CEVICT

SES Bridge for Ghost · Guide · checked October 1, 2026

Sending Ghost newsletters through Amazon SES: your options

Disclosure: this guide is written with AI by CEVICT, which sells one of the options below (SES Bridge for Ghost, currently a pre-order). We've tried to describe every option fairly, including the free ones. Facts were checked on October 1, 2026; corrections are welcome at support@cevict.ai.

The short answer

Self-hosted Ghost can send transactional email (sign-in links, staff invites) through Amazon SES using its normal SMTP mail settings. But Ghost's newsletter (bulk email) sending only speaks Mailgun's API. Ghost's own configuration docs say Mailgun is optional for transactional email "but it is required for bulk mail". So to send newsletters through SES you need something that speaks Mailgun's API to Ghost and hands the mail to SES: a Mailgun-compatible proxy. You can run one yourself for free, or pay for a hosted one.

Your options at a glance

OptionCostYou run a server?Good fit if…
Stay on MailgunMailgun's plan pricesNoIt works for you and the bill is fine.
Ghost(Pro)Ghost(Pro) planNoYou'd rather not self-host at all. Ghost(Pro) sends newsletters for you; you don't choose the provider.
Self-host an open-source Mailgun-to-SES proxyFree software + your hosting + SES feesYesYou're comfortable running, updating and monitoring one more service.
Hosted proxy (Mailpunch, SES Bridge for Ghost)Monthly fee + SES feesNoYou want SES pricing without operating the proxy.
Send newsletters from a separate email toolThat tool's priceNoYou're willing to give up Ghost's built-in newsletter editor and member email analytics.

What any SES route needs from you

Whichever proxy you choose, the AWS side is the same, and it's your account:

  1. Verify your sending domain in SES (Easy DKIM records in your DNS), ideally with a custom MAIL FROM subdomain.
  2. Request SES production access. New SES accounts start in the sandbox, which only sends to verified addresses. AWS reviews the request; describe your opt-in newsletter and how you handle bounces and complaints.
  3. Create a configuration set with event publishing (for example to SNS) for deliveries, bounces, complaints and, if you want open tracking, opens. Without this, Ghost's newsletter analytics and member email status won't update.
  4. Create a narrowly scoped IAM user or role that can only send email through SES (for example ses:SendEmail and ses:SendRawEmail), and give the proxy only those keys.

SES pricing: on September 30, 2026 AWS listed $0.10 per 1,000 emails à la carte, or $0.16 per 1,000 on the Essentials plan that new SES accounts start on. Check the AWS SES pricing page for current numbers and data-transfer charges.

What a proxy has to do for Ghost to work properly

Ghost's bulk email client reads a Mailgun base URL, API key and domain from its settings (bulkEmail.mailgun in the Ghost source). A proxy that only accepts sends is not enough. To keep Ghost working fully, it should handle:

When comparing proxies, check which of these each one implements, and check its license and how recently it was updated.

Option: self-host an open-source proxy (free)

There are several open-source Mailgun-compatible proxies for Ghost on GitHub. These are the ones we found on October 1, 2026 (we haven't audited any of them; read the code and license before you deploy one):

What you take on: a server or container to run it, TLS, keeping it updated as Ghost changes, storing your AWS keys safely, wiring SES events back so Ghost's analytics work, and noticing when it breaks before a newsletter goes out.

Option: a hosted proxy

Which should you pick?

Whatever you choose, send only to people who subscribed to your Ghost site, and keep bounce and complaint rates low. AWS can pause SES sending for accounts with high bounce or complaint rates.

See SES Bridge for Ghost