AWS connection health errors

Amazon SES (BYOS)Updated

What each "Needs attention" message on Settings → AWS means, and which button fixes which fault.

EmailFig re-checks your AWS connection every few hours. If something it needs is missing, Settings → AWS shows the status Needs attention, an alert headed We can’t reach part of your SES setup with the specific reason, and one button. New sends are blocked until it clears, and we email you once, subject Action needed: your AWS connection is broken.

Most of these faults break the path your delivery notifications travel, so bounces and complaints stop reaching EmailFig. Rather than let the next campaign mail addresses that should have been suppressed, EmailFig holds new sends until the connection is healthy again. The check reports the first broken link, not a symptom further down, and emails you once per change of state.

The messages

“We can’t assume the EmailfigConnectRole in your AWS account. Check the CloudFormation stack still exists and that its trust policy hasn’t been edited.” The stack was deleted or rolled back, or the trust policy changed. Restore the stack in us-east-1, then use the card’s button: Check again if setup had finished, Try again if it hadn’t.

“The emailfig-lifecycle SNS topic in your AWS account is gone. Without it we never learn about bounces or complaints.” The topic was deleted. Click Rebuild my SES setup.

“Our subscription to your emailfig-lifecycle topic has been removed, so your delivery events aren’t reaching us.” The subscription belongs to EmailFig, so only we can restore it. Click Rebuild my SES setup. The same message covers a subscription switched to raw message delivery.

“Your SES configuration set no longer publishes events to the emailfig-lifecycle topic.” The event destination was deleted or re-pointed. Click Rebuild my SES setup.

“We reached your AWS account but couldn’t finish setting SES up in it. Check the CloudFormation stack completed, then try again.” Setup stopped part-way. Confirm the stack completed, then click Try again, or Rebuild my SES setup if setup had completed once before. Re-running is safe.

“AWS has paused sending on your SES account. Open your SES console to see why — we can’t lift it for you.” Amazon’s decision, not ours. See Amazon suspended my SES account. Once AWS lifts it, click Check again.

“The role we assumed belongs to a different AWS account than the one your stack reported.” Something is inconsistent between the stack and the role. Email support@emailfig.com with your sign-in email; there’s no self-serve fix.

“The EmailfigConnectRole in that AWS account lets us in without the External ID we issued, so we won’t use it.” The trust policy isn’t enforcing the External ID, so we refuse to send through it. Email support@emailfig.com with your sign-in email.

“Your stack reached us but we couldn’t finish connecting it. Nothing is wrong with your AWS setup.” A fault on our side, with no button. Email support@emailfig.com with your sign-in email.

“That AWS account is already connected to another EmailFig account.” An AWS account backs exactly one EmailFig account. The launch button stays so you can connect a different one. See Connect your own Amazon SES account.

“We’ve hit a limit on our side while connecting your account — nothing is wrong with your AWS setup.” Ours, not yours, and we’re already alerted. Email support@emailfig.com if you need a timescale.

The button

Label What it does
Try again Runs the whole connect-and-provision pass again, for a connection that never finished setting up
Rebuild my SES setup Re-creates the SES and SNS resources: the fix when something we own has been removed
Check again Re-reads your AWS account, for faults only you or AWS can fix

The button never just marks the error cleared: it re-builds or re-reads, and the flag lifts only once the check actually passes.

Settings, AWS with an unhealthy connection: a Needs attention badge, the red We can’t reach part of your SES setup alert naming the missing SNS topic, and a Rebuild my SES setup button.

Both buttons spend API calls in your AWS account, so they’re rate limited. Click too often and EmailFig answers Please wait a moment before checking again.

What happens to campaigns in the meantime

A send you start by hand is refused with Can’t send yet: your AWS connection needs attention — see Settings → AWS. A scheduled campaign keeps retrying for an hour, then reverts to draft, and we email you. Nothing is lost. Adding a sending domain is blocked too, with a Set up AWS first button in place of Add domain.

Next