# Amazon SES privacy rating

Amazon Simple Email Service, an email API and SMTP relay on AWS for sending and receiving email, billed per message.

## Summary

Amazon SES scores 54 out of 100 (grade D) on the email sending services criteria. It meets 7 of 12 criteria: transparency report, tells users about requests, TLS configuration, security headers, open and click tracking off by default, encrypted delivery can be enforced and EU data location. It partly meets no ads or data sales and independent audit. It does not meet open source and no trackers or telemetry. Still needing evidence: message content deleted after delivery. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A.

- Website: https://aws.amazon.com/ses/
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Home page trackers: none found
- Category: [Email sending services](https://privacyratings.com/email-sending/)
- Also rated: [AWS End User Messaging SMS](https://privacyratings.com/communications-apis/aws-end-user-messaging-sms/) (SMS and voice APIs), [Amazon Route 53](https://privacyratings.com/dns-hosting/amazon-route-53/) (DNS hosting), [Amazon Web Services](https://privacyratings.com/server-hosting/amazon-web-services/) (Server hosting), [Kindle](https://privacyratings.com/ebook-readers/kindle/) (Ebook readers), [Amazon Alexa](https://privacyratings.com/smart-home/amazon-alexa/) (Smart home), [Amazon Music](https://privacyratings.com/music-streaming/amazon-music/) (Music streaming), [Amazon Photos](https://privacyratings.com/photo-management/amazon-photos/) (Photo management)
- Grade: D (54/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | No | Closed source. |  |
| No trackers or telemetry | No | The website loads Amplitude, DoubleClick and Marketo scripts. |  |
| No ads or data sales | Partial | Customer content is not used for marketing or advertising, but the website loads DoubleClick advertising scripts to promote AWS. | https://aws.amazon.com/compliance/data-privacy-faq/ |
| Independent audit | Partial | A SOC 3 summary report is public. The full SOC 2 report is only available to customers through AWS Artifact. | https://aws.amazon.com/compliance/soc-faqs/ |
| Transparency report | Yes | Amazon regularly publishes a report on the types and volume of information requests it receives. | https://aws.amazon.com/compliance/data-privacy-faq/ |
| Tells users about requests | Yes | AWS gives customers notice of demands for their content unless legally prohibited. | https://aws.amazon.com/compliance/data-privacy-faq/ |
| TLS configuration | Yes | Grade A+ | https://www.ssllabs.com/ssltest/analyze.html?d=aws.amazon.com&hideResults=on |
| Security headers | Yes | Grade A (95/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=aws.amazon.com |
| Modern web standards | Not tested yet | Not tested yet. |  |
| Message content deleted after delivery | Unknown |  |  |
| Open and click tracking off by default | Yes | Open and click tracking only apply to mail sent with a configuration set that publishes those events. | https://docs.aws.amazon.com/ses/latest/dg/faqs-metrics.html |
| Encrypted delivery can be enforced | Yes | TLS is opportunistic by default. A configuration set with the TLS policy set to Require drops mail that cannot be sent over TLS. | https://docs.aws.amazon.com/ses/latest/dg/security-protocols.html |
| EU data location | Yes | Available in several EU regions, including Frankfurt, Ireland, Paris, Milan and Stockholm. | https://docs.aws.amazon.com/general/latest/gr/ses.html |

Source: https://privacyratings.com/email-sending/amazon-ses/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/email-sending/amazon-ses.md
