Amazon Simple Email Service

2026/09/01 - Amazon Simple Email Service - 4 new 2 updated api methods

Changes  Added support for managing SMIME signing certificates for email identities, including associating, listing, and disassociating certificates. Added the UpdateConfigurationSet operation to configure message security options such as signing scheme.

UpdateConfigurationSet (new) Link ¶

Updates an existing configuration set.

This operation performs a partial update. Only the attributes that you include in the request are updated; any omitted attribute is left unchanged.

See also: AWS API Documentation

Request Syntax

client.update_configuration_set(
    ConfigurationSetName='string',
    MessageSecurityOptions={
        'SigningScheme': {
            'DefaultScheme': {}
            ,
            'SmimeScheme': {
                'SignatureFormat': 'DETACHED'
            }
        }
    }
)
type ConfigurationSetName:

string

param ConfigurationSetName:

[REQUIRED]

The name of the configuration set to update.

type MessageSecurityOptions:

dict

param MessageSecurityOptions:

The security options that apply to the MIME message itself for messages sent with the configuration set.

  • SigningScheme (dict) --

    The signing scheme that Amazon SES API v2 applies to messages sent with the configuration set.

    • DefaultScheme (dict) --

      Use the default signing behavior. When you select this option, Amazon SES API v2 doesn't add an S/MIME signature to messages sent with the configuration set.

    • SmimeScheme (dict) --

      Sign messages sent with the configuration set using S/MIME. For signing to apply, the email identity used to send a message must have an active S/MIME certificate association.

      • SignatureFormat (string) --

        The format of the S/MIME signature that Amazon SES API v2 applies to messages.

rtype:

dict

returns:

Response Syntax

{}

Response Structure

  • (dict) --

    An HTTP 200 response if the request succeeds, or an error message if the request fails.

AssociateEmailIdentityCertificate (new) Link ¶

Associates an S/MIME certificate with an email identity. After the certificate is active, Amazon SES API v2 can add an S/MIME signature to messages that you send from the associated address when signing is enabled on the configuration set used to send the message.

The certificate is an X.509 certificate that you manage in Certificate Manager (ACM). You identify it by its Amazon Resource Name (ARN).

  • If the email identity is a domain, you must specify a FromAddress that belongs to that domain or one of its subdomains. The certificate applies to messages sent from that address.

  • If the email identity is an email address, FromAddress is optional. If you specify it, it must exactly match the email identity.

When the association is created, the certificate begins provisioning and its status is PROVISIONING. The status changes to ACTIVE when the certificate is ready to use for signing. Each email address can have only one certificate association. If an association already exists for the address, this operation returns an error, unless the existing association is in the DEPROVISIONING state.

See also: AWS API Documentation

Request Syntax

client.associate_email_identity_certificate(
    EmailIdentity='string',
    FromAddress='string',
    CertificateArn='string'
)
type EmailIdentity:

string

param EmailIdentity:

[REQUIRED]

The email identity, either an email address or a domain, to associate the certificate with.

type FromAddress:

string

param FromAddress:

The email address that the certificate applies to. This value is required when the email identity is a domain, and the address must belong to that domain or one of its subdomains. When the email identity is an email address, this value is optional. If you specify it, it must exactly match the email identity.

type CertificateArn:

string

param CertificateArn:

[REQUIRED]

The Amazon Resource Name (ARN) of the Certificate Manager (ACM) certificate to associate with the email identity.

rtype:

dict

returns:

Response Syntax

{}

Response Structure

  • (dict) --

    An HTTP 200 response if the request succeeds, or an error message if the request fails.

ListEmailIdentityCertificates (new) Link ¶

Lists the S/MIME certificates that are associated with the specified email identity. The results include certificates in all states, such as PROVISIONING, ACTIVE, INACTIVE, DEPROVISIONING, and FAILED.

If a certificate has passed its expiration time, it's returned with a status of FAILED.

We recommend using pagination to ensure that the operation returns quickly and successfully. When there are more results than fit in a single response, the response includes a NextToken value that you use in a subsequent call to retrieve the next set of results.

See also: AWS API Documentation

Request Syntax

client.list_email_identity_certificates(
    EmailIdentity='string',
    NextToken='string',
    PageSize=123
)
type EmailIdentity:

string

param EmailIdentity:

[REQUIRED]

The email identity whose certificate associations you want to list.

type NextToken:

string

param NextToken:

A token returned from a previous call to ListEmailIdentityCertificates to indicate the position in the list of certificates.

type PageSize:

integer

param PageSize:

The number of results to show in a single call to ListEmailIdentityCertificates. If the number of results is larger than the number you specified in this parameter, then the response includes a NextToken element, which you can use to obtain additional results.

rtype:

dict

returns:

Response Syntax

{
    'Certificates': [
        {
            'FromAddress': 'string',
            'Status': 'PROVISIONING'|'INACTIVE'|'DEPROVISIONING'|'ACTIVE'|'FAILED',
            'CertificateArn': 'string',
            'CertificateExpiryTime': datetime(2015, 1, 1)
        },
    ],
    'NextToken': 'string'
}

Response Structure

  • (dict) --

    Information about the S/MIME certificates that are associated with an email identity.

    • Certificates (list) --

      An array that contains the certificate associations for the email identity. Each entry includes the from address, the certificate's status, its Amazon Resource Name (ARN), and its expiry time.

      • (dict) --

        An object that contains information about an S/MIME certificate that's associated with an email identity.

        • FromAddress (string) --

          The email address that the certificate applies to.

        • Status (string) --

          The status of the certificate association. A status of ACTIVE indicates that the certificate is ready to use for signing.

        • CertificateArn (string) --

          The Amazon Resource Name (ARN) of the Certificate Manager (ACM) certificate that's associated with the email identity.

        • CertificateExpiryTime (datetime) --

          The timestamp after which the certificate is no longer valid.

    • NextToken (string) --

      A token that indicates that there are additional certificates to list. To view additional certificates, issue another request to ListEmailIdentityCertificates, and pass this token in the NextToken parameter.

DisassociateEmailIdentityCertificate (new) Link ¶

Removes the association between an S/MIME certificate and an email identity. After the association is removed, Amazon SES API v2 stops adding an S/MIME signature to messages sent from that address.

If the email identity is a domain, specify the FromAddress whose certificate association you want to remove.

This operation is idempotent. If the specified email identity exists but there's no matching certificate association, the operation succeeds without making any changes. Amazon SES API v2 returns a NotFoundException only when the specified email identity doesn't exist.

See also: AWS API Documentation

Request Syntax

client.disassociate_email_identity_certificate(
    EmailIdentity='string',
    FromAddress='string'
)
type EmailIdentity:

string

param EmailIdentity:

[REQUIRED]

The email identity whose certificate association you want to remove.

type FromAddress:

string

param FromAddress:

The email address whose certificate association you want to remove. This value is required when the email identity is a domain. When the email identity is an email address, this value is optional.

rtype:

dict

returns:

Response Syntax

{}

Response Structure

  • (dict) --

    An HTTP 200 response if the request succeeds, or an error message if the request fails.

CreateConfigurationSet (updated) Link ¶
Changes (request)
{'MessageSecurityOptions': {'SigningScheme': {'DefaultScheme': {},
                                              'SmimeScheme': {'SignatureFormat': 'DETACHED'}}}}

Create a configuration set. Configuration sets are groups of rules that you can apply to the emails that you send. You apply a configuration set to an email by specifying the name of the configuration set when you call the Amazon SES API v2. When you apply a configuration set to an email, all of the rules in that configuration set are applied to the email.

See also: AWS API Documentation

Request Syntax

client.create_configuration_set(
    ConfigurationSetName='string',
    TrackingOptions={
        'CustomRedirectDomain': 'string',
        'HttpsPolicy': 'REQUIRE'|'REQUIRE_OPEN_ONLY'|'OPTIONAL'
    },
    DeliveryOptions={
        'TlsPolicy': 'REQUIRE'|'OPTIONAL',
        'SendingPoolName': 'string',
        'MaxDeliverySeconds': 123
    },
    ReputationOptions={
        'ReputationMetricsEnabled': True|False,
        'LastFreshStart': datetime(2015, 1, 1)
    },
    SendingOptions={
        'SendingEnabled': True|False
    },
    Tags=[
        {
            'Key': 'string',
            'Value': 'string'
        },
    ],
    SuppressionOptions={
        'SuppressedReasons': [
            'BOUNCE'|'COMPLAINT',
        ],
        'SuppressionScope': 'ACCOUNT'|'TENANT',
        'ValidationOptions': {
            'ConditionThreshold': {
                'ConditionThresholdEnabled': 'ENABLED'|'DISABLED',
                'OverallConfidenceThreshold': {
                    'ConfidenceVerdictThreshold': 'MEDIUM'|'HIGH'|'MANAGED'
                }
            }
        }
    },
    VdmOptions={
        'DashboardOptions': {
            'EngagementMetrics': 'ENABLED'|'DISABLED'
        },
        'GuardianOptions': {
            'OptimizedSharedDelivery': 'ENABLED'|'DISABLED'
        }
    },
    ArchivingOptions={
        'ArchiveArn': 'string'
    },
    MessageSecurityOptions={
        'SigningScheme': {
            'DefaultScheme': {}
            ,
            'SmimeScheme': {
                'SignatureFormat': 'DETACHED'
            }
        }
    }
)
type ConfigurationSetName:

string

param ConfigurationSetName:

[REQUIRED]

The name of the configuration set. The name can contain up to 64 alphanumeric characters, including letters, numbers, hyphens (-) and underscores (_) only.

type TrackingOptions:

dict

param TrackingOptions:

An object that defines the open and click tracking options for emails that you send using the configuration set.

  • CustomRedirectDomain (string) -- [REQUIRED]

    The domain to use for tracking open and click events.

  • HttpsPolicy (string) --

    The https policy to use for tracking open and click events.

type DeliveryOptions:

dict

param DeliveryOptions:

An object that defines the dedicated IP pool that is used to send emails that you send using the configuration set.

  • TlsPolicy (string) --

    Specifies whether messages that use the configuration set are required to use Transport Layer Security (TLS). If the value is Require, messages are only delivered if a TLS connection can be established. If the value is Optional, messages can be delivered in plain text if a TLS connection can't be established.

  • SendingPoolName (string) --

    The name of the dedicated IP pool to associate with the configuration set.

  • MaxDeliverySeconds (integer) --

    The maximum amount of time, in seconds, that Amazon SES API v2 will attempt delivery of email. If specified, the value must greater than or equal to 300 seconds (5 minutes) and less than or equal to 50400 seconds (840 minutes).

type ReputationOptions:

dict

param ReputationOptions:

An object that defines whether or not Amazon SES collects reputation metrics for the emails that you send that use the configuration set.

  • ReputationMetricsEnabled (boolean) --

    If true, tracking of reputation metrics is enabled for the configuration set. If false, tracking of reputation metrics is disabled for the configuration set.

  • LastFreshStart (datetime) --

    The date and time (in Unix time) when the reputation metrics were last given a fresh start. When your account is given a fresh start, your reputation metrics are calculated starting from the date of the fresh start.

type SendingOptions:

dict

param SendingOptions:

An object that defines whether or not Amazon SES can send email that you send using the configuration set.

  • SendingEnabled (boolean) --

    If true, email sending is enabled for the configuration set. If false, email sending is disabled for the configuration set.

type Tags:

list

param Tags:

An array of objects that define the tags (keys and values) to associate with the configuration set.

  • (dict) --

    An object that defines the tags that are associated with a resource. A tag is a label that you optionally define and associate with a resource. Tags can help you categorize and manage resources in different ways, such as by purpose, owner, environment, or other criteria. A resource can have as many as 50 tags.

    Each tag consists of a required tag key and an associated tag value, both of which you define. A tag key is a general label that acts as a category for a more specific tag value. A tag value acts as a descriptor within a tag key. A tag key can contain as many as 128 characters. A tag value can contain as many as 256 characters. The characters can be Unicode letters, digits, white space, or one of the following symbols: _ . : / = + -. The following additional restrictions apply to tags:

    • Tag keys and values are case sensitive.

    • For each associated resource, each tag key must be unique and it can have only one value.

    • The  aws: prefix is reserved for use by Amazon Web Services; you can’t use it in any tag keys or values that you define. In addition, you can't edit or remove tag keys or values that use this prefix. Tags that use this prefix don’t count against the limit of 50 tags per resource.

    • You can associate tags with public or shared resources, but the tags are available only for your Amazon Web Services account, not any other accounts that share the resource. In addition, the tags are available only for resources that are located in the specified Amazon Web Services Region for your Amazon Web Services account.

    • Key (string) -- [REQUIRED]

      One part of a key-value pair that defines a tag. The maximum length of a tag key is 128 characters. The minimum length is 1 character.

    • Value (string) -- [REQUIRED]

      The optional part of a key-value pair that defines a tag. The maximum length of a tag value is 256 characters. The minimum length is 0 characters. If you don't want a resource to have a specific tag value, don't specify a value for this parameter. If you don't specify a value, Amazon SES sets the value to an empty string.

type SuppressionOptions:

dict

param SuppressionOptions:

An object that contains information about the suppression list preferences for the configuration set. You can optionally include a SuppressionScope to override the tenant or account suppression scope for emails sent using this configuration set.

  • SuppressedReasons (list) --

    A list that contains the reasons that email addresses are automatically added to the suppression list for your account or for a specific tenant. This list can contain any or all of the following:

    • COMPLAINT – Amazon SES adds an email address to the suppression list for your account or for a specific tenant when a message sent to that address results in a complaint.

    • BOUNCE – Amazon SES adds an email address to the suppression list for your account or for a specific tenant when a message sent to that address results in a hard bounce.

    • (string) --

      The reason that the address was added to the suppression list for your account or for a specific tenant. The value can be one of the following:

      • COMPLAINT – Amazon SES added an email address to the suppression list for your account or for a specific tenant because a message sent to that address results in a complaint.

      • BOUNCE – Amazon SES added an email address to the suppression list for your account or for a specific tenant because a message sent to that address results in a hard bounce.

  • SuppressionScope (string) --

    The suppression scope for the configuration set. This overrides the tenant or account suppression scope for emails sent using this configuration set. Can be one of the following:

    • TENANT – Use the tenant's suppression list.

    • ACCOUNT – Use the account-level suppression list.

  • ValidationOptions (dict) --

    Contains validation options for email address suppression.

    • ConditionThreshold (dict) -- [REQUIRED]

      Specifies the condition threshold settings for suppression validation.

      • ConditionThresholdEnabled (string) -- [REQUIRED]

        Indicates whether Auto Validation is enabled for suppression. Set to ENABLED to enable the Auto Validation feature, or set to DISABLED to disable it.

      • OverallConfidenceThreshold (dict) --

        The overall confidence threshold used to determine suppression decisions.

        • ConfidenceVerdictThreshold (string) -- [REQUIRED]

          The confidence level threshold for suppression decisions.

type VdmOptions:

dict

param VdmOptions:

An object that defines the VDM options for emails that you send using the configuration set.

  • DashboardOptions (dict) --

    Specifies additional settings for your VDM configuration as applicable to the Dashboard.

    • EngagementMetrics (string) --

      Specifies the status of your VDM engagement metrics collection. Can be one of the following:

      • ENABLED – Amazon SES enables engagement metrics for the configuration set.

      • DISABLED – Amazon SES disables engagement metrics for the configuration set.

  • GuardianOptions (dict) --

    Specifies additional settings for your VDM configuration as applicable to the Guardian.

    • OptimizedSharedDelivery (string) --

      Specifies the status of your VDM optimized shared delivery. Can be one of the following:

      • ENABLED – Amazon SES enables optimized shared delivery for the configuration set.

      • DISABLED – Amazon SES disables optimized shared delivery for the configuration set.

type ArchivingOptions:

dict

param ArchivingOptions:

An object that defines the MailManager archiving options for emails that you send using the configuration set.

  • ArchiveArn (string) --

    The Amazon Resource Name (ARN) of the MailManager archive where the Amazon SES API v2 will archive sent emails.

type MessageSecurityOptions:

dict

param MessageSecurityOptions:

The message security options to apply to the configuration set, such as the signing scheme used for messages that you send with the configuration set.

  • SigningScheme (dict) --

    The signing scheme that Amazon SES API v2 applies to messages sent with the configuration set.

    • DefaultScheme (dict) --

      Use the default signing behavior. When you select this option, Amazon SES API v2 doesn't add an S/MIME signature to messages sent with the configuration set.

    • SmimeScheme (dict) --

      Sign messages sent with the configuration set using S/MIME. For signing to apply, the email identity used to send a message must have an active S/MIME certificate association.

      • SignatureFormat (string) --

        The format of the S/MIME signature that Amazon SES API v2 applies to messages.

rtype:

dict

returns:

Response Syntax

{}

Response Structure

  • (dict) --

    An HTTP 200 response if the request succeeds, or an error message if the request fails.

GetConfigurationSet (updated) Link ¶
Changes (response)
{'MessageSecurityOptions': {'SigningScheme': {'DefaultScheme': {},
                                              'SmimeScheme': {'SignatureFormat': 'DETACHED'}}}}

Get information about an existing configuration set, including the dedicated IP pool that it's associated with, whether or not it's enabled for sending email, and more.

Configuration sets are groups of rules that you can apply to the emails you send. You apply a configuration set to an email by including a reference to the configuration set in the headers of the email. When you apply a configuration set to an email, all of the rules in that configuration set are applied to the email.

See also: AWS API Documentation

Request Syntax

client.get_configuration_set(
    ConfigurationSetName='string'
)
type ConfigurationSetName:

string

param ConfigurationSetName:

[REQUIRED]

The name of the configuration set.

rtype:

dict

returns:

Response Syntax

{
    'ConfigurationSetName': 'string',
    'TrackingOptions': {
        'CustomRedirectDomain': 'string',
        'HttpsPolicy': 'REQUIRE'|'REQUIRE_OPEN_ONLY'|'OPTIONAL'
    },
    'DeliveryOptions': {
        'TlsPolicy': 'REQUIRE'|'OPTIONAL',
        'SendingPoolName': 'string',
        'MaxDeliverySeconds': 123
    },
    'ReputationOptions': {
        'ReputationMetricsEnabled': True|False,
        'LastFreshStart': datetime(2015, 1, 1)
    },
    'SendingOptions': {
        'SendingEnabled': True|False
    },
    'Tags': [
        {
            'Key': 'string',
            'Value': 'string'
        },
    ],
    'SuppressionOptions': {
        'SuppressedReasons': [
            'BOUNCE'|'COMPLAINT',
        ],
        'SuppressionScope': 'ACCOUNT'|'TENANT',
        'ValidationOptions': {
            'ConditionThreshold': {
                'ConditionThresholdEnabled': 'ENABLED'|'DISABLED',
                'OverallConfidenceThreshold': {
                    'ConfidenceVerdictThreshold': 'MEDIUM'|'HIGH'|'MANAGED'
                }
            }
        }
    },
    'VdmOptions': {
        'DashboardOptions': {
            'EngagementMetrics': 'ENABLED'|'DISABLED'
        },
        'GuardianOptions': {
            'OptimizedSharedDelivery': 'ENABLED'|'DISABLED'
        }
    },
    'ArchivingOptions': {
        'ArchiveArn': 'string'
    },
    'MessageSecurityOptions': {
        'SigningScheme': {
            'DefaultScheme': {},
            'SmimeScheme': {
                'SignatureFormat': 'DETACHED'
            }
        }
    }
}

Response Structure

  • (dict) --

    Information about a configuration set.

    • ConfigurationSetName (string) --

      The name of the configuration set.

    • TrackingOptions (dict) --

      An object that defines the open and click tracking options for emails that you send using the configuration set.

      • CustomRedirectDomain (string) --

        The domain to use for tracking open and click events.

      • HttpsPolicy (string) --

        The https policy to use for tracking open and click events.

    • DeliveryOptions (dict) --

      An object that defines the dedicated IP pool that is used to send emails that you send using the configuration set.

      • TlsPolicy (string) --

        Specifies whether messages that use the configuration set are required to use Transport Layer Security (TLS). If the value is Require, messages are only delivered if a TLS connection can be established. If the value is Optional, messages can be delivered in plain text if a TLS connection can't be established.

      • SendingPoolName (string) --

        The name of the dedicated IP pool to associate with the configuration set.

      • MaxDeliverySeconds (integer) --

        The maximum amount of time, in seconds, that Amazon SES API v2 will attempt delivery of email. If specified, the value must greater than or equal to 300 seconds (5 minutes) and less than or equal to 50400 seconds (840 minutes).

    • ReputationOptions (dict) --

      An object that defines whether or not Amazon SES collects reputation metrics for the emails that you send that use the configuration set.

      • ReputationMetricsEnabled (boolean) --

        If true, tracking of reputation metrics is enabled for the configuration set. If false, tracking of reputation metrics is disabled for the configuration set.

      • LastFreshStart (datetime) --

        The date and time (in Unix time) when the reputation metrics were last given a fresh start. When your account is given a fresh start, your reputation metrics are calculated starting from the date of the fresh start.

    • SendingOptions (dict) --

      An object that defines whether or not Amazon SES can send email that you send using the configuration set.

      • SendingEnabled (boolean) --

        If true, email sending is enabled for the configuration set. If false, email sending is disabled for the configuration set.

    • Tags (list) --

      An array of objects that define the tags (keys and values) that are associated with the configuration set.

      • (dict) --

        An object that defines the tags that are associated with a resource. A tag is a label that you optionally define and associate with a resource. Tags can help you categorize and manage resources in different ways, such as by purpose, owner, environment, or other criteria. A resource can have as many as 50 tags.

        Each tag consists of a required tag key and an associated tag value, both of which you define. A tag key is a general label that acts as a category for a more specific tag value. A tag value acts as a descriptor within a tag key. A tag key can contain as many as 128 characters. A tag value can contain as many as 256 characters. The characters can be Unicode letters, digits, white space, or one of the following symbols: _ . : / = + -. The following additional restrictions apply to tags:

        • Tag keys and values are case sensitive.

        • For each associated resource, each tag key must be unique and it can have only one value.

        • The  aws: prefix is reserved for use by Amazon Web Services; you can’t use it in any tag keys or values that you define. In addition, you can't edit or remove tag keys or values that use this prefix. Tags that use this prefix don’t count against the limit of 50 tags per resource.

        • You can associate tags with public or shared resources, but the tags are available only for your Amazon Web Services account, not any other accounts that share the resource. In addition, the tags are available only for resources that are located in the specified Amazon Web Services Region for your Amazon Web Services account.

        • Key (string) --

          One part of a key-value pair that defines a tag. The maximum length of a tag key is 128 characters. The minimum length is 1 character.

        • Value (string) --

          The optional part of a key-value pair that defines a tag. The maximum length of a tag value is 256 characters. The minimum length is 0 characters. If you don't want a resource to have a specific tag value, don't specify a value for this parameter. If you don't specify a value, Amazon SES sets the value to an empty string.

    • SuppressionOptions (dict) --

      An object that contains information about the suppression list preferences for your account or for a specific tenant.

      • SuppressedReasons (list) --

        A list that contains the reasons that email addresses are automatically added to the suppression list for your account or for a specific tenant. This list can contain any or all of the following:

        • COMPLAINT – Amazon SES adds an email address to the suppression list for your account or for a specific tenant when a message sent to that address results in a complaint.

        • BOUNCE – Amazon SES adds an email address to the suppression list for your account or for a specific tenant when a message sent to that address results in a hard bounce.

        • (string) --

          The reason that the address was added to the suppression list for your account or for a specific tenant. The value can be one of the following:

          • COMPLAINT – Amazon SES added an email address to the suppression list for your account or for a specific tenant because a message sent to that address results in a complaint.

          • BOUNCE – Amazon SES added an email address to the suppression list for your account or for a specific tenant because a message sent to that address results in a hard bounce.

      • SuppressionScope (string) --

        The suppression scope for the configuration set. This overrides the tenant or account suppression scope for emails sent using this configuration set. Can be one of the following:

        • TENANT – Use the tenant's suppression list.

        • ACCOUNT – Use the account-level suppression list.

      • ValidationOptions (dict) --

        Contains validation options for email address suppression.

        • ConditionThreshold (dict) --

          Specifies the condition threshold settings for suppression validation.

          • ConditionThresholdEnabled (string) --

            Indicates whether Auto Validation is enabled for suppression. Set to ENABLED to enable the Auto Validation feature, or set to DISABLED to disable it.

          • OverallConfidenceThreshold (dict) --

            The overall confidence threshold used to determine suppression decisions.

            • ConfidenceVerdictThreshold (string) --

              The confidence level threshold for suppression decisions.

    • VdmOptions (dict) --

      An object that contains information about the VDM preferences for your configuration set.

      • DashboardOptions (dict) --

        Specifies additional settings for your VDM configuration as applicable to the Dashboard.

        • EngagementMetrics (string) --

          Specifies the status of your VDM engagement metrics collection. Can be one of the following:

          • ENABLED – Amazon SES enables engagement metrics for the configuration set.

          • DISABLED – Amazon SES disables engagement metrics for the configuration set.

      • GuardianOptions (dict) --

        Specifies additional settings for your VDM configuration as applicable to the Guardian.

        • OptimizedSharedDelivery (string) --

          Specifies the status of your VDM optimized shared delivery. Can be one of the following:

          • ENABLED – Amazon SES enables optimized shared delivery for the configuration set.

          • DISABLED – Amazon SES disables optimized shared delivery for the configuration set.

    • ArchivingOptions (dict) --

      An object that defines the MailManager archive where sent emails are archived that you send using the configuration set.

      • ArchiveArn (string) --

        The Amazon Resource Name (ARN) of the MailManager archive where the Amazon SES API v2 will archive sent emails.

    • MessageSecurityOptions (dict) --

      The message security options that are applied to the configuration set, such as the signing scheme used for messages that you send with the configuration set.

      • SigningScheme (dict) --

        The signing scheme that Amazon SES API v2 applies to messages sent with the configuration set.

        • DefaultScheme (dict) --

          Use the default signing behavior. When you select this option, Amazon SES API v2 doesn't add an S/MIME signature to messages sent with the configuration set.

        • SmimeScheme (dict) --

          Sign messages sent with the configuration set using S/MIME. For signing to apply, the email identity used to send a message must have an active S/MIME certificate association.

          • SignatureFormat (string) --

            The format of the S/MIME signature that Amazon SES API v2 applies to messages.