Amazon's own email service. It's the one piece of AWS where the spam is unambiguously Amazon's to deal with.
amazonses.com in the headers. If it's there, report it through
AWS's abuse form, one message per report, with the full
headers included.Open the full headers. In Gmail it's the three dots next to Reply, then Show original. Here's how in other mail programs. Mail sent through Amazon SES carries lines like these. This is from a real one I got:
Received: from a8-19.smtp-out.amazonses.com (54.240.8.19) Feedback-ID: ::1.us-east-1.RKWWcKbF/jH52ji1QNb5y0RdAbT4H87O+BIOzvBuI8U=:AmazonSES X-SES-Outgoing: 2026.04.09-54.240.8.19 DKIM-Signature: ... d=amazonses.com ...
Received line from smtp-out.amazonses.com. That's SES's mail server handing it to yours.Feedback-ID ending in AmazonSES, and an X-SES-Outgoing header.amazonses.com, usually next to one from the sender's own domain.Lots of spam comes from Amazon's network without being SES. The big one: Salesforce runs its mail servers on Amazon Web Services, so Salesforce mail comes from Amazon IP addresses too. If the headers show mta.salesforce.com and X-SFDC- lines, it's Salesforce's to deal with, and AWS will tell you so. Report Salesforce mail this way instead.
SES is different. The sender has an AWS account and is using Amazon's own email product directly. There's no middleman to point at.
email-abuse@amazon.com, but in my experience that address sends back an automatic reply with no case number, so there's nothing to follow up on. The form gets you a case number.You'll get an automatic reply, then often a note that your report was forwarded to the SES team. After that you may hear nothing, or get a short notice that the issue was "mitigated" without saying what that means. Keep the case numbers. If the same sender comes back, report it again and cite them.
Across 77 AWS case numbers on all kinds of spam, AWS has never told me what it actually did to a sender. The closest it gets is "mitigated," with no detail. Here's how every company I report to stacks up.