AllStackd is live: one workspace for every Amazon SES account

I run a lot of domains on Amazon SES, so I built the control plane I wanted. Monitor every SES account, region and domain in one place, keep delivery in your own AWS account, and send transactional mail through an optional durable API. 14-day trial, no card.

~9 min read

AllStackd is live — Amazon SES control plane for every product

Back in July I wrote about the AWS AI Get Certified Challenge for Central and Eastern Europe. I got in. The first month of Skill Builder is done — online training and the digital classroom. Live sessions start in October and run through the end of the year as I keep going on the AWS AI Practitioner path.

At some point reading about IAM and shared responsibility isn’t enough. I wanted to put what I’d learned so far into practice — on a real product, with real domains, in my own AWS account.

Here’s the result.

AllStackd went live on 30 Sep 2026. It’s an Amazon SES control plane for every product. You monitor every SES account, region and domain from one workspace. Delivery stays in your own AWS account. And when you want it, there’s an optional durable API for transactional mail.

AllStackd is not an email host and it doesn’t replace SES. AWS delivers the mail and bills the sends. AllStackd bills the workspace.

Start here: allstackd.com → Start 14-day trial (no card) → create an AWS connection in Settings → upload the CloudFormation template in your AWS account → paste back the three stack outputs. Setup guide: allstackd.com/docs.

Why I built it

I have a lot of domains. Side projects, experiments, sites that need a welcome email, a password reset or a receipt. I was already deep in the AWS CEE learning track, so Amazon SES was the obvious place for their mail: pay-as-you-go, no contract, and delivery in an account I own.

SES is great at sending. The pain is everything around it:

The AWS AI Practitioner program isn’t an email course. But it expects familiarity with IAM, the shared responsibility model and AWS pricing models. Those three ideas are exactly what AllStackd is built on: a scoped IAM role instead of keys, your account stays yours, and AWS bills AWS usage.

So I built the layer I wanted for my own domains, then shaped it for other indie developers like me.

What AllStackd is

AllStackd operates the layer above SES. Your AWS account remains the delivery system. AllStackd is the health view, the policy gate, and an optional sending API.

It has two operating modes:

ModeWhat it does
ObserveSee SES identities, DKIM, SPF, DMARC, sandbox status, quotas and reputation without routing email through AllStackd. Read-only against SES configuration and reputation APIs.
ControlAdd a durable, policy-enforced sending layer project by project, with idempotency, suppressions and short retention. Delivery still happens in your AWS account.

Health findings come with a next safe action: DKIM drift, sandbox and quota issues surface in the dashboard before the next release.

AllStackd Observe view — SES connections showing Healthy, DKIM drift, and Sandbox with a next safe action

Observe mode: health across SES connections — Healthy, DKIM drift, Sandbox — plus a next safe action.

What the site compares it to:

Amazon SES aloneSES + AllStackd
Operate accounts and regions separatelyOne workspace across SES connections
Manual identity and DKIM checksHealth findings with a next safe action
App-specific SES credentialsProject-scoped API keys
DIY queue and retry logicDurable Control-mode sending workflow

How it works

Setup takes four steps.

  1. AWS + SES. Verify a domain you own in SES (Easy DKIM CNAMEs, plus SPF and DMARC). Request production access when you’re ready to mail real users. AWS reviews that request, not AllStackd, and AWS says it gives an initial response within 24 hours.
  2. CloudFormation role. In AllStackd → Settings, create a connection and download the template. In AWS CloudFormation: Create stack → With new resources → Upload a template file. Paste the RoleArn, SnsTopicArn and ConfigurationSetName outputs back into AllStackd, then confirm the SNS subscription.
  3. Domain health. Confirm DKIM, SPF and DMARC on the Domains page. Owned domains only, no Gmail or Outlook as the From domain.
  4. Optional Control API. Create a project, assign the connection, mint an as_ API key and send with an idempotency key.
AllStackd docs — prepare Amazon SES and connect with CloudFormation, not access keys

Docs: prepare SES in your AWS account, then connect with CloudFormation — not long-lived keys.

A send looks like this:

curl -X POST https://allstackd.com/api/v1/emails \
  -H "Authorization: Bearer $ALLSTACKD_API_KEY" \
  -H "Idempotency-Key: welcome-user-42" \
  -H "Content-Type: application/json" \
  -d '{
    "from":"hello@your-verified-domain.com",
    "to":["customer@example.com"],
    "template":{"alias":"welcome","variables":{"first_name":"Ada"}}
  }'

A few details I care about as a builder:

What stays in your AWS account

This was the part I wouldn’t compromise on.

Pricing

Every plan includes Observe and Control. An SES connection is one AWS account in one region. Recipients/month count Control-mode recipients submitted through AllStackd; Observe doesn’t meter mail you send outside AllStackd.

PlanMonthlyYearlySES connectionsControl recipients/monthSigned webhooks
Portfolio€9€891100k1
Studio (best fit)€29€2895500k5
Agency€79€789252m20

AWS bills the sending separately. As of Sep 2026, new SES accounts start on the Essentials plan at $0.16 per 1,000 emails (first 10M/month), and you can switch to à-la-carte at $0.10 per 1,000 outbound (Amazon SES pricing).

Who it’s for

The site names four groups:

And who doesn’t need it, in the site’s own words: one SES account, one product, low volume — stay in the Amazon SES console. I mean that. AllStackd fits when you run several products, regions or client AWS accounts.

For me, that’s the vibe coder with a handful of domains and several side projects, each needing its own mail. I’m a solo developer in Hungary, and AllStackd is built for people who work the same way.

Running more than one product on SES?

Start the 14-day trial (no card) and connect one account in Observe mode first. Founder-assisted setup is available.

Open allstackd.com →

Your turn — get started

One path from trial to first health check (and optional send).

  1. Verify a domain in Amazon SES

    Easy DKIM, SPF and DMARC on a domain you own.

  2. Request production access

    For that region when you’re ready for real recipients. Sandbox is per region.

  3. Start the 14-day trial

    Sign up at allstackd.com. No card during the trial.

  4. Connect with CloudFormation

    Settings → create a connection → download the template → create the stack in your SES region → paste RoleArn, SnsTopicArn, ConfigurationSetName → confirm the SNS subscription.

  5. Check Domains health

    Confirm DKIM / SPF / DMARC in Observe mode.

  6. Optional Control send

    Create a project, mint an as_ key, send a test email.

  7. Stuck or found a bug?

    Read allstackd.com/docs, email support@allstackd.com for founder-assisted setup, or reply to the newsletter. Share with a friend who runs more SES accounts than they check.

If you only remember one line: SES delivers. AllStackd operates.

FAQ

What is an Amazon SES dashboard?

The built-in one is the SES console's account dashboard: sending activity, quota used, bounces and complaints for a single AWS account, with sandbox status per region. A third-party SES dashboard like AllStackd sits on top of that and pulls identities, DKIM, SPF, DMARC, sandbox status, quotas and reputation from several SES accounts and regions into one workspace, while delivery stays in your AWS account.

How do I monitor multiple Amazon SES accounts in one place?

Connect each AWS account and region to one monitoring layer instead of logging into every console. In AllStackd, each connection is one AWS account in one region, added through a CloudFormation-created IAM role with a unique External ID, not access keys. Observe mode then shows identity health, DKIM drift, sandbox status, quotas and reputation for all connections in one view. Portfolio covers 1 connection, Studio 5, Agency 25.

Is AllStackd free?

No, but there's a 14-day free trial and no card is required during it. After the trial, checkout is required to keep access. Plans are Portfolio at €9/month or €89/year, Studio at €29/month or €289/year, and Agency at €79/month or €789/year. Every plan includes Observe and Control. Amazon SES sending charges are billed separately by AWS, and prices may exclude tax.

Does AllStackd replace Amazon SES?

No. AllStackd is not an email host. Messages are delivered by Amazon SES in your own AWS account, and AWS bills you for those sends. AllStackd is the operations layer on top: a health view across accounts and regions, plus an optional Control-mode API that queues transactional email with idempotency and suppressions before submitting it through your SES account.

Do I need to give AllStackd my AWS access keys?

No. You download a CloudFormation template from AllStackd, create the stack in your AWS account, and paste back the role, SNS topic and configuration set outputs. AllStackd assumes that role with a unique External ID, and sessions last at most one hour. It never asks for long-lived access keys or SES SMTP passwords. Observe mode is read-only; Control mode adds sending permissions.

How do I get out of the Amazon SES sandbox?

Request production access in the SES console: Account dashboard → View Get set up page → Request production access. Choose Transactional or Marketing, add your website URL, and confirm you only mail people who asked for it and handle bounces and complaints. AWS says it sends an initial response within 24 hours. Sandbox status is per region, so repeat this for every region you send from.

How much does Amazon SES cost in 2026?

As of Sep 2026, new SES accounts start on the Essentials plan at $0.16 per 1,000 emails for the first 10 million per month, with no monthly fee. À-la-carte outbound is $0.10 per 1,000, and attachments add $0.12 per GB. Pro ($105) and Enterprise ($500) plans add a per-account, per-region monthly fee. New AWS customers can get up to $200 in Free Tier credits.

Sources: AllStackd · Amazon SES pricing · AWS Certified AI Practitioner.

Disclosure: AllStackd is my product (paid beta with a 14-day trial). No affiliate links in this post.

Questions? Get in touch — or subscribe for the next ship notes.

← All posts