Every new AWS account starts with Amazon SES in **sandbox mode**. This is an AWS-imposed restriction designed to prevent abuse — it limits who you can send to and how much you can send. This page explains what sandbox mode means, how it affects your sending, and how to move to production.


  The sandbox is an Amazon SES limitation that applies at the AWS account level. SendOps has no control over these restrictions. SendOps works fully in both sandbox and production mode — the only difference is the volume and recipients you can reach through SES.


## What is SES sandbox mode?

When your AWS account is new (or when SES is first enabled in a region), SES operates in sandbox mode. In sandbox mode, SES restricts your sending to protect its shared infrastructure and your sender reputation.

## Sandbox limitations

| Restriction | Sandbox limit |
|---|---|
| **Recipients** | You can only send to **verified email addresses and domains** |
| **Daily sending quota** | **200 emails** per 24-hour period |
| **Sending rate** | **1 email per second** |
| **From address** | Must be a **verified identity** (this applies in production too) |

In sandbox mode, every recipient address must be individually verified in SES before you can send to it. This makes sandbox mode suitable for development and testing, but not for real-world sending.

## Does SendOps work in sandbox mode?

**Yes.** SendOps captures and processes events regardless of whether your SES account is in sandbox or production mode. You can:

- Complete the full onboarding flow (AWS integration, connection validation, domain verification, and test send)
- Send test emails to verified addresses
- See delivery, bounce, and engagement events appear in your SendOps dashboard
- Verify that notifications and alerting are working

After your first domain is verified during onboarding, SendOps provisions four default channels — **Default**, **Transactional**, **Marketing**, and **Onboarding** — each backed by its own SES configuration set. This happens regardless of whether your account is in sandbox or production mode.

## How SendOps detects sandbox status

SendOps automatically checks your SES account status during the **Connection Validation** phase of onboarding. The validation results include:

- Whether SES sending is enabled in your region
- Whether your account is in sandbox or production mode
- Your current sending limits (daily quota and per-second rate)
- The number of verified identities detected in your SES account

If your account is in sandbox mode, the validation shows a warning: **"Sandbox mode active"** with a note that you can only send to verified email addresses.

After onboarding, the **AWS Status Badge** in the sidebar header reflects your sandbox status. When your account is in sandbox mode, the badge displays **"Sandbox"** with an amber indicator instead of the green **"AWS Connected"** indicator shown for production accounts. Clicking the badge shows your region, account ID, and mode.

## Sandbox warnings during test send

During the **First Test Send** phase of onboarding, if your account is in sandbox mode, SendOps shows a warning listing your verified identities. If you enter a recipient address that does not match a verified email address or a verified domain, SendOps warns that the send will likely fail.

## Checking your SES account status

You can check your sandbox status in two places:

**In SendOps:** Look at the AWS Status Badge in the sidebar header. If it shows "Sandbox" with an amber dot, your account is in sandbox mode. If it shows "AWS Connected" with a green dot, you have production access.

**In the AWS console:**

1. Open the [AWS SES console](https://console.aws.amazon.com/ses/).
2. In the left sidebar, go to **Account dashboard**.
3. Look for the **Account status** section. It will show either "Sandbox" or "Production".



## Requesting production access

When you are ready to send to any email address without recipient verification limits, you need production access from AWS. **You can request it right inside SendOps — you don't have to touch the AWS console.**

### Request it from SendOps (recommended)

SendOps has a built-in **Production Access** request flow. Open it from **Infrastructure → Production Access**, or click **Request Production Access** on the AWS status badge in the sidebar.

The form is **pre-filled** from what SendOps already knows about your account: your **verified domains** and **configuration sets** are listed automatically, your **last-30-day sending volume** is summarized as a daily average, and a suggested **use-case description** plus an auto-generated **infrastructure summary** are drafted for you. You just pick a **mail type** (transactional or promotional), confirm your **website URL**, adjust the description, and optionally add a contact email.

When you submit, SendOps sends the request **directly to AWS** on your behalf — no copy-pasting into a support ticket. It then **tracks the request for you**, checking AWS periodically and updating the status on the page (pending → under review → granted). You'll get a notification when it's approved, and the AWS status badge flips from "Sandbox" to "AWS Connected" automatically.

### Alternative: request it in the AWS console

You can still submit the request manually through AWS if you prefer:


  <Step title="Open the SES console">
    Go to the [AWS SES console](https://console.aws.amazon.com/ses/) and navigate to **Account dashboard**.
  </Step>
  <Step title="Click Request production access">
    In the account status section, click the **Request production access** button.

    
  </Step>
  <Step title="Fill out the request form">
    AWS asks for details about your sending use case. Be specific and thorough:

    - **Mail type** — choose Transactional, Marketing, or both
    - **Website URL** — the website or application associated with your sending
    - **Use case description** — explain what emails you send, who your recipients are, and how you handle bounces and complaints
    - **Additional contacts** — an email address where AWS can reach you about your account
  </Step>
  <Step title="Submit and wait for review">
    AWS reviews production access requests manually by opening a **support ticket** on your behalf. Approval typically takes **24 hours** but can take longer. You will receive an email notification when your request is approved or if AWS needs more information.
  </Step>


### What AWS looks for

AWS doesn't approve production access automatically — a human reviews your request through a support ticket. In most cases, they will reply asking for evidence that you follow good sending practices. Specifically, they want to see:

- **Bounce handling** — how you detect and stop sending to addresses that bounce
- **Complaint management** — how you process and act on spam complaints
- **List hygiene** — how you maintain a clean recipient list and avoid sending to invalid addresses
- **Deliverability monitoring** — what tools you use to track your sender reputation

### Using SendOps to support your request

SendOps gives you exactly the kind of infrastructure AWS wants to see. When responding to the support ticket, mention that you use SendOps for:

- **Real-time bounce and complaint monitoring** with automated notifications when rates exceed thresholds
- **Suppression management** to prevent re-sending to addresses that have bounced or complained
- **Engagement tracking** (opens and clicks) to measure recipient interaction and identify disengaged addresses
- **Channel-based traffic separation** so transactional, marketing, and onboarding emails are tracked independently
- **Deliverability reports** filtered by channel, domain, and time period

Referencing specific tooling like this demonstrates to AWS that you take deliverability seriously and significantly improves your chances of approval.


  AWS may deny requests that are vague or incomplete. To improve your chances of approval:

  - Explain your use case clearly — what kind of emails, to whom, and how often
  - Describe your bounce and complaint handling process, and mention that you use SendOps for monitoring and alerting
  - Specify realistic sending volumes
  - Make sure you have a working website at the URL you provide
  - If AWS replies asking for more detail, respond promptly and thoroughly — the support ticket stays open until resolved


For the full details on the request process, see the [AWS documentation on requesting production access](https://docs.aws.amazon.com/ses/latest/dg/request-production-access.html).

## After production access is granted

Once your account moves to production mode:

- You can send to **any email address** — recipients no longer need to be verified
- Your daily sending quota increases (typically to **50,000 emails/day** initially)
- Your sending rate increases (typically to **14 emails/second** initially)
- AWS may increase these limits further over time based on your sending patterns and reputation

SendOps detects the change automatically. The AWS Status Badge updates from "Sandbox" to "AWS Connected", and SendOps sends a notification informing you that your account has moved out of sandbox mode. No configuration changes are needed on the SendOps side.

## Sandbox status notifications

SendOps periodically monitors your SES account status. If your sandbox status changes — either from sandbox to production, or from production back to sandbox (which can happen if AWS places your account under review) — SendOps sends a notification to your organization. These notifications appear in your SendOps notification feed and are dispatched through any configured notification channels (email, Slack, webhooks).

## Sandbox mode per region

SES sandbox status is **per region**. If you enable SES in a new AWS region, that region starts in sandbox mode even if your primary region is in production. You need to request production access separately for each region you plan to send from.

If you use SendOps with [multiple regions](/aws-setup/supported-regions), make sure each region has production access before sending real email from it.

## What's next?

- Learn about [How Email Flows](/sending-email/email-flow) from your application through SES and into SendOps
- Set up your sending identities in [Adding a Domain](/domains/adding-a-domain) or [Email Identities](/domains/email-identities)
- Organize your identities into [Channels](/channels/understanding-channels) for focused reporting