Getting started
Domains & DNS
Receive and send on your own domain through Amazon SES.
Squadmail receives and sends all mail through Amazon SES in your AWS account. Any domain or subdomain whose DNS you control works — it does not have to be on Cloudflare.
1. Connect Amazon SES (once per instance)
Set AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY and AWS_REGION (a region with SES receiving, e.g. eu-west-1). Then open the setup wizard → Amazon SES → Set up receiving automatically. It creates:
- an S3 bucket where SES stores incoming messages,
- an SNS topic that notifies your Worker at
/hooks/ses/<secret>, - an SES receipt rule set with one rule for all verified domains.
No dashboard access? Run the same setup from your machine: node --env-file=.env scripts/ses-setup.ts (pnpm ses:setup).
2. Add the domain
Settings → Domains → Add domain (or the setup wizard). Squadmail registers it with SES and shows the DNS records to publish:
| Section | Type | Name | Purpose |
|---|---|---|---|
| Receiving | MX | your.domain | Deliver incoming mail to SES |
| Sending | CNAME | 3 × …._domainkey.your.domain | Verify the domain and DKIM-sign outgoing mail |
| Sending | MX | send.your.domain | Bounces (custom MAIL FROM) |
| Sending | TXT | send.your.domain | SPF for the MAIL FROM domain |
| DMARC (optional) | TXT | _dmarc.your.domain | Recommended DMARC policy |
Most DNS providers expect the name relative to your domain (send, not send.your.domain) — that is how the dashboard shows it. TTL can stay on Auto.
Click Check again after publishing; the domain turns Verified once SES sees the records (usually minutes).
A dedicated subdomain such as
agents.example.comkeeps agent mail apart from your main mailboxes and their reputation.
3. Test
The setup wizard creates a test inbox and waits live for your first mail.
Catch-all
With catch-all on, an inbox is created automatically the first time an unknown address on the domain receives mail.
Unknown recipients
SES cannot reject at SMTP level, so mail to an address without an inbox is dropped and recorded in the event log — never silently.
Sending
Once verified, the same domain sends replies, forwards and send_email messages. See Sending & replies.