What Does "Whitelisting" Mean for Amazon SES?
Disambiguates a genuinely mixed-intent query, then walks through the real AWS production-access process with exact form fields.
Amazon SES whitelist usually means one thing: getting out of the sandbox, where every new account is capped at 200 messages per day, 1 per second, and can only send to verified addresses. Production access is requested from the SES console under Get set up, then Request production access, and mostly comes down to how clearly your use case and website match what you tell AWS you are sending.
"Whitelisting" Means Different Things in Amazon SES
If you searched for Amazon SES whitelist, you could mean one of three different things, and they have almost nothing to do with each other. Most people who land here mean the first one.
Getting your account out of the sandbox is the most common meaning. Amazon SES puts every new account in a sandbox that restricts you to sending to verified recipients only. Since you effectively have to whitelist every single recipient by hand until AWS approves you, people commonly call this whitelisting their SES account. This is what the rest of this guide covers.
SES identity-based sending policies are a separate, real Amazon SES feature that restricts which specific addresses or identities are allowed to send or receive through an account, configured through IAM or identity policies. If you are trying to lock down who can use your SES account rather than get approved to send more broadly, this guide is not about that.
A recipient's mail server allowlisting your sending IP is a third possibility. If you are trying to get a specific company's Office 365 or Google Workspace admin to stop blocking your cold email, that is a conversation with them about their own spam filter, not an AWS setting. Amazon SES has no control over another organization's allowlist.
What the Sandbox Actually Restricts
Every new Amazon SES account starts in the sandbox, independently in every AWS Region. While your account is in the sandbox, Amazon SES enforces three hard limits: you can only send to verified email addresses and domains, you are capped at 200 messages per 24-hour period, and you can send a maximum of 1 message per second. None of these are configurable from your side. They lift only when AWS moves your account to production.
Want every check on this page run automatically?
EmailQo runs SPF, DKIM, DMARC, blacklist, and content checks before every campaign, on your own Gmail, Outlook, or AWS SES sending account. Start the 7-day free trial, no card.
Start free trial →Requesting Production Access: The Exact Process
Production access is requested from the SES console's Account Dashboard, under Get set up, then Request production access. AWS asks for five specific things:
Mail type. Marketing, sent one-to-many to a list, or Transactional, sent one-to-one and triggered by a user action. Pick whichever describes most of what you will send.
Website URL. A link AWS uses to sanity-check that your described use case matches what your site actually does.
Additional contacts. Up to 4 email addresses to receive account communications.
Preferred contact language. English or Japanese.
Acknowledgement. A checkbox confirming you will only send to people who have explicitly requested your email, and that you have a process for handling bounce and complaint notifications.
AWS's stated response window is 24 hours for an initial reply. If they need more information before approving, that adds time on top.
If you are verifying a domain, not just an email address, before you request access, AWS explicitly recommends doing that first. AWS calls a verified domain identity a best practice that speeds up approval.
A Use-Case Template That Gets Approved
AWS's request form varies slightly by account and region, some show only the five structured fields above, others add a free-text box for extra context. Either way, having this written out before you open the form means you are not improvising an answer under a submission deadline. Copy and adapt it:
"We are a [describe your business briefly, e.g. B2B software company / marketing agency / consulting firm] that uses email outreach to reach potential business customers. Our contact lists consist of professionals in [your industry] who are relevant to our product or service.
We collect contacts through [e.g. LinkedIn research / industry databases / trade shows / website sign-ups / referrals]. All our emails include a clear unsubscribe link and we immediately process all unsubscribe requests.
We use [your sending platform] to manage our campaigns, which includes automatic bounce handling and complaint processing. We aim to maintain a bounce rate well below 2% and a complaint rate below 0.1%.
We are requesting production access to send targeted outreach emails to our contact lists. We are requesting a daily sending quota of [10,000 / 50,000] emails per day."
Every sentence in that template maps to something a reviewer checks for: what you send, who you send it to, how you got them, how you handle bounces and complaints, and how much volume you need. That is the same specificity the Mail type, Website URL, and Acknowledgement fields are designed to surface, this just puts it in your own words, in one place, so nothing gets left out.
What Happens After You Submit
The timeline is short and mostly automated until a human reviews your request:
Within about an hour. AWS sends an automated acknowledgement confirming your request was received. This is not the decision.
Within 24 hours. A reviewer checks the request against your website and the details you provided. Most legitimate business requests are approved within this window.
If approved. You get a confirmation email and your account moves to production immediately, the 200-per-day cap and verified-recipient restriction lift right away.
If rejected. AWS explains why in the rejection email. It is almost always a specificity problem, not a policy problem, see below for what to do next.
Why Requests Stall, and What to Do If Yours Is Rejected
AWS does not publish a list of rejection reasons, so treat this as informed inference from what the form itself asks for, not an official checklist. The acknowledgement checkbox and the website URL field are the two places reviewers have something concrete to check against. If your described mail type does not match what your website suggests you are sending, or your request does not make clear how recipients ended up on your list and how you handle bounces and complaints, that is exactly the kind of mismatch a manual reviewer flags for follow-up. Vague answers cost you the 24-hour window. Specific ones, like how you collect consent and what your bounce threshold trigger is, do not.
If you are rejected, do not resubmit the identical form and hope for a different reviewer. Fix the specific gap AWS calls out in the rejection email, tighten your mail type, website URL, and acknowledgement answers so they visibly agree with each other, and reapply using the template above. There is no cooldown period or penalty for reapplying, a tightened second request is commonly approved within the same 24-hour window.
After Approval
Once you are in production, Amazon SES lifts the verified-recipient restriction and you can send to any valid address. You still have to verify any identity you use as a From, Source, Sender, or Return-Path address. Production access removes the recipient restriction, not the sender verification requirement. Initial production sending limits are typically modest and rise automatically as your sending history stays clean, meaning low bounce and complaint rates. You can request explicit quota increases through the same console once you need more.
Related Resources
Does whitelisting Amazon SES mean the same thing as production access?
Usually yes in practice, though AWS itself never uses the word whitelist. The sandbox requires every recipient to be individually verified until you are approved for production, which is what most people mean when they search for this.
How long does Amazon SES production access take?
AWS's stated initial response window is 24 hours. It can take longer if they request more information about your use case.
What are the sandbox limits before I get production access?
200 messages per 24-hour period, 1 message per second, and sending is restricted to verified email addresses and domains only.
Does verifying a domain instead of just an email address help my request?
AWS specifically calls out a verified domain as a best practice that helps requests get approved faster.
Do I still need to verify my sending identity after production access is granted?
Yes. Production access removes the restriction on who you can send to. You still must verify any address or domain you send from.
Can Amazon SES whitelist my domain with another company's mail server?
No. That is a setting controlled by the recipient's own mail provider, not by AWS. Amazon SES has no ability to get another organization to allowlist your sending domain.
Keep the guide close, get deliverability tips monthly
One short, useful email per month covering SPF/DKIM/DMARC pitfalls, warmup, and cold-email content. No spam. Unsubscribe anytime.
By subscribing you agree to receive occasional tips at this address. See our Privacy Policy. Unsubscribe anytime from any email or at /unsubscribe.
Your emails deserve the inbox.
Start free trialKeep reading
SPF Setup Guide for Cold Email Senders
Step by step SPF record setup for cold email. Includes DNS examples, common mistakes, and how to validate your record is working.
GuideDKIM Setup for Amazon SES | Step by Step
Complete DKIM setup guide for Amazon SES. Generate keys, add DNS records, verify in AWS console, and start sending authenticated email.
GuideDMARC Setup Guide for Cold Email Senders
Step by step DMARC setup for cold email. Choose the right policy, set up reporting, and protect your domain from spoofing.
AlternativeInstantly Alternative: Own Your Infrastructure
Instantly uses shared sending pools. EmailQo routes through your own AWS SES. Own your reputation instead of sharing it with thousands of senders.
AlternativeSmartlead Alternative: Dedicated Infrastructure
Smartlead shares your sending reputation with other users. EmailQo gives you your own AWS SES infrastructure. Dedicated sending from $19/mo.