Create IAM Policies
IAM policies define what actions a user can perform. You'll create a custom policy with the exact permissions BYOMailer needs to operate.
Create the Policy
Open the IAM Policies Page
In the AWS Console, navigate to IAM → Policies and click Create policy.
Open IAM PoliciesSwitch to JSON Editor
Click the JSON tab in the policy editor, clear the default content, and paste the policy below.
Paste the Policy JSON
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"ses:GetAccount",
"ses:SendEmail",
"ses:SendRawEmail",
"ses:SendBulkEmail",
"ses:SendBulkTemplatedEmail",
"ses:CreateEmailIdentity",
"ses:GetEmailIdentity",
"ses:PutEmailIdentityMailFromAttributes",
"ses:PutEmailIdentityConfigurationSetAttributes",
"ses:CreateTemplate",
"ses:DeleteTemplate",
"ses:ListTemplates",
"ses:ListConfigurationSets",
"ses:GetConfigurationSet",
"ses:GetConfigurationSetEventDestinations",
"ses:CreateConfigurationSet",
"ses:CreateConfigurationSetEventDestination",
"ses:UpdateConfigurationSetEventDestination",
"ses:PutConfigurationSetTrackingOptions",
"ses:DeleteConfigurationSet",
"ses:CreateTenant",
"ses:CreateTenantResourceAssociation",
"ses:GetTenant",
"ses:UpdateReputationEntityPolicy",
"ses:DeleteTenantResourceAssociation",
"sns:CreateTopic",
"sns:DeleteTopic",
"sns:Subscribe",
"sns:Unsubscribe"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"sts:GetCallerIdentity",
"iam:SimulatePrincipalPolicy"
],
"Resource": "*"
}
]
}Name and Save the Policy
Click Next, then name the policy (e.g., BYOMailerSESPolicy). Optionally add a description, then click Create policy.
Permission Breakdown
Here's what each permission does and why BYOMailer needs it.
Email Sending
ses:SendEmailSend formatted emails through SES.
ses:SendRawEmailSend raw MIME emails, used for attachments and custom headers.
ses:SendBulkEmailSend bulk emails efficiently in batches.
ses:SendBulkTemplatedEmailSend bulk emails using SES templates.
Account & Identity Management
ses:GetAccountRetrieve your SES account details including sending limits and quotas.
ses:CreateEmailIdentityRegister a new email address or domain as a verified sender.
ses:GetEmailIdentityCheck the verification status of an email identity.
ses:PutEmailIdentityMailFromAttributesConfigure the custom MAIL FROM domain for an identity.
ses:PutEmailIdentityConfigurationSetAttributesSet the default configuration set on an email identity.
Template Management
ses:CreateTemplateCreate reusable email templates in SES.
ses:DeleteTemplateRemove email templates from SES.
ses:ListTemplatesList all available email templates in your account.
Configuration Sets
ses:ListConfigurationSetsList all configuration sets. Used to check if BYOMailer's set exists.
ses:GetConfigurationSetRetrieve details of a specific configuration set.
ses:GetConfigurationSetEventDestinationsRead event destinations to detect open and click tracking status.
ses:CreateConfigurationSetCreate a configuration set for tracking email events (opens, clicks, bounces).
ses:CreateConfigurationSetEventDestinationConfigure where email events are sent (SNS topic).
ses:UpdateConfigurationSetEventDestinationUpdate event destination settings.
ses:PutConfigurationSetTrackingOptionsConfigure open and click tracking for a configuration set.
ses:DeleteConfigurationSetRemove a configuration set from your account.
Tenant Isolation
ses:CreateTenantCreate an isolated tenant within your SES account for BYOMailer sends.
ses:CreateTenantResourceAssociationAssociate email identities and configuration sets with the BYOMailer tenant.
ses:GetTenantRetrieve tenant details when the tenant already exists.
ses:UpdateReputationEntityPolicySet the reputation policy on the BYOMailer tenant.
ses:DeleteTenantResourceAssociationRemove resource associations from the tenant when cleaning up templates.
SNS (Notifications)
sns:CreateTopicCreate an SNS topic to receive SES event notifications (bounces, complaints, deliveries).
sns:DeleteTopicRemove an SNS topic.
sns:SubscribeSubscribe BYOMailer's endpoint to receive notifications from the SNS topic.
sns:UnsubscribeRemove a subscription from an SNS topic.
Identity & Permission Verification
sts:GetCallerIdentityVerify that the provided AWS credentials are valid before saving them.
iam:SimulatePrincipalPolicyCheck which SES permissions your IAM user has without making real API calls.
Next Step
Now proceed to Attach Policies to Your IAM User.