Create IAM Policies

IAM policies define what actions a user can perform. You'll create a custom policy with the exact permissions BYOMailer needs to operate.

Create the Policy

1

Open the IAM Policies Page

In the AWS Console, navigate to IAM → Policies and click Create policy.

Open IAM Policies
2

Switch to JSON Editor

Click the JSON tab in the policy editor, clear the default content, and paste the policy below.

3

Paste the Policy JSON

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "ses:GetAccount",
                "ses:SendEmail",
                "ses:SendRawEmail",
                "ses:SendBulkEmail",
                "ses:SendBulkTemplatedEmail",
                "ses:CreateEmailIdentity",
                "ses:GetEmailIdentity",
                "ses:PutEmailIdentityMailFromAttributes",
                "ses:PutEmailIdentityConfigurationSetAttributes",
                "ses:CreateTemplate",
                "ses:DeleteTemplate",
                "ses:ListTemplates",
                "ses:ListConfigurationSets",
                "ses:GetConfigurationSet",
                "ses:GetConfigurationSetEventDestinations",
                "ses:CreateConfigurationSet",
                "ses:CreateConfigurationSetEventDestination",
                "ses:UpdateConfigurationSetEventDestination",
                "ses:PutConfigurationSetTrackingOptions",
                "ses:DeleteConfigurationSet",
                "ses:CreateTenant",
                "ses:CreateTenantResourceAssociation",
                "ses:GetTenant",
                "ses:UpdateReputationEntityPolicy",
                "ses:DeleteTenantResourceAssociation",
                "sns:CreateTopic",
                "sns:DeleteTopic",
                "sns:Subscribe",
                "sns:Unsubscribe"
            ],
            "Resource": "*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "sts:GetCallerIdentity",
                "iam:SimulatePrincipalPolicy"
            ],
            "Resource": "*"
        }
    ]
}
4

Name and Save the Policy

Click Next, then name the policy (e.g., BYOMailerSESPolicy). Optionally add a description, then click Create policy.

Permission Breakdown

Here's what each permission does and why BYOMailer needs it.

Email Sending

ses:SendEmail

Send formatted emails through SES.

ses:SendRawEmail

Send raw MIME emails, used for attachments and custom headers.

ses:SendBulkEmail

Send bulk emails efficiently in batches.

ses:SendBulkTemplatedEmail

Send bulk emails using SES templates.

Account & Identity Management

ses:GetAccount

Retrieve your SES account details including sending limits and quotas.

ses:CreateEmailIdentity

Register a new email address or domain as a verified sender.

ses:GetEmailIdentity

Check the verification status of an email identity.

ses:PutEmailIdentityMailFromAttributes

Configure the custom MAIL FROM domain for an identity.

ses:PutEmailIdentityConfigurationSetAttributes

Set the default configuration set on an email identity.

Template Management

ses:CreateTemplate

Create reusable email templates in SES.

ses:DeleteTemplate

Remove email templates from SES.

ses:ListTemplates

List all available email templates in your account.

Configuration Sets

ses:ListConfigurationSets

List all configuration sets. Used to check if BYOMailer's set exists.

ses:GetConfigurationSet

Retrieve details of a specific configuration set.

ses:GetConfigurationSetEventDestinations

Read event destinations to detect open and click tracking status.

ses:CreateConfigurationSet

Create a configuration set for tracking email events (opens, clicks, bounces).

ses:CreateConfigurationSetEventDestination

Configure where email events are sent (SNS topic).

ses:UpdateConfigurationSetEventDestination

Update event destination settings.

ses:PutConfigurationSetTrackingOptions

Configure open and click tracking for a configuration set.

ses:DeleteConfigurationSet

Remove a configuration set from your account.

Tenant Isolation

ses:CreateTenant

Create an isolated tenant within your SES account for BYOMailer sends.

ses:CreateTenantResourceAssociation

Associate email identities and configuration sets with the BYOMailer tenant.

ses:GetTenant

Retrieve tenant details when the tenant already exists.

ses:UpdateReputationEntityPolicy

Set the reputation policy on the BYOMailer tenant.

ses:DeleteTenantResourceAssociation

Remove resource associations from the tenant when cleaning up templates.

SNS (Notifications)

sns:CreateTopic

Create an SNS topic to receive SES event notifications (bounces, complaints, deliveries).

sns:DeleteTopic

Remove an SNS topic.

sns:Subscribe

Subscribe BYOMailer's endpoint to receive notifications from the SNS topic.

sns:Unsubscribe

Remove a subscription from an SNS topic.

Identity & Permission Verification

sts:GetCallerIdentity

Verify that the provided AWS credentials are valid before saving them.

iam:SimulatePrincipalPolicy

Check which SES permissions your IAM user has without making real API calls.

Next Step

Now proceed to Attach Policies to Your IAM User.

BYOMailer

© 2026 All rights reserved.