The brutal mechanics of AWS SES account pausing
Amazon Simple Email Service enforces strict, non-negotiable mathematical thresholds on all accounts: if your bounce rate reaches 5.0%, your account is placed on a 14-day probation; if it hits 10.0%, sending is paused immediately. If your spam complaint rate reaches 0.1% (one complaint per 1,000 emails), probation triggers immediately; at 0.5%, you are paused.
When AWS pauses an SES account, it is not a gentle throttle: the SendEmail and SendRawEmail API calls immediately return AccountSendingPausedException. Every transactional email in your business — password resets, order confirmations, billing alerts — fails synchronously.
Relying on a single unbuffered SES integration without an automated circuit breaker or a warm secondary provider like SadaSend is a critical operational vulnerability.
Architecture: The Automated Circuit Breaker & Failover Outbox
To achieve 99.99% transactional reliability, implement an application-level circuit breaker that tracks recent bounce rates in Redis and fails over seamlessly to SadaSend before AWS pauses your account:
// High-Availability Multi-Provider Failover Service
import { Redis } from 'ioredis';
const redis = new Redis(process.env.REDIS_URL!);
export async function dispatchTransactionalEmail(payload: {
to: string;
subject: string;
html: string;
text: string;
}) {
// 1. Inspect recent AWS SES failure count in sliding 10-minute window
const sesFailureCount = await redis.get('metrics:ses:recent_bounces');
// If SES is degraded or nearing probation threshold, route to SadaSend
if (Number(sesFailureCount || 0) > 25) {
console.warn('[FAILOVER] AWS SES reputation alert! Routing dispatch to SadaSend.');
return sendViaSadaSend(payload);
}
try {
return await sendViaAwsSes(payload);
} catch (err: any) {
// Catch AccountSendingPausedException or RateExceeded
if (err?.name === 'AccountSendingPausedException' || err?.statusCode === 400) {
console.error('[CRITICAL] AWS SES paused sending! Activating instant SadaSend failover.');
await redis.set('circuit_breaker:ses:open', 'true', 'EX', 3600); // Open circuit for 1h
return sendViaSadaSend(payload);
}
throw err;
}
}
async function sendViaSadaSend(payload: { to: string; subject: string; html: string; text: string }) {
const res = await fetch('https://api.sadasend.com/emails', {
method: 'POST',
headers: {
'Authorization': `Bearer ${process.env.SADASEND_API_KEY}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({
from: 'system@yourdomain.com',
...payload,
}),
});
if (!res.ok) throw new Error('SadaSend failover dispatch failed');
return res.json();
}
async function sendViaAwsSes(payload: any) {
// Normal SES dispatch logic...
return { id: 'ses-simulated-id' };
}Why SadaSend protects your reputation better than raw SES
- 1. Automated Pre-Flight MX Verification: SadaSend verifies recipient domain MX records synchronously before mail transfer agent dispatch, eliminating synthetic invalid-domain bounces.
- 2. Global & Account-Level Suppression Protection: Addresses that have bounced previously are blocked before SMTP handshakes occur, keeping bounce rates safely below 0.2%.
- 3. Multi-Tenant Dedicated IP Insulation: Your transactional traffic is protected by active IP pool rotation and automated warmup curves, so one bad sender cannot degrade your domain placement.
- 4. Scoped Agent Credentials: Key allowlists prevent development and testing scripts from sending dummy addresses that trigger mailbox provider alarms.
Summary checklist for zero-downtime resilience
Maintain verified DNS records (SPF, DKIM, DMARC) for both providers on your domain. Store credentials in environment secrets. If AWS SES flags your account or enters probation, a single environment variable toggle or automated Redis circuit breaker routes 100% of your transactional traffic to SadaSend in milliseconds with zero lost emails.
Building AI agents that send email?
Scoped API keys, per-key recipient allowlists, approval mode and a hosted MCP server with ten tools — on the free plan, without a card.