SendOps creates a small set of resources in your AWS account, and it needs all of them. This page lists each one, what it is for, and what happens if it is deleted. Read it before you tidy up your SES console.


  `sendops-events` looks like an unused configuration set, but it isn't a channel: SendOps sends its test emails through it, and so does any domain without a default channel. If it is deleted, SES rejects those sends. Re-applying the SendOps CloudFormation template **does not** bring it back. See [Recreating sendops-events](#recreating-sendops-events) below.


## Created by the CloudFormation stack

These are created when you [connect your AWS account](/aws-setup/connecting-aws), by the `sendops` stack in your sending region. SendOps needs every one of them.

| Resource | Name | What it does |
|---|---|---|
| IAM role | `SendOpsRole` | Lets SendOps act in your account, restricted by an external ID only you and SendOps know. See [IAM Permissions Explained](/aws-setup/iam-permissions). |
| IAM role | `SendOpsEventBridgeRole` | Lets EventBridge deliver your SES events to SendOps. |
| SES configuration set | `sendops-events` | SendOps' own configuration set. Not a channel. Test sends go through it, and it makes SES emit per-message events. |
| SES event destination | `sendops-eventbridge` (on `sendops-events`) | Sends those events to your default EventBridge bus. |
| EventBridge connection | `sendops-webhook` | Holds the API key EventBridge uses to authenticate to SendOps. |
| EventBridge API destination | `sendops-ingest` | The SendOps endpoint your events are delivered to. |
| EventBridge rule | `sendops-ses-events` | Forwards every SES event on the default bus to that endpoint. |

If you deleted one of these by hand, CloudFormation doesn't notice. The stack still reports as healthy, and a stack update that touches the missing resource fails and rolls back. Recreate the resource by hand with the same name, or contact support.

The optional capabilities add their own resources: see [Edge Stack](/edge/edge-stack) and [Inbound Receiving](/inbound/inbound-receiving). Remove a capability from **Infrastructure → AWS Stacks** in SendOps, not by deleting its resources in AWS.

## Created for your channels

Once a sending identity is set up, SendOps creates one SES configuration set for each [channel](/channels/understanding-channels) through the SES API, not through CloudFormation. Each is named `sesmail-<workspace>--<channel>` and has its own `sendops-eventbridge` event destination. Four channels are created by default:

| Channel | What it's for |
|---|---|
| Default | Your domains' default configuration set. Mail goes through it unless a send picks another channel. |
| Transactional | Password resets, receipts and system notifications. Bounced addresses are suppressed. |
| Marketing | Newsletters and campaigns. Open and click tracking is on, and bounced and complaining addresses are suppressed. |
| Onboarding | Welcome emails and activation flows. |

Deleting the CloudFormation stack does not delete these, because the stack didn't create them.

## What is safe to remove

- **A channel you don't use.** Detach or archive it on the **Channels** page in SendOps. That only changes SendOps; nothing in AWS is deleted. If you also want its configuration set gone from AWS, check first that nothing sends through it, because SES rejects every send to a deleted configuration set, including from any domain whose default it is.
- **A capability you don't use** (Edge, Inbound). Remove it from **Infrastructure → AWS Stacks**. SendOps gives you the stack update to apply.
- **Resources SendOps did not create.** SendOps never needs a configuration set, rule or role that isn't listed on this page.

Nothing in the [CloudFormation stack table](#created-by-the-cloudformation-stack) is safe to remove while you use SendOps.

## Recreating sendops-events

If `sendops-events` was deleted, SendOps notices at its next [account sync](/aws-setup/account-sync), which runs hourly. It then shows a banner on the **AWS Stacks** and **Channels** pages and sends a *SendOps Configuration Set Missing* notification. To fix it:

1. Open the [SES console](https://console.aws.amazon.com/ses/home#/configuration-sets) in your sending region and choose **Create set**. Name it `sendops-events`.
2. Open the new set, go to **Event destinations**, and choose **Add destination**. Select every event type, choose **Amazon EventBridge** with the **default** event bus, and name the destination `sendops-eventbridge`.
3. Back in SendOps, choose **Check again** on the banner, or wait for the next sync. The banner clears once SendOps finds the set.

Don't try to restore it by re-applying the CloudFormation template. CloudFormation still believes the set exists, so an update doesn't recreate it.