Simple Email Service

eventNameDescriptionSampleRule
anyCatch-all entry for Simple Email Service rules that match the service but not a specific eventName.NN
CreateEmailIdentityCreates a new email identity (domain or email address) and begins the verification process.YY
DeleteEmailIdentityDeletes an email identity (domain or email address) previously created in SES v2.YY
DeleteIdentityDeletes the specified email address or domain identity from the list of verified identities in Amazon SES.YY
PutAccountSendingAttributesEnables or disables the ability to send email from the AWS account globally.NY
PutConfigurationSetSendingOptionsEnables or disables email sending for a specific configuration set.YY
UpdateAccountSendingEnabledEnables or disables email sending for an Amazon SES account.YY
UpdateConfigurationSetSendingEnabledEnables or disables email sending for a configuration set (SES v1 API).YY
VerifyDomainDkimReturns a set of DKIM tokens for a domain identity and begins the DKIM verification process.YY
VerifyDomainIdentityAdds a domain to the list of identities and initiates domain ownership verification.YY
VerifyEmailIdentityAdds an email address to the list of identities and attempts to verify it by sending a verification email.YY
DeleteSuppressedDestinationDeleteSuppressedDestination recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
DescribeActiveReceiptRuleSetDescribeActiveReceiptRuleSet recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.YN
DescribeReceiptRuleSetDescribeReceiptRuleSet recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetAccountGetAccount recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetConfigurationSetGetConfigurationSet recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetConfigurationSetEventDestinationsGetConfigurationSetEventDestinations recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetDedicatedIpsGetDedicatedIps recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetEmailIdentityGetEmailIdentity recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetEmailIdentityPoliciesGetEmailIdentityPolicies recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetEmailTemplateGetEmailTemplate recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetIdentityDkimAttributesGetIdentityDkimAttributes recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetIdentityMailFromDomainAttributesGetIdentityMailFromDomainAttributes recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetIdentityVerificationAttributesGetIdentityVerificationAttributes recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NY
GetSendQuotaGetSendQuota recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NY
ListConfigurationSetsListConfigurationSets recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListContactListsListContactLists recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListCustomVerificationEmailTemplatesListCustomVerificationEmailTemplates recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListDedicatedIpPoolsListDedicatedIpPools recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListEmailIdentitiesListEmailIdentities recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListEmailTemplatesListEmailTemplates recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListExportJobsListExportJobs recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListIdentitiesListIdentities recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.YN
ListImportJobsListImportJobs recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListIngressPointsListIngressPoints recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListMultiRegionEndpointsListMultiRegionEndpoints recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListReceiptFiltersListReceiptFilters recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListReceiptRuleSetsListReceiptRuleSets recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListRecommendationsListRecommendations recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListRuleSetsListRuleSets recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListSuppressedDestinationsListSuppressedDestinations recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListTrafficPoliciesListTrafficPolicies recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetAccountSendingEnabledReturns the email sending status of the Amazon SES account for the current Region.NY
BatchGetMetricDataRetrieves batches of metric data collected based on your sending activity.NN
CancelExportJobCancels an export job.NN
CloneReceiptRuleSetCreates a receipt rule set by cloning an existing one.NN
CreateConfigurationSetCreate a configuration set.NN
CreateConfigurationSetEventDestinationCreate an event destination.NN
CreateConfigurationSetTrackingOptionsCreates an association between a configuration set and a custom domain for open and click event tracking.NN
CreateContactCreates a contact, which is an end-user who is receiving the email, and adds them to a contact list.NN
CreateContactListCreates a contact list.NN
CreateCustomVerificationEmailTemplateCreates a new custom verification email template.NN
CreateDedicatedIpPoolCreate a new pool of dedicated IP addresses.NN
CreateDeliverabilityTestReportCreate a new predictive inbox placement test.NN
CreateEmailIdentityPolicyCreates the specified sending authorization policy for the given identity (an email address or a domain).NN
CreateEmailTemplateCreates an email template.NN
CreateExportJobCreates an export job for a data source and destination.NN
CreateImportJobCreates an import job for a data destination.NN
CreateMultiRegionEndpointCreates a multi-region endpoint (global-endpoint).NN
CreateReceiptFilterCreates a new IP address filter.NN
CreateReceiptRuleCreates a receipt rule.NN
CreateReceiptRuleSetCreates an empty receipt rule set.NN
CreateTemplateCreates an email template.NN
CreateTenantCreate a tenant.NN
CreateTenantResourceAssociationAssociate a resource with a tenant.NN
DeleteConfigurationSetDelete an existing configuration set.NN
DeleteConfigurationSetEventDestinationDelete an event destination.NN
DeleteConfigurationSetTrackingOptionsDeletes an association between a configuration set and a custom domain for open and click event tracking.NN
DeleteContactRemoves a contact from a contact list.NN
DeleteContactListDeletes a contact list and all of the contacts on that list.NN
DeleteCustomVerificationEmailTemplateDeletes an existing custom verification email template.NN
DeleteDedicatedIpPoolDelete a dedicated IP pool.NN
DeleteEmailIdentityPolicyDeletes the specified sending authorization policy for the given identity (an email address or a domain).NN
DeleteEmailTemplateDeletes an email template.NN
DeleteIdentityPolicyDeletes the specified sending authorization policy for the given identity (an email address or a domain).NN
DeleteMultiRegionEndpointDeletes a multi-region endpoint (global-endpoint).NN
DeleteReceiptFilterDeletes the specified IP address filter.NN
DeleteReceiptRuleDeletes the specified receipt rule.NN
DeleteReceiptRuleSetDeletes the specified receipt rule set and all of the receipt rules it contains.NN
DeleteTemplateDeletes an email template.NN
DeleteTenantDelete an existing tenant.NN
DeleteTenantResourceAssociationDelete an association between a tenant and a resource.NN
DeleteVerifiedEmailAddressDeprecated.NN
DescribeConfigurationSetReturns the details of the specified configuration set.NN
DescribeReceiptRuleReturns the details of the specified receipt rule.NN
GetBlacklistReportsRetrieve a list of the blacklists that your dedicated IP addresses appear on.NN
GetContactReturns a contact from a contact list.NN
GetContactListReturns contact list metadata.NN
GetCustomVerificationEmailTemplateReturns the custom email verification template for the template name you specify.NN
GetDedicatedIpGet information about a dedicated IP address, including the name of the dedicated IP pool that it's associated with, as well information about the automatic warm-up process for the address.NN
GetDedicatedIpPoolRetrieve information about the dedicated pool.NN
GetDeliverabilityDashboardOptionsRetrieve information about the status of the Deliverability dashboard for your Amazon Pinpoint account.NN
GetDeliverabilityTestReportRetrieve the results of a predictive inbox placement test.NN
GetDomainDeliverabilityCampaignRetrieve all the deliverability data for a specific campaign.NN
GetDomainStatisticsReportRetrieve inbox placement and engagement rates for the domains that you use to send email.NN
GetEmailAddressInsightsProvides validation insights about a specific email address, including syntax validation, DNS record checks, mailbox existence, and other deliverability factors.NN
GetExportJobProvides information about an export job.NN
GetIdentityNotificationAttributesGiven a list of verified identities (email addresses and/or domains), returns a structure describing identity notification attributes.NN
GetIdentityPoliciesReturns the requested sending authorization policies for the given identity (an email address or a domain).NN
GetImportJobProvides information about an import job.NN
GetMessageInsightsProvides information about a specific message, including the from address, the subject, the recipient address, email tags, as well as events associated with the message.NN
GetMultiRegionEndpointDisplays the multi-region endpoint (global-endpoint) configuration.NN
GetReputationEntityRetrieve information about a specific reputation entity, including its reputation management policy, customer-managed status, Amazon Web Services Amazon SES-managed status, and aggregate sending status.NN
GetSendStatisticsProvides sending statistics for the current Amazon Web Services Region.NN
GetSuppressedDestinationRetrieves information about a specific email address that's on the suppression list for your account or for a specific tenant.NN
GetTemplateDisplays the template object (which includes the Subject line, HTML part and text part) for the template you specify.NN
GetTenantGet information about a specific tenant, including the tenant's name, ID, ARN, creation timestamp, tags, sending status, and suppression attributes.NN
ListContactsLists the contacts present in a specific contact list.NN
ListDeliverabilityTestReportsShow a list of the predictive inbox placement tests that you've performed, regardless of their statuses.NN
ListDomainDeliverabilityCampaignsRetrieve deliverability data for all the campaigns that used a specific domain to send email during a specified time range.NN
ListIdentityPoliciesReturns a list of sending authorization policies that are attached to the given identity (an email address or a domain).NN
ListReputationEntitiesList reputation entities in your Amazon SES account in the current Amazon Web Services Region.NN
ListResourceTenantsList all tenants associated with a specific resource.NN
ListTagsForResourceRetrieve a list of the tags (keys and values) that are associated with a specified resource.NN
ListTemplatesLists the email templates present in your Amazon SES account in the current Amazon Web Services Region.NN
ListTenantResourcesList all resources associated with a specific tenant.NN
ListTenantsList all tenants associated with your account in the current Amazon Web Services Region.NN
ListVerifiedEmailAddressesDeprecated.NN
PutAccountDedicatedIpWarmupAttributesEnable or disable the automatic warm-up feature for dedicated IP addresses.NN
PutAccountDetailsUpdate your Amazon SES account details.NN
PutAccountSuppressionAttributesChange the settings for the account-level suppression list.NN
PutAccountVdmAttributesUpdate your Amazon SES account VDM attributes.NN
PutConfigurationSetArchivingOptionsAssociate the configuration set with a MailManager archive.NN
PutConfigurationSetDeliveryOptionsAssociate a configuration set with a dedicated IP pool.NN
PutConfigurationSetReputationOptionsEnable or disable collection of reputation metrics for emails that you send using a particular configuration set in a specific AWS Region.NN
PutConfigurationSetSuppressionOptionsSpecify the suppression list preferences for a configuration set.NN
PutConfigurationSetTrackingOptionsSpecify a custom domain to use for open and click tracking elements in email that you send using Amazon Pinpoint.NN
PutConfigurationSetVdmOptionsSpecify VDM preferences for email that you send using the configuration set.NN
PutDedicatedIpInPoolMove a dedicated IP address to an existing dedicated IP pool.NN
PutDedicatedIpPoolScalingAttributesUsed to convert a dedicated IP pool to a different scaling mode.NN
PutDedicatedIpWarmupAttributesPutDedicatedIpWarmupAttributes API operation for Amazon Simple Email Service.NN
PutDeliverabilityDashboardOptionEnable or disable the Deliverability dashboard for your Amazon Pinpoint account.NN
PutEmailIdentityConfigurationSetAttributesUsed to associate a configuration set with an email identity.NN
PutEmailIdentityDkimAttributesUsed to enable or disable DKIM authentication for an email identity.NN
PutEmailIdentityDkimSigningAttributesUsed to configure or change the DKIM authentication settings for an email domain identity.NN
PutEmailIdentityFeedbackAttributesUsed to enable or disable feedback forwarding for an identity.NN
PutEmailIdentityMailFromAttributesUsed to enable or disable the custom Mail-From domain configuration for an email identity.NN
PutIdentityPolicyAdds or updates a sending authorization policy for the specified identity (an email address or a domain).NN
PutSuppressedDestinationAdds an email address to the suppression list for your account or for a specific tenant.NN
PutTenantSuppressionAttributesConfigure the suppression list preferences for a tenant.NN
ReorderReceiptRuleSetReorders the receipt rules within a receipt rule set.NN
SendBounceGenerates and sends a bounce message to the sender of an email you received through Amazon SES.NN
SendBulkEmailComposes an email message to multiple destinations.NN
SendBulkTemplatedEmailComposes an email message to multiple destinations.NN
SendCustomVerificationEmailAdds an email address to the list of identities for your Amazon SES account in the current Amazon Web Services Region and attempts to verify it.NN
SendEmailSends an email message.NN
SendRawEmailComposes an email message and immediately queues it for sending.NN
SendTemplatedEmailComposes an email message using an email template and immediately queues it for sending.NN
SetActiveReceiptRuleSetSets the specified receipt rule set as the active receipt rule set.NN
SetIdentityDkimEnabledEnables or disables Easy DKIM signing of email sent from an identity.NN
SetIdentityFeedbackForwardingEnabledGiven an identity (an email address or a domain), enables or disables whether Amazon SES forwards bounce and complaint notifications as email.NN
SetIdentityHeadersInNotificationsEnabledGiven an identity (an email address or a domain), sets whether Amazon SES includes the original email headers in the Amazon Simple Notification Service (Amazon SNS) notifications of a specified type.NN
SetIdentityMailFromDomainEnables or disables the custom MAIL FROM domain setup for a verified identity (an email address or a domain).NN
SetIdentityNotificationTopicSets an Amazon Simple Notification Service (Amazon SNS) topic to use when delivering notifications.NN
SetReceiptRulePositionSets the position of the specified receipt rule in the receipt rule set.NN
TagResourceAdd one or more tags (keys and values) to a specified resource.NN
TestRenderEmailTemplateCreates a preview of the MIME content of an email when provided with a template and a set of replacement data.NN
TestRenderTemplateCreates a preview of the MIME content of an email when provided with a template and a set of replacement data.NN
UntagResourceRemove one or more tags (keys and values) from a specified resource.NN
UpdateConfigurationSetEventDestinationUpdate the configuration of an event destination for a configuration set.NN
UpdateConfigurationSetReputationMetricsEnabledEnables or disables the publishing of reputation metrics for emails sent using a specific configuration set in a given Amazon Web Services Region.NN
UpdateConfigurationSetTrackingOptionsModifies an association between a configuration set and a custom domain for open and click event tracking.NN
UpdateContactUpdates a contact's preferences for a list.NN
UpdateContactListUpdates contact list metadata.NN
UpdateCustomVerificationEmailTemplateUpdates an existing custom verification email template.NN
UpdateEmailIdentityPolicyUpdates the specified sending authorization policy for the given identity (an email address or a domain).NN
UpdateEmailTemplateUpdates an email template.NN
UpdateReceiptRuleUpdates a receipt rule.NN
UpdateReputationEntityCustomerManagedStatusUpdate the customer-managed sending status for a reputation entity.NN
UpdateReputationEntityPolicyUpdate the reputation management policy for a reputation entity.NN
UpdateTemplateUpdates an email template.NN
VerifyEmailAddressDeprecated.NN
PutAccountPricingAttributesSet the pricing plan for your Amazon SES account.NN

any: Simple Email Service (catch-all)

#
Service
ses

Description

Catch-all entry for Simple Email Service rules that match the service but not a specific eventName.

CreateEmailIdentity

#
Service
ses

Description

Creates a new email identity (domain or email address) and begins the verification process.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "5ea8bf6c-d18f-4e8b-987c-c7e1e0f785bc",
  "eventName": "CreateEmailIdentity",
  "eventSource": "ses.amazonaws.com",
  "eventTime": "2026-06-29T19:25:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c01cbc4c-b20b-4ff2-85d5-283952327ba0",
  "requestParameters": {
    "emailIdentity": "dwfix2@example.com"
  },
  "responseElements": {
    "identityType": "EMAIL_ADDRESS",
    "verifiedForSendingStatus": false
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "email.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

DeleteEmailIdentity

#
Service
ses

Description

Deletes an email identity (domain or email address) previously created in SES v2.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "2d766db2-585c-4594-b465-0073a38e47de",
  "eventName": "DeleteEmailIdentity",
  "eventSource": "ses.amazonaws.com",
  "eventTime": "2026-06-29T19:25:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f98cb016-4b4d-494a-80ad-d0a9af89ac1d",
  "requestParameters": {
    "emailIdentity": "dwfix2@example.com"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "email.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

DeleteIdentity

#
Service
ses

Description

Deletes the specified email address or domain identity from the list of verified identities in Amazon SES.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "56133045-444a-423f-a63f-1b25a0a5a8f0",
  "eventName": "DeleteIdentity",
  "eventSource": "ses.amazonaws.com",
  "eventTime": "2026-06-29T19:25:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d0f38f11-9503-4b28-a3ff-5c053b5cdd0d",
  "requestParameters": {
    "identity": "dwfix@example.com"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "email.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

  • SES Identity Has Been Deleted source medium: Detects an instance of an SES identity being deleted via the "DeleteIdentity" event. This may be an indicator of an adversary removing the account that carried out suspicious or malicious activitiesT1070

PutAccountSendingAttributes

#
Service
ses

Description

Enables or disables the ability to send email from the AWS account globally.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

PutConfigurationSetSendingOptions

#
Service
ses

Description

Enables or disables email sending for a specific configuration set.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "749d7d0e-7ad5-414f-a22d-913ffef9bd93",
  "eventName": "PutConfigurationSetSendingOptions",
  "eventSource": "ses.amazonaws.com",
  "eventTime": "2026-06-29T19:25:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "71d6fb61-d709-4b10-8a8e-218301f47952",
  "requestParameters": {
    "configurationSetName": "dwfix-cs",
    "sendingEnabled": true
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "email.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

UpdateAccountSendingEnabled

#
Service
ses

Description

Enables or disables email sending for an Amazon SES account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::123456789012:user/TrailDiscover is not authorized to perform: ses:UpdateAccountSendingEnabled because no identity-based policy allows the ses:UpdateAccountSendingEnabled action",
  "eventCategory": "Management",
  "eventID": "d234aba0-2ad3-4956-89ac-9c0e31e34cf7",
  "eventName": "UpdateAccountSendingEnabled",
  "eventSource": "ses.amazonaws.com",
  "eventTime": "2024-08-18T16:21:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6d503bfc-74ce-495e-bce8-54ab5c19d2f7",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "0.0.0.0",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "email.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_8e0a4769-3fe9-43b1-9892-845f4bfc1864 cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#ses.update-account-sending-enabled",
  "userIdentity": {
    "accessKeyId": "AKIA****************",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/TrailDiscover",
    "principalId": "AROA****************:User",
    "type": "IAMUser",
    "userName": "TrailDiscover"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

References #

UpdateConfigurationSetSendingEnabled

#
Service
ses

Description

Enables or disables email sending for a configuration set (SES v1 API).

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "ThrottlingException",
  "errorMessage": "Update conflict when updating configuration set <dw-probe>.",
  "eventCategory": "Management",
  "eventID": "2cfbd256-ff4b-441e-9342-47874ae0881f",
  "eventName": "UpdateConfigurationSetSendingEnabled",
  "eventSource": "ses.amazonaws.com",
  "eventTime": "2026-06-29T19:26:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "aa5687e2-1f84-413a-9051-78a8ccebdee7",
  "requestParameters": {
    "configurationSetName": "dw-probe",
    "enabled": false
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "email.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

VerifyDomainDkim

#
Service
ses

Description

Returns a set of DKIM tokens for a domain identity and begins the DKIM verification process.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "453e5986-beee-4cad-a83f-0baabf774d6f",
  "eventName": "VerifyDomainDkim",
  "eventSource": "ses.amazonaws.com",
  "eventTime": "2026-06-29T19:25:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "751e0e7b-5bb6-49fc-9a70-8c898303e6ba",
  "requestParameters": {
    "domain": "dwfix.example.com"
  },
  "responseElements": {
    "dkimTokens": [
      "fdv636i5jpjsoshs7g7jothf22heh4jx",
      "qyxoh4wzvv3flwhhsh4rs63t2x2zixyk",
      "4bn3r4lmr3f2ukidlfvt45roljxgno7b"
    ]
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "email.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

VerifyDomainIdentity

#
Service
ses

Description

Adds a domain to the list of identities and initiates domain ownership verification.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "2c7ff554-7e58-4da6-b09f-5de82686de7a",
  "eventName": "VerifyDomainIdentity",
  "eventSource": "ses.amazonaws.com",
  "eventTime": "2026-06-29T19:25:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7c36f914-a46d-4df6-a90e-b8f430470fcb",
  "requestParameters": {
    "disableEmailNotifications": false,
    "domain": "dwfix.example.com"
  },
  "responseElements": {
    "verificationToken": "Hw1ecktdYs9Q15bCML+ASEnSzgGjS9xSkHQY8t+EkuQ="
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "email.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

VerifyEmailIdentity

#
Service
ses

Description

Adds an email address to the list of identities and attempts to verify it by sending a verification email.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "d9d9b64d-6010-47ad-859c-7ab7c2d28dea",
  "eventName": "VerifyEmailIdentity",
  "eventSource": "ses.amazonaws.com",
  "eventTime": "2026-06-29T19:25:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b98b4f56-f909-49e2-973f-8fa4b82eab43",
  "requestParameters": {
    "emailAddress": "dwfix@example.com"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "email.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,n,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

DeleteSuppressedDestination

#
Service
ses

Description

DeleteSuppressedDestination recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "1750d0f7-811e-4db7-8025-ed82a70f22de",
  "eventSource": "ses.amazonaws.com",
  "eventName": "DeleteSuppressedDestination",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "f616d718-6fd8-4129-b0d6-a770ca36bb28",
  "userAgent": "Boto3/1.43.54 md/Botocore#1.43.54 ua/2.1 os/linux#6.8.0-1061-aws md/arch#aarch64 lang/python#3.11.15 md/pyimpl#CPython m/0,b,Z,D cfg/retry-mode#legacy Botocore/1.43.54",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.ap-southeast-2.amazonaws.com"
  }
}

DescribeActiveReceiptRuleSet

#
Service
ses

Description

DescribeActiveReceiptRuleSet recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

{
  "additionalEventData": {
    "SignatureVersion": "4"
  },
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "636dd6b4-98a4-4774-96b8-84445fc4da63",
  "eventName": "DescribeActiveReceiptRuleSet",
  "eventSource": "ses.amazonaws.com",
  "eventTime": "2021-04-13T11:35:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "111111111111",
  "requestID": "dce43587-af21-4cf5-b916-6b3b43e4106f",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "95.90.195.80",
  "userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
    "accountId": "111111111111",
    "arn": "arn:aws:iam::111111111111:user/cloudsploit",
    "principalId": "AIDAYTOGP2RLMDEPWZWMJ",
    "type": "IAMUser",
    "userName": "cloudsploit"
  }
}

References #

DescribeReceiptRuleSet

#
Service
ses

Description

DescribeReceiptRuleSet recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "51c4bfdb-5f8c-406c-bfb4-8fca0bc81f35",
  "eventSource": "ses.amazonaws.com",
  "eventName": "DescribeReceiptRuleSet",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "982284e7-1d16-4cba-9a65-ee915fd15a06",
  "userAgent": "config.amazonaws.com"
}

GetAccount

#
Service
ses

Description

GetAccount recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d858db9f-c03a-4135-b9a4-b5d4b7b481c7",
  "eventSource": "ses.amazonaws.com",
  "eventName": "GetAccount",
  "awsRegion": "ap-northeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "cd3d3ade-d119-4d0d-93dd-1070456d71f6",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sesv2#1.60.3 m/E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.ap-northeast-2.amazonaws.com"
  }
}

GetConfigurationSet

#
Service
ses

Description

GetConfigurationSet recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "8e3fa9c9-a699-4b86-bbc0-2e77d469ca64",
  "eventSource": "ses.amazonaws.com",
  "eventName": "GetConfigurationSet",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "5797ab90-70e0-44a1-83ea-2f962cf09254",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sesv2#1.60.3 m/E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetConfigurationSetEventDestinations

#
Service
ses

Description

GetConfigurationSetEventDestinations recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "bf1188f9-ead2-4526-8949-a7b2ad2da5c5",
  "eventSource": "ses.amazonaws.com",
  "eventName": "GetConfigurationSetEventDestinations",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "63243c64-beb8-4724-af5f-b5bee9035918",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sesv2#1.60.3 m/E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetDedicatedIps

#
Service
ses

Description

GetDedicatedIps recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "8f422a52-f380-498e-8551-1e506feb35dc",
  "eventSource": "ses.amazonaws.com",
  "eventName": "GetDedicatedIps",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "767ec84f-d18d-4ab4-aa19-3847c98a68a3",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sesv2#1.60.3 m/C,E,i",
  "errorCode": "BadRequestException",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetEmailIdentity

#
Service
ses

Description

GetEmailIdentity recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "35a2b0ef-6ae6-4f87-b82d-f16eac59b4c1",
  "eventSource": "ses.amazonaws.com",
  "eventName": "GetEmailIdentity",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "9bc124c9-56f7-4e3b-92f9-94a764318fe6",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sesv2#1.60.3 m/E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-2.amazonaws.com"
  }
}

GetEmailIdentityPolicies

#
Service
ses

Description

GetEmailIdentityPolicies recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "9f6ab7f2-e8fe-49e4-9c08-d163fb025446",
  "eventSource": "ses.amazonaws.com",
  "eventName": "GetEmailIdentityPolicies",
  "awsRegion": "eu-west-3",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "eb69aa84-ac88-418f-93b7-89bf377de675",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-3.amazonaws.com"
  }
}

GetEmailTemplate

#
Service
ses

Description

GetEmailTemplate recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "83288fc6-9ca0-4c25-8dbb-545167ed39a8",
  "eventSource": "ses.amazonaws.com",
  "eventName": "GetEmailTemplate",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "6a4708fb-eb0d-47da-a6b7-3989051ce121",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  }
}

GetIdentityDkimAttributes

#
Service
ses

Description

GetIdentityDkimAttributes recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "94435a7f-db3c-44f5-92bd-6354491b2d0b",
  "eventSource": "ses.amazonaws.com",
  "eventName": "GetIdentityDkimAttributes",
  "awsRegion": "eu-west-3",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "4f5a0995-df4d-42aa-8eb9-5f3bfc94ef68",
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/ses#1.35.2 m/g",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-3.amazonaws.com"
  }
}

GetIdentityMailFromDomainAttributes

#
Service
ses

Description

GetIdentityMailFromDomainAttributes recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "8bec9851-0d16-4570-a0b5-4e0953650d17",
  "eventSource": "ses.amazonaws.com",
  "eventName": "GetIdentityMailFromDomainAttributes",
  "awsRegion": "eu-west-3",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "d6a6feef-36fc-462e-876a-bf83b2ec0d0d",
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/ses#1.35.2 m/g",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-3.amazonaws.com"
  }
}

GetIdentityVerificationAttributes

#
Service
ses

Description

GetIdentityVerificationAttributes recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "7f9b4319-99e6-4332-b531-f6cb17042ae2",
  "eventSource": "ses.amazonaws.com",
  "eventName": "GetIdentityVerificationAttributes",
  "awsRegion": "eu-west-3",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "a5b8617d-667b-48de-ae53-04c6475002a7",
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.15.5 (+https://www.terraform.io) terraform-provider-aws/6.50.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 api/ses#1.35.2 m/g",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-3.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

GetSendQuota

#
Service
ses

Description

GetSendQuota recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "4e0c1f91-44f1-43ef-8760-11b4097efaf0",
  "eventSource": "ses.amazonaws.com",
  "eventName": "GetSendQuota",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "55b1e113-81af-4958-b5c5-f81d808d4acb",
  "userAgent": "trustedadvisor.amazonaws.com"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ListConfigurationSets

#
Service
ses

Description

ListConfigurationSets recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "b514052a-7de4-4d53-9738-e3c54c3757dc",
  "eventSource": "ses.amazonaws.com",
  "eventName": "ListConfigurationSets",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "22c0a863-9c77-4e92-9d9f-e9fc95d9ad84",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sesv2#1.60.3 m/C,E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-west-2.amazonaws.com"
  }
}

ListContactLists

#
Service
ses

Description

ListContactLists recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "a24005eb-7afb-4e03-a16d-21710910df61",
  "eventSource": "ses.amazonaws.com",
  "eventName": "ListContactLists",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "cdfe1fac-f9c6-4940-9827-1dcf77d95b42",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
  }
}

ListCustomVerificationEmailTemplates

#
Service
ses

Description

ListCustomVerificationEmailTemplates recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "08af0a1a-8c33-44ba-b2b1-b02378dd2422",
  "eventSource": "ses.amazonaws.com",
  "eventName": "ListCustomVerificationEmailTemplates",
  "awsRegion": "ca-central-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "42aced4c-5282-4cc7-b1b4-2f49dd3a2846",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.ca-central-1.amazonaws.com"
  }
}

ListDedicatedIpPools

#
Service
ses

Description

ListDedicatedIpPools recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "59533c1b-9906-4b0c-a057-1c784a4b6843",
  "eventSource": "ses.amazonaws.com",
  "eventName": "ListDedicatedIpPools",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "7c60c047-1924-4f52-8bce-0ba81a4e4b71",
  "userAgent": "config.amazonaws.com"
}

ListEmailIdentities

#
Service
ses

Description

ListEmailIdentities recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "a26a3f33-2cbf-4bff-9698-a1ec363a7a80",
  "eventSource": "ses.amazonaws.com",
  "eventName": "ListEmailIdentities",
  "awsRegion": "us-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "d6ba18c7-9384-41ee-ab86-4c8f16de53a4",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/sesv2#1.60.3 m/C,E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-west-1.amazonaws.com"
  }
}

ListEmailTemplates

#
Service
ses

Description

ListEmailTemplates recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "fece5409-ffe6-4363-8818-fbfc2f3f9417",
  "eventSource": "ses.amazonaws.com",
  "eventName": "ListEmailTemplates",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "d2843cf8-a234-4ddf-9c76-016b0a2847e0",
  "userAgent": "config.amazonaws.com"
}

ListExportJobs

#
Service
ses

Description

ListExportJobs recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "fce41dbe-17ea-40ae-ae0b-f7a2d4e31193",
  "eventSource": "ses.amazonaws.com",
  "eventName": "ListExportJobs",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "173e2d54-aa7e-4b3f-bf6e-c1fede26e5d8",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
  }
}

ListIdentities

#
Service
ses

Description

ListIdentities recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::731544447609:user/cloudsploit is not authorized to perform: ses:ListIdentities",
  "eventCategory": "Management",
  "eventID": "d43e5d54-2d54-4312-83f1-cce597ec0237",
  "eventName": "ListIdentities",
  "eventSource": "ses.amazonaws.com",
  "eventTime": "2021-04-13T11:35:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "731544447609",
  "requestID": "efe55a33-5d29-4e6b-8e90-eaf118538cd1",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "34.12.134.20",
  "userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
    "accountId": "731544447609",
    "arn": "arn:aws:iam::731544447609:user/cloudsploit",
    "principalId": "AIDAYTOGP2RLMDEPWZWMJ",
    "type": "IAMUser",
    "userName": "cloudsploit"
  }
}

References #

ListImportJobs

#
Service
ses

Description

ListImportJobs recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "25757cb3-ca45-4caa-9072-b0445471bda8",
  "eventSource": "ses.amazonaws.com",
  "eventName": "ListImportJobs",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "d8b23733-dec9-4e8b-a038-3775a3ebcf9a",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "errorCode": "BadRequestException",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
  }
}

ListIngressPoints

#
Service
ses

Description

ListIngressPoints recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "e268d834-e340-448f-b045-e73d3a323385",
  "eventSource": "ses.amazonaws.com",
  "eventName": "ListIngressPoints",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "83479ce0-3117-4d2f-b6f8-1a8ab1c0d772",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/mailmanager#1.19.5 m/C,E",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.us-east-2.amazonaws.com"
  }
}

ListMultiRegionEndpoints

#
Service
ses

Description

ListMultiRegionEndpoints recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f8b9f098-43f1-4d1a-9404-5d5ba0ed74f0",
  "eventSource": "ses.amazonaws.com",
  "eventName": "ListMultiRegionEndpoints",
  "awsRegion": "ap-northeast-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "1e5fc7e6-9dd7-4ef4-9cde-508355b8e361",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.ap-northeast-1.amazonaws.com"
  }
}

ListReceiptFilters

#
Service
ses

Description

ListReceiptFilters recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "63a9cb26-573d-4df9-84b5-e1a9ea4bb1ae",
  "eventSource": "ses.amazonaws.com",
  "eventName": "ListReceiptFilters",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "4e17413a-86a7-4411-9b8c-6e77c22d5e0d",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/ses#1.30.5 m/E,i",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.ap-southeast-2.amazonaws.com"
  }
}

ListReceiptRuleSets

#
Service
ses

Description

ListReceiptRuleSets recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "1bf81b05-d193-4e22-8fba-bb0f102eb971",
  "eventSource": "ses.amazonaws.com",
  "eventName": "ListReceiptRuleSets",
  "awsRegion": "us-east-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "99bdb602-dca1-4c11-a57e-745c524ac92b",
  "userAgent": "config.amazonaws.com"
}

ListRecommendations

#
Service
ses

Description

ListRecommendations recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "fb2da2ce-98f6-43d3-acf9-5c1150346daf",
  "eventSource": "ses.amazonaws.com",
  "eventName": "ListRecommendations",
  "awsRegion": "ap-northeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "bfe3bb4a-6cfc-459c-bb63-d597b9e9c540",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.ap-northeast-2.amazonaws.com"
  }
}

ListRuleSets

#
Service
ses

Description

ListRuleSets recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "1acdbd70-e0cc-4b39-adf1-c8677c7c26f9",
  "eventSource": "ses.amazonaws.com",
  "eventName": "ListRuleSets",
  "awsRegion": "eu-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "0270ecbf-f3b1-42e7-a7bc-1afe77144d6d",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/mailmanager#1.19.5 m/C,E",
  "tlsDetails": {
    "clientProvidedHostHeader": "example.eu-west-2.amazonaws.com"
  }
}

ListSuppressedDestinations

#
Service
ses

Description

ListSuppressedDestinations recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d1806f5e-937c-4ec2-8b30-12872af1d119",
  "eventSource": "ses.amazonaws.com",
  "eventName": "ListSuppressedDestinations",
  "awsRegion": "eu-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "26c3deb3-7f2f-40c2-b2f3-878abb672198",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.eu-west-1.amazonaws.com"
  }
}

ListTrafficPolicies

#
Service
ses

Description

ListTrafficPolicies recorded by CloudTrail for Amazon Simple Email Service. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d2f14f3d-b450-435b-b071-ece2b47fd252",
  "eventSource": "ses.amazonaws.com",
  "eventName": "ListTrafficPolicies",
  "awsRegion": "eu-west-3",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "56456ee5-1cc5-43aa-bf9b-a1ac32f9c3af",
  "userAgent": "config.amazonaws.com"
}

GetAccountSendingEnabled

#
Service
ses

Description

Returns the email sending status of the Amazon SES account for the current Region.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

BatchGetMetricData

#
Service
ses

Description

Retrieves batches of metric data collected based on your sending activity.

CancelExportJob

#
Service
ses

Description

Cancels an export job.

CloneReceiptRuleSet

#
Service
ses

Description

Creates a receipt rule set by cloning an existing one.

CreateConfigurationSet

#
Service
ses

Description

Create a configuration set.

CreateConfigurationSetEventDestination

#
Service
ses

Description

Create an event destination.

CreateConfigurationSetTrackingOptions

#
Service
ses

Description

Creates an association between a configuration set and a custom domain for open and click event tracking.

CreateContact

#
Service
ses

Description

Creates a contact, which is an end-user who is receiving the email, and adds them to a contact list.

CreateContactList

#
Service
ses

Description

Creates a contact list.

CreateCustomVerificationEmailTemplate

#
Service
ses

Description

Creates a new custom verification email template.

CreateDedicatedIpPool

#
Service
ses

Description

Create a new pool of dedicated IP addresses.

CreateDeliverabilityTestReport

#
Service
ses

Description

Create a new predictive inbox placement test.

CreateEmailIdentityPolicy

#
Service
ses

Description

Creates the specified sending authorization policy for the given identity (an email address or a domain).

CreateEmailTemplate

#
Service
ses

Description

Creates an email template.

CreateExportJob

#
Service
ses

Description

Creates an export job for a data source and destination.

CreateImportJob

#
Service
ses

Description

Creates an import job for a data destination.

CreateMultiRegionEndpoint

#
Service
ses

Description

Creates a multi-region endpoint (global-endpoint).

CreateReceiptFilter

#
Service
ses

Description

Creates a new IP address filter.

CreateReceiptRule

#
Service
ses

Description

Creates a receipt rule.

CreateReceiptRuleSet

#
Service
ses

Description

Creates an empty receipt rule set.

CreateTemplate

#
Service
ses

Description

Creates an email template.

CreateTenant

#
Service
ses

Description

Create a tenant.

CreateTenantResourceAssociation

#
Service
ses

Description

Associate a resource with a tenant.

DeleteConfigurationSet

#
Service
ses

Description

Delete an existing configuration set.

DeleteConfigurationSetEventDestination

#
Service
ses

Description

Delete an event destination.

DeleteConfigurationSetTrackingOptions

#
Service
ses

Description

Deletes an association between a configuration set and a custom domain for open and click event tracking.

DeleteContact

#
Service
ses

Description

Removes a contact from a contact list.

DeleteContactList

#
Service
ses

Description

Deletes a contact list and all of the contacts on that list.

DeleteCustomVerificationEmailTemplate

#
Service
ses

Description

Deletes an existing custom verification email template.

DeleteDedicatedIpPool

#
Service
ses

Description

Delete a dedicated IP pool.

DeleteEmailIdentityPolicy

#
Service
ses

Description

Deletes the specified sending authorization policy for the given identity (an email address or a domain).

DeleteEmailTemplate

#
Service
ses

Description

Deletes an email template.

DeleteIdentityPolicy

#
Service
ses

Description

Deletes the specified sending authorization policy for the given identity (an email address or a domain).

DeleteMultiRegionEndpoint

#
Service
ses

Description

Deletes a multi-region endpoint (global-endpoint).

DeleteReceiptFilter

#
Service
ses

Description

Deletes the specified IP address filter.

DeleteReceiptRule

#
Service
ses

Description

Deletes the specified receipt rule.

DeleteReceiptRuleSet

#
Service
ses

Description

Deletes the specified receipt rule set and all of the receipt rules it contains.

DeleteTemplate

#
Service
ses

Description

Deletes an email template.

DeleteTenant

#
Service
ses

Description

Delete an existing tenant.

DeleteTenantResourceAssociation

#
Service
ses

Description

Delete an association between a tenant and a resource.

DeleteVerifiedEmailAddress

#
Service
ses

Description

Deprecated.

DescribeConfigurationSet

#
Service
ses

Description

Returns the details of the specified configuration set.

DescribeReceiptRule

#
Service
ses

Description

Returns the details of the specified receipt rule.

GetBlacklistReports

#
Service
ses

Description

Retrieve a list of the blacklists that your dedicated IP addresses appear on.

GetContact

#
Service
ses

Description

Returns a contact from a contact list.

GetContactList

#
Service
ses

Description

Returns contact list metadata.

GetCustomVerificationEmailTemplate

#
Service
ses

Description

Returns the custom email verification template for the template name you specify.

GetDedicatedIp

#
Service
ses

Description

Get information about a dedicated IP address, including the name of the dedicated IP pool that it's associated with, as well information about the automatic warm-up process for the address.

GetDedicatedIpPool

#
Service
ses

Description

Retrieve information about the dedicated pool.

GetDeliverabilityDashboardOptions

#
Service
ses

Description

Retrieve information about the status of the Deliverability dashboard for your Amazon Pinpoint account.

GetDeliverabilityTestReport

#
Service
ses

Description

Retrieve the results of a predictive inbox placement test.

GetDomainDeliverabilityCampaign

#
Service
ses

Description

Retrieve all the deliverability data for a specific campaign.

GetDomainStatisticsReport

#
Service
ses

Description

Retrieve inbox placement and engagement rates for the domains that you use to send email.

GetEmailAddressInsights

#
Service
ses

Description

Provides validation insights about a specific email address, including syntax validation, DNS record checks, mailbox existence, and other deliverability factors.

GetExportJob

#
Service
ses

Description

Provides information about an export job.

GetIdentityNotificationAttributes

#
Service
ses

Description

Given a list of verified identities (email addresses and/or domains), returns a structure describing identity notification attributes.

GetIdentityPolicies

#
Service
ses

Description

Returns the requested sending authorization policies for the given identity (an email address or a domain).

GetImportJob

#
Service
ses

Description

Provides information about an import job.

GetMessageInsights

#
Service
ses

Description

Provides information about a specific message, including the from address, the subject, the recipient address, email tags, as well as events associated with the message.

GetMultiRegionEndpoint

#
Service
ses

Description

Displays the multi-region endpoint (global-endpoint) configuration.

GetReputationEntity

#
Service
ses

Description

Retrieve information about a specific reputation entity, including its reputation management policy, customer-managed status, Amazon Web Services Amazon SES-managed status, and aggregate sending status.

GetSendStatistics

#
Service
ses

Description

Provides sending statistics for the current Amazon Web Services Region.

GetSuppressedDestination

#
Service
ses

Description

Retrieves information about a specific email address that's on the suppression list for your account or for a specific tenant.

GetTemplate

#
Service
ses

Description

Displays the template object (which includes the Subject line, HTML part and text part) for the template you specify.

GetTenant

#
Service
ses

Description

Get information about a specific tenant, including the tenant's name, ID, ARN, creation timestamp, tags, sending status, and suppression attributes.

ListContacts

#
Service
ses

Description

Lists the contacts present in a specific contact list.

ListDeliverabilityTestReports

#
Service
ses

Description

Show a list of the predictive inbox placement tests that you've performed, regardless of their statuses.

ListDomainDeliverabilityCampaigns

#
Service
ses

Description

Retrieve deliverability data for all the campaigns that used a specific domain to send email during a specified time range.

ListIdentityPolicies

#
Service
ses

Description

Returns a list of sending authorization policies that are attached to the given identity (an email address or a domain).

ListReputationEntities

#
Service
ses

Description

List reputation entities in your Amazon SES account in the current Amazon Web Services Region.

ListResourceTenants

#
Service
ses

Description

List all tenants associated with a specific resource.

ListTagsForResource

#
Service
ses

Description

Retrieve a list of the tags (keys and values) that are associated with a specified resource.

ListTemplates

#
Service
ses

Description

Lists the email templates present in your Amazon SES account in the current Amazon Web Services Region.

ListTenantResources

#
Service
ses

Description

List all resources associated with a specific tenant.

ListTenants

#
Service
ses

Description

List all tenants associated with your account in the current Amazon Web Services Region.

ListVerifiedEmailAddresses

#
Service
ses

Description

Deprecated.

PutAccountDedicatedIpWarmupAttributes

#
Service
ses

Description

Enable or disable the automatic warm-up feature for dedicated IP addresses.

PutAccountDetails

#
Service
ses

Description

Update your Amazon SES account details.

PutAccountSuppressionAttributes

#
Service
ses

Description

Change the settings for the account-level suppression list.

PutAccountVdmAttributes

#
Service
ses

Description

Update your Amazon SES account VDM attributes.

PutConfigurationSetArchivingOptions

#
Service
ses

Description

Associate the configuration set with a MailManager archive.

PutConfigurationSetDeliveryOptions

#
Service
ses

Description

Associate a configuration set with a dedicated IP pool.

PutConfigurationSetReputationOptions

#
Service
ses

Description

Enable or disable collection of reputation metrics for emails that you send using a particular configuration set in a specific AWS Region.

PutConfigurationSetSuppressionOptions

#
Service
ses

Description

Specify the suppression list preferences for a configuration set.

PutConfigurationSetTrackingOptions

#
Service
ses

Description

Specify a custom domain to use for open and click tracking elements in email that you send using Amazon Pinpoint.

PutConfigurationSetVdmOptions

#
Service
ses

Description

Specify VDM preferences for email that you send using the configuration set.

PutDedicatedIpInPool

#
Service
ses

Description

Move a dedicated IP address to an existing dedicated IP pool.

PutDedicatedIpPoolScalingAttributes

#
Service
ses

Description

Used to convert a dedicated IP pool to a different scaling mode.

PutDedicatedIpWarmupAttributes

#
Service
ses

Description

PutDedicatedIpWarmupAttributes API operation for Amazon Simple Email Service.

PutDeliverabilityDashboardOption

#
Service
ses

Description

Enable or disable the Deliverability dashboard for your Amazon Pinpoint account.

PutEmailIdentityConfigurationSetAttributes

#
Service
ses

Description

Used to associate a configuration set with an email identity.

PutEmailIdentityDkimAttributes

#
Service
ses

Description

Used to enable or disable DKIM authentication for an email identity.

PutEmailIdentityDkimSigningAttributes

#
Service
ses

Description

Used to configure or change the DKIM authentication settings for an email domain identity.

PutEmailIdentityFeedbackAttributes

#
Service
ses

Description

Used to enable or disable feedback forwarding for an identity.

PutEmailIdentityMailFromAttributes

#
Service
ses

Description

Used to enable or disable the custom Mail-From domain configuration for an email identity.

PutIdentityPolicy

#
Service
ses

Description

Adds or updates a sending authorization policy for the specified identity (an email address or a domain).

PutSuppressedDestination

#
Service
ses

Description

Adds an email address to the suppression list for your account or for a specific tenant.

PutTenantSuppressionAttributes

#
Service
ses

Description

Configure the suppression list preferences for a tenant.

ReorderReceiptRuleSet

#
Service
ses

Description

Reorders the receipt rules within a receipt rule set.

SendBounce

#
Service
ses

Description

Generates and sends a bounce message to the sender of an email you received through Amazon SES.

SendBulkEmail

#
Service
ses

Description

Composes an email message to multiple destinations.

SendBulkTemplatedEmail

#
Service
ses

Description

Composes an email message to multiple destinations.

SendCustomVerificationEmail

#
Service
ses

Description

Adds an email address to the list of identities for your Amazon SES account in the current Amazon Web Services Region and attempts to verify it.

SendEmail

#
Service
ses

Description

Sends an email message.

SendRawEmail

#
Service
ses

Description

Composes an email message and immediately queues it for sending.

SendTemplatedEmail

#
Service
ses

Description

Composes an email message using an email template and immediately queues it for sending.

SetActiveReceiptRuleSet

#
Service
ses

Description

Sets the specified receipt rule set as the active receipt rule set.

SetIdentityDkimEnabled

#
Service
ses

Description

Enables or disables Easy DKIM signing of email sent from an identity.

SetIdentityFeedbackForwardingEnabled

#
Service
ses

Description

Given an identity (an email address or a domain), enables or disables whether Amazon SES forwards bounce and complaint notifications as email.

SetIdentityHeadersInNotificationsEnabled

#
Service
ses

Description

Given an identity (an email address or a domain), sets whether Amazon SES includes the original email headers in the Amazon Simple Notification Service (Amazon SNS) notifications of a specified type.

SetIdentityMailFromDomain

#
Service
ses

Description

Enables or disables the custom MAIL FROM domain setup for a verified identity (an email address or a domain).

SetIdentityNotificationTopic

#
Service
ses

Description

Sets an Amazon Simple Notification Service (Amazon SNS) topic to use when delivering notifications.

SetReceiptRulePosition

#
Service
ses

Description

Sets the position of the specified receipt rule in the receipt rule set.

TagResource

#
Service
ses

Description

Add one or more tags (keys and values) to a specified resource.

TestRenderEmailTemplate

#
Service
ses

Description

Creates a preview of the MIME content of an email when provided with a template and a set of replacement data.

TestRenderTemplate

#
Service
ses

Description

Creates a preview of the MIME content of an email when provided with a template and a set of replacement data.

UntagResource

#
Service
ses

Description

Remove one or more tags (keys and values) from a specified resource.

UpdateConfigurationSetEventDestination

#
Service
ses

Description

Update the configuration of an event destination for a configuration set.

UpdateConfigurationSetReputationMetricsEnabled

#
Service
ses

Description

Enables or disables the publishing of reputation metrics for emails sent using a specific configuration set in a given Amazon Web Services Region.

UpdateConfigurationSetTrackingOptions

#
Service
ses

Description

Modifies an association between a configuration set and a custom domain for open and click event tracking.

UpdateContact

#
Service
ses

Description

Updates a contact's preferences for a list.

UpdateContactList

#
Service
ses

Description

Updates contact list metadata.

UpdateCustomVerificationEmailTemplate

#
Service
ses

Description

Updates an existing custom verification email template.

UpdateEmailIdentityPolicy

#
Service
ses

Description

Updates the specified sending authorization policy for the given identity (an email address or a domain).

UpdateEmailTemplate

#
Service
ses

Description

Updates an email template.

UpdateReceiptRule

#
Service
ses

Description

Updates a receipt rule.

UpdateReputationEntityCustomerManagedStatus

#
Service
ses

Description

Update the customer-managed sending status for a reputation entity.

UpdateReputationEntityPolicy

#
Service
ses

Description

Update the reputation management policy for a reputation entity.

UpdateTemplate

#
Service
ses

Description

Updates an email template.

VerifyEmailAddress

#
Service
ses

Description

Deprecated.

PutAccountPricingAttributes

#
Service
ses

Description

Set the pricing plan for your Amazon SES account.