Skip to main content
Administrator Guide
Last Updated: 2026-07-10
Concept: Amazon SES Email Delivery

Concept: Amazon SES Email Delivery

This topic provides details on how to ensure workers receive emails from Workday tenants that use Amazon Simple Email Service (SES) to send emails.
The Workday SMTP now uses Amazon Simple Email Service (SES) to deliver Workday emails.

Security

Workday has set up appropriate Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) records for Workday emails from myworkday.com and otp.workday.com, and their related bounce subdomains. Workday has also configured a Domain-based Message Authentication, Reporting & Conformance (DMARC) policy for receiving servers to follow. This policy helps email receiver systems distinguish between legitimate and fraudulent emails. We deliver emails over opportunistic TLS if your mail server supports it.
Workday recommends that you configure your mail servers to check our DMARC policy based on the DKIM and SPF values defined by our Workday sending domains.
Current SPF settings for myworkday.com and its related bounce subdomain use a hard fail, while SPF settings for otp.workday.com and its related bounce subdomain use a soft fail.

Return Path

Workday tracks email bounces using the related subdomains of myworkday.com and otp.workday.com. These subdomains appear in the Return Path of the email headers. The subdomains are different for each Workday data center and region. See the
Emails to Allow
section for the names of the bounce subdomains for each data center. Mail servers use these subdomains to provide alerts to Workday about email bounces.

Bounce Handling

Amazon SES uses bounce subdomains for enhanced bounce-back monitoring.
When emails soft bounce, or fail temporarily, Workday continues attempting to send them, increasing the delay between each attempt. Emails can soft bounce for many reasons, including internet connectivity issues, target mail server issues, or other temporary problems, so you don't need to take any action.
When emails hard bounce, or fail permanently, Workday stops sending emails to that address, flags it as a bounced email address, and suppresses it. See Concept: Amazon SES Email Suppression List for information on the Amazon SES Email Suppression List. Emails can hard bounce for many reasons, including typos in email addresses, former employee email addresses, or incorrect spam rejections. Workday recommends that you review emails that hard bounce and correct their system email addresses to help keep Workday's email reputation high.

Customer Mail Server Configuration

If your company requires the configuration of your mail server through a filter to accept emails from Workday, ensure that it is conditional on:
  • Passing SPF and DKIM authentication.
  • Verifying DMARC alignment.
These authentication methods ensure that only properly authenticated messages are trusted, reducing the risk of phishing or spoofing.
Amazon SES uses dynamic IP addresses, so instead of adding only individual IP addresses to your firewall and allowlist, Workday recommends that you also add the domains and subdomains listed for your company’s data center to your company's permit list:
Data Center
Email Domains
WD2 - Non-Production and WD1 - Production
  • *@us-east-1.bounce.myworkday.com
  • *@us-east-1.bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD3 - Non Production and Production
  • *@eu-west-1.bounce.myworkday.com
  • *@eu-west-1.bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD104 - Non Production
  • *@us-west-2.bounce.myworkdaygov.com
  • myworkdaygov.com
WD104 - Production
  • *@us-east-2.bounce.myworkdaygov.com
  • myworkdaygov.com
WD5 - Non Production and Production
  • *@bounce.myworkday.com
  • *@bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD10 - Non Production and Production
  • *@ca-central-1.bounce.myworkday.com
  • *@ca-central-1.bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD12 - Non Production
  • *@bounce.myworkday.com
  • *@bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD12 - Production
  • @us-east-1.@bounce.myworkday.com
  • @us-east-1.@bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD102 - Non Production and Production
  • *@ap-southeast-1.bounce.myworkday.com
  • *@ap-southeast-1.bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD103 - Non Production and Production
  • *@eu-central-1.bounce.myworkday.com
  • *@eu-central-1.bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD105 - Non Production and Production
  • *@ap-southeast-2.bounce.myworkday.com
  • *@ap-southeast-2.bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD107 - Non Production and Production
  • *@eu-west-2.bounce.myworkday.com
  • *@eu-west-2.bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD108 - Non Production and Production
  • *@us-east-2.bounce.myworkday.com
  • *@eu-east-2.bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD109 - Non Production and Production
  • *@ap-northeast-1.bounce.myworkday.com
  • *@ap-northeast-1.bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD115 - Non Production and Production
  • @us-east-1.@bounce.myworkday.com
  • @us-east-1.@bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD116 - Non Production and Production
  • *@eu-west-1.bounce.myworkday.com
  • *@eu-west-1.bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD117 - Non Production and Production
  • *@ap-south-1.bounce.myworkday.com
  • *@ap-south-1.bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD118 - Non Production and Production
  • *@eusc-de-east-1.bounce.myworkday.eu
  • myworkday.eu
WD501 - Non Production
  • *@us-west-2.bounce.myworkday.com
  • *@us-west-2.bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD501 - Production
  • *@us-east-1.bounce.myworkday.com
  • *@us-east-1.bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD502 - Non Production and Production
  • *@eu-west-1.bounce.myworkday.com
  • *@eu-west-1.bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
WD503 - Non Production and Production
  • *@us-east-2.bounce.myworkday.com
  • *@us-east-2.bounce.otp.workday.com
  • myworkday.com
  • otp.workday.com
If you don't update your company permit list or firewall with the recommended domains, Workday will still send emails, but your system firewall or spam detection configurations may prevent them from being delivered to their intended recipients or mark them as being from an external sender.

Testing

Workday recommends that you test email delivery by sending test emails to a small group of employees. This approach enables you to troubleshoot if you encounter any issues.