retrieves information about a specific email address that's on the suppression list for your account or for a specific tenant.
GetTemplate
#Description
Displays the template object (which includes the Subject line, HTML part and text part) for the template you specify.
GetTenant
#Description
Get information about a specific tenant, including the tenant's name, ID, ARN, creation timestamp, tags, sending status, and suppression attributes.
ListContacts
#Description
Lists the contacts present in a specific contact list.
ListDeliverabilityTestReports
#Description
Show a list of the predictive inbox placement tests that you've performed, regardless of their statuses.
ListDomainDeliverabilityCampaigns
#Description
Retrieve deliverability data for all the campaigns that used a specific domain to send email during a specified time range.
ListIdentityPolicies
#Description
Returns a list of sending authorization policies that are attached to the given identity (an email address or a domain).
ListReputationEntities
#Description
List reputation entities in your Amazon SES account in the current Amazon Web Services Region.
ListResourceTenants
#Description
List all tenants associated with a specific resource.
ListTemplates
#Description
Lists the email templates present in your Amazon SES account in the current Amazon Web Services Region.
ListTenantResources
#Description
List all resources associated with a specific tenant.
ListTenants
#Description
List all tenants associated with your account in the current Amazon Web Services Region.
ListVerifiedEmailAddresses
#Description
Deprecated.
PutAccountDedicatedIpWarmupAttributes
#Description
Enable or disable the automatic warm-up feature for dedicated IP addresses.
PutAccountDetails
#Description
Update your Amazon SES account details.
PutAccountSuppressionAttributes
#Description
Change the settings for the account-level suppression list.
PutAccountVdmAttributes
#Description
Update your Amazon SES account VDM attributes.
PutConfigurationSetArchivingOptions
#Description
Associate the configuration set with a MailManager archive.
PutConfigurationSetDeliveryOptions
#Description
Associate a configuration set with a dedicated IP pool.
PutConfigurationSetReputationOptions
#Description
Enable or disable collection of reputation metrics for emails that you send using a particular configuration set in a specific AWS Region.
PutConfigurationSetSuppressionOptions
#Description
Specify the suppression list preferences for a configuration set.
PutConfigurationSetTrackingOptions
#Description
Specify a custom domain to use for open and click tracking elements in email that you send using Amazon Pinpoint.
PutConfigurationSetVdmOptions
#Description
Specify VDM preferences for email that you send using the configuration set.
PutDedicatedIpInPool
#Description
Move a dedicated IP address to an existing dedicated IP pool.
PutDedicatedIpPoolScalingAttributes
#Description
Used to convert a dedicated IP pool to a different scaling mode.
PutDedicatedIpWarmupAttributes
#Description
PutDedicatedIpWarmupAttributes API operation for Amazon Simple Email Service.
PutDeliverabilityDashboardOption
#Description
Enable or disable the Deliverability dashboard for your Amazon Pinpoint account.
PutEmailIdentityConfigurationSetAttributes
#Description
Used to associate a configuration set with an email identity.
PutEmailIdentityDkimAttributes
#Description
Used to enable or disable DKIM authentication for an email identity.
PutEmailIdentityDkimSigningAttributes
#Description
Used to configure or change the DKIM authentication settings for an email domain identity.
PutEmailIdentityFeedbackAttributes
#Description
Used to enable or disable feedback forwarding for an identity.
PutEmailIdentityMailFromAttributes
#Description
Used to enable or disable the custom Mail-From domain configuration for an email identity.
PutIdentityPolicy
#Description
Adds or updates a sending authorization policy for the specified identity (an email address or a domain).
PutSuppressedDestination
#Description
Adds an email address to the suppression list for your account or for a specific tenant.
PutTenantSuppressionAttributes
#Description
Configure the suppression list preferences for a tenant.
ReorderReceiptRuleSet
#Description
Reorders the receipt rules within a receipt rule set.
SendBounce
#Description
Generates and sends a bounce message to the sender of an email you received through Amazon SES.
SendBulkEmail
#Description
Composes an email message to multiple destinations.
SendBulkTemplatedEmail
#Description
Composes an email message to multiple destinations.
SendCustomVerificationEmail
#Description
Adds an email address to the list of identities for your Amazon SES account in the current Amazon Web Services Region and attempts to verify it.
SendEmail
#Description
Sends an email message.
SendRawEmail
#Description
Composes an email message and immediately queues it for sending.
SendTemplatedEmail
#Description
Composes an email message using an email template and immediately queues it for sending.
SetActiveReceiptRuleSet
#Description
Sets the specified receipt rule set as the active receipt rule set.
SetIdentityDkimEnabled
#Description
Enables or disables Easy DKIM signing of email sent from an identity.
SetIdentityFeedbackForwardingEnabled
#Description
Given an identity (an email address or a domain), enables or disables whether Amazon SES forwards bounce and complaint notifications as email.
SetIdentityHeadersInNotificationsEnabled
#Description
Given an identity (an email address or a domain), sets whether Amazon SES includes the original email headers in the Amazon Simple Notification Service (Amazon SNS) notifications of a specified type.
SetIdentityMailFromDomain
#Description
Enables or disables the custom MAIL FROM domain setup for a verified identity (an email address or a domain).
SetIdentityNotificationTopic
#Description
Sets an Amazon Simple Notification Service (Amazon SNS) topic to use when delivering notifications.
SetReceiptRulePosition
#Description
Sets the position of the specified receipt rule in the receipt rule set.
TagResource
#Description
Add one or more tags (keys and values) to a specified resource.
TestRenderEmailTemplate
#Description
Creates a preview of the MIME content of an email when provided with a template and a set of replacement data.
TestRenderTemplate
#Description
Creates a preview of the MIME content of an email when provided with a template and a set of replacement data.
UntagResource
#Description
Remove one or more tags (keys and values) from a specified resource.
UpdateConfigurationSetEventDestination
#Description
Update the configuration of an event destination for a configuration set.
UpdateConfigurationSetReputationMetricsEnabled
#Description
Enables or disables the publishing of reputation metrics for emails sent using a specific configuration set in a given Amazon Web Services Region.
UpdateConfigurationSetTrackingOptions
#Description
Modifies an association between a configuration set and a custom domain for open and click event tracking.
UpdateContact
#Description
Updates a contact's preferences for a list.
UpdateContactList
#Description
Updates contact list metadata.
UpdateCustomVerificationEmailTemplate
#Description
Updates an existing custom verification email template.
UpdateEmailIdentityPolicy
#Description
Updates the specified sending authorization policy for the given identity (an email address or a domain).
UpdateEmailTemplate
#Description
Updates an email template.
UpdateReceiptRule
#Description
Updates a receipt rule.
UpdateReputationEntityCustomerManagedStatus
#Description
Update the customer-managed sending status for a reputation entity.
UpdateReputationEntityPolicy
#Description
Update the reputation management policy for a reputation entity.
UpdateTemplate
#Description
Updates an email template.
VerifyEmailAddress
#Description
Deprecated.
PutAccountPricingAttributes
#Description
Set the pricing plan for your Amazon SES account.