New: one-click AWS connect. No access keys to create or store

Connect Amazon SES
in one click.

Ops-Free is a Resend/Postmark-style email API and dashboard that sends through your own AWS account. Click Create stack in AWS and you're connected: no IAM users to set up, no access keys to copy, nothing secret for us to store.

2
clicks to connect your AWS account
0
access keys stored with one-click connect
~1s
from queued to handed to Amazon SES

Illustrative preview of the connect flow.

01The problem

Raw SES gives you the infrastructure.
You still have to operate it.

Six problems every team hits within the first month of sending production email through SES — and how Ops-Free absorbs each one.

01
DNS & domain setup

Raw SES

Configure SPF, DKIM, DMARC, domain verification and DNS records manually.

Ops-Free

Guided domain verification with DNS configuration and verification status in one place.

02
Bounce & complaint handling

Raw SES

A hard bounce or complaint can damage your sending reputation if you don't handle it correctly.

Ops-Free

Automatically process bounce and complaint events and maintain a suppression list.

03
Rate limits

Raw SES

SES has account-specific sending quotas and send-rate limits. Burst traffic can result in throttling.

Ops-Free

Queue outgoing messages and throttle delivery according to your SES sending limits.

04
AWS sandbox

Raw SES

New SES accounts start with restrictions that make production usage difficult.

Ops-Free

A guided production-access workflow and preparation checklist.

05
Infrastructure operations

Raw SES

You have to build the surrounding infrastructure yourself: queues, retries, logs, event processing and monitoring.

Ops-Free

One API layer for sending, queueing, retries, event tracking and operational visibility.

06
Developer experience

Raw SES

You're working directly with AWS APIs and infrastructure primitives.

Ops-Free

A simple developer API designed around sending email, not operating AWS infrastructure.

02Before / after

8 setup steps.
5 of them are gone.

Ops-Free still sends through your own SES account. This is every step of setting SES up properly, and what's left of it for you.

  1. 01AWS access

    One click

    Raw SES

    • Create an IAM user and write its policy
    • Generate access keys
    • Store them safely and rotate them

    With Ops-Free

    Click Connect AWS and create the stack. It adds one scoped IAM role. There are no keys.

  2. 02Domain verification

    Guided

    Raw SES

    • Create the identity in SES
    • Copy the DKIM records into your DNS
    • Check back until it verifies

    With Ops-Free

    Type your domain and add the three records shown, with copy buttons. On Route 53 they’re added for you.

  3. 03Delivery events

    Removed

    Raw SES

    • Create an SNS topic
    • Subscribe an HTTPS endpoint and confirm it
    • Create a configuration set and its event destination

    With Ops-Free

    Nothing. Connecting AWS also creates the topic, the subscription and the configuration set in your account.

  4. 04Event handling

    Removed

    Raw SES

    • Write a webhook that verifies SNS signatures
    • Parse bounce, complaint and delivery events

    With Ops-Free

    Nothing. Events are verified and recorded against each email.

  5. 05Suppression

    Removed

    Raw SES

    • Store every bounced and complained address
    • Check that list before each send

    With Ops-Free

    Nothing. Those addresses are blocked automatically and checked before every send.

  6. 06Rate limits

    Removed

    Raw SES

    • Look up your SES send rate
    • Build a queue that paces sends to it
    • Retry throttled and failed sends

    With Ops-Free

    Nothing. Sends are queued, paced to your SES rate and retried with backoff.

  7. 07Send log

    Removed

    Raw SES

    • Record every send and its outcome yourself
    • Build somewhere to search it

    With Ops-Free

    Nothing. Every email and what happened to it is in the dashboard.

  8. 08Production access

    Guided

    Raw SES

    • Write the use-case description from scratch
    • Submit it and hope it’s enough

    With Ops-Free

    Answer a few questions. It drafts the request in the fields AWS asks for, and you submit it.

Still yours: the AWS bill for what you send, your domain's DNS records (unless it's on Route 53), and AWS's review of your production-access request.

03Architecture

How it works.

Two paths through the system: sending a message, and receiving delivery events back from SES.

Sending

Your application

Ops-Free API

POST /api/v1/send

Queue & rate limiter

AWS SES

your account

Recipient

Events

AWS SES

SNS events

Ops-Free webhook

Delivery / bounce / complaint

Dashboard & blocked addresses

04Get started

From sign-up to first email.

Four steps to send, one more before you go to production. You need an AWS account, and a domain or just an email address.

Create an account

Read the full walkthrough with every click spelled out.

  1. 1

    Create an account

    Sign up with an email and password.

  2. 2

    Connect your AWS account

    Click Connect AWS and pick your region. In the AWS tab that opens, tick the box and click Create stack. That creates one IAM role in your account that only Ops-Free can use, and the dashboard turns to Connected by itself. Delivery and bounce tracking is set up in the same step. No access keys to create, copy or store. Read the template first. You can delete the stack in AWS at any time to cut off access, or use an access key instead if you prefer.

    What the role is allowed to do
    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Effect": "Allow",
          "Action": [
            "ses:GetAccount",
            "ses:SendEmail",
            "ses:CreateEmailIdentity",
            "ses:GetEmailIdentity",
            "ses:CreateConfigurationSet",
            "ses:CreateConfigurationSetEventDestination",
            "ses:UpdateConfigurationSetEventDestination",
            "ses:PutEmailIdentityConfigurationSetAttributes",
            "sns:CreateTopic",
            "sns:Subscribe"
          ],
          "Resource": "*"
        },
        {
          "Effect": "Allow",
          "Action": [
            "route53:ListHostedZonesByName",
            "route53:ChangeResourceRecordSets"
          ],
          "Resource": "*"
        }
      ]
    }
  3. 3

    Verify your domain or email address

    Type your domain. Ops-Free creates it in your SES account and shows three DNS records to add, with copy buttons. If your DNS is in Route 53, they're added for you. No domain yet? Verify your email address instead: click the link Amazon sends you, and you can send.

  4. 4

    Create an API key and send

    One click creates your key and shows a ready-to-run request. Send a test email from the dashboard, or call POST /api/v1/send from your app.

  5. 5

    Start sending to anyoneBefore production

    New SES accounts can only send to verified addresses, up to 200 emails a day. Start sending to anyone prepares the request for you to submit to AWS, which usually reviews it within a day.

05Developer experience

A developer API, not an AWS SDK call.

Send with a bearer API key over HTTP. Ops-Free authenticates the key, checks the suppression list, durably queues the message and hands it to SES from your AWS account. The response comes back before delivery completes — status updates arrive through the dashboard and your connected webhook.

  • Idempotency-Key header

    Retried requests are deduplicated server-side, so a network retry never double-sends.

  • Templates or inline content

    Send HTML/text inline with variables, or reference a stored template by id.

  • Enforced before the queue

    Per-key and per-account rate limits are checked before a message is ever persisted.

send.http

POST /api/v1/send
Authorization: Bearer sk_live_...
Content-Type: application/json

{
  "from": "hello@example.com",
  "to": ["user@example.com"],
  "subject": "Welcome",
  "html": "<h1>Hello</h1>"
}

202 Accepted

{
  "id": "3f2a1c9e-...",
  "status": "queued",
  "message": "Accepted for asynchronous delivery"
}
06Product

One dashboard for delivery, domains and keys.

Every message, bounce and complaint lands here — alongside domain verification, API keys and sending status.

app.opsfree.dev/dashboard

Overview

production
Accepted
12,480
Delivered
12,190
Bounced
142
Complained
6
Suppressed
31
Queue depth
0
Volume by outcome
Daily, last 14 days · UTC
  • Delivered
  • Awaiting outcome
  • Bounced / complained
  • Failed / suppressed
0200400600800Sep 1Sep 3Sep 5Sep 7Sep 9Sep 11Sep 13
Show data table
Day (UTC)DeliveredAwaiting outcomeBounced / complainedFailed / suppressed
2026-09-013951564420
2026-09-024321675460
2026-09-034791885510
2026-09-044511775480
2026-09-055732296610
2026-09-062821053300
2026-09-07244943260
2026-09-085081985540
2026-09-095552096590
2026-09-105832296620
2026-09-115452096580
2026-09-1260222106640
2026-09-132911153310
2026-09-1464924107690
Domain verification
mail.example.com verified
API keys
2 active
Sending status
Workers healthy

Illustrative preview built from the real dashboard components — your account starts empty.

07Cost model

Keep AWS SES economics.
Lose the operational overhead.

Ops-Free is a developer experience and operations layer on top of your own AWS SES account — it sends through your credentials and your quota. There's no separate email-sending infrastructure to provision or pay for beyond what SES already charges you.

You keep the AWS bill you'd have anyway. Ops-Free is what runs the queue, the retries, the bounce handling and the dashboard around it.

Ops-Free operations layer

Queueing, retries, bounce/complaint handling, dashboard

runs on ↓

Your AWS account

Amazon SES usage-based pricing, billed directly by AWS

08Pricing

Free to start. Pay when you outgrow it.

Full pricing and FAQ

For now, everything is free. There are no limits during the beta. These are the plans we're planning for when paid plans open.

Free

$0/ month

No card needed

Everything you need to send your first emails.

3,000 emails / month

  • 1 verified domain or address
  • 3-day email history
  • 3 templates

Pro

Opens after beta

$7/ month

or $70 / year — 2 months free

For a product that sends real traffic.

50,000 emails / month

  • 10 verified domains and addresses
  • 30-day email history

On every plan

  • One-click AWS setup
  • Delivery events and the activity log
  • Automatic suppression of bounces and complaints
  • API and dashboard

Founding-member rate

Everyone who signs up during the beta gets 50% off Pro for as long as they keep the plan, once paid plans open. The beta is free in the meantime.

Prices are in US dollars. Amazon charges for SES separately, directly to your AWS account.

09Who it's for

Built for people already shipping on AWS.

SaaS developers

Transactional email — welcome, password reset, invoices — without owning bounce processing.

Indie hackers

Production email infrastructure without the time cost of building queues and retry logic solo.

Startups

Start on SES economics from day one, with the operational layer already handled.

Backend engineers

An API that matches how you already think about sending mail, not an AWS SDK to wrap yourself.

Teams on AWS already

Keep credentials and delivery inside your own AWS account — Ops-Free doesn't ask you to leave it.

Anyone tired of reputation risk

Suppression and complaint handling run automatically, before a bad send touches your sender reputation.

Stop building email infrastructure around SES.
Start building your product.

Ops-Free SES Engine