When would you move an Amazon SES workload from the shared IP pool onto dedicated IPs, and what does that commit you to?
answer
- shared means pooled reputation, no warm-up
- dedicated means yours alone, both ways
- ramp volume before you rely on it
- idle IPs go cold again
- one pool per stream, per configuration set
basics
~20 sMove only at consistent high volume, when isolating your reputation from other senders is worth owning it. Dedicated IPs cost a fixed monthly fee per address, must be warmed up gradually, and decay if your sending volume is not steady.
solid answer
~50 sOn the shared pool your mail leaves from addresses used by many SES customers, so reputation is pooled and largely managed for you — no warm-up, no monthly fee, and good behaviour by the crowd carries occasional bad behaviour. Dedicated IPs give you an address nobody else sends from: your reputation is yours alone, which cuts both ways. The commitments are real. You pay per IP per month, you must **warm up** by ramping volume gradually so receivers build a history rather than seeing a cold address suddenly emit large volume, and you must **sustain** volume, because reputation on an idle IP fades. SES offers dedicated IPs in two flavours — standard, where you own the warm-up plan, and managed, where SES handles warm-up and scales the pool for you. Assign a pool per configuration set so a marketing stream cannot damage the address transactional mail leaves from. The honest default for most workloads is: stay on shared.
code
bash · 12 lines# Managed pool: SES owns warm-up and scales IP count to volume
aws sesv2 create-dedicated-ip-pool \
--pool-name transactional --scaling-mode MANAGED
# Bind the pool to one sending stream
aws sesv2 put-configuration-set-delivery-options \
--configuration-set-name transactional \
--sending-pool-name transactional
# Measure before and after
aws sesv2 put-account-vdm-attributes \
--vdm-attributes VdmEnabled=ENABLEDgo deeper
Know that SES can send from shared addresses used by many customers or from addresses reserved for you, and that reserved ones cost money and need a gradual volume ramp.
Explain the mechanics: why a cold IP needs warm-up, why reputation decays without steady volume, and how a pool is attached to a sending stream through a configuration set.
Demonstrate operating it: choose managed over standard when nobody will own a warm-up plan, split transactional and marketing onto separate pools, and monitor per-IP reputation rather than assuming it holds.
Own the call and its limits. Defend staying on shared IPs when volume is spiky, name what pool isolation does and does not protect against at the account level, and insist on a measured baseline before and after the move.
## The actual decision Interviewers ask this because the wrong answer is enthusiastic. Dedicated IPs sound like the professional choice, so candidates recommend them by reflex. The right answer starts by defending the shared pool and names the conditions under which leaving it is justified. ## What the shared pool gives you On shared IPs your mail leaves alongside many other SES customers'. Consequences: - **No warm-up.** The addresses already have a long, established history with every major receiver. - **No per-IP cost.** - **Volume-tolerant.** Spiky or low sending is fine, because the addresses stay warm on aggregate traffic even when yours goes quiet for a week. - **Reputation is pooled**, and AWS actively polices the pool — that policing is the reason bounce and complaint thresholds are enforced on your account at all. The downside is the one everyone names: another customer's behaviour can, in principle, affect you. In practice AWS's enforcement makes this a much smaller effect than candidates assume, and it is rarely on its own a reason to move. ## What dedicated IPs give you, and what they take A dedicated IP is an address only you send from. The upside is isolation and control: your sending history is yours, some enterprise recipients and partners want a fixed, allow-listable address, and you can segment streams onto separate addresses. The costs are structural, not just financial: **Warm-up.** A brand-new address has no history. Blasting full volume from it on day one reads to receivers exactly like a spammer who just bought an address block — deferrals, spam-foldering, or outright blocks. Warm-up means ramping daily volume over a period of weeks, ideally sending your most-engaged recipients first, because opens and low complaints are what build the history. SES supports this with a warm-up mechanism that throttles how much of your traffic goes to a new dedicated IP while the rest overflows. **Sustained volume.** Reputation is a rolling window. An IP that sends heavily in December and nothing in January is partly cold again by February. This is why the guidance is consistent high volume — not a peak, a floor. A workload that sends a large campaign monthly and nothing between is a worse fit for dedicated IPs than one sending steadily every day at a fraction of that total. **Operational ownership.** Blocklist monitoring, per-IP reputation, warm-up plans for each new address — all now yours. ## Standard vs managed SES sells dedicated IPs two ways, and knowing the difference is the tell that you have used them: - **Standard** — you request the IPs, you own the warm-up plan and the volume distribution, you decide when to add another. - **Managed** — SES handles warm-up automatically and scales the number of IPs to your sending volume, adding and removing capacity as traffic changes. Managed removes most of the reasons a team gets dedicated IPs wrong. If the driver is "we want our own reputation" rather than "we need a specific fixed address to allow-list," managed is usually the better trade. You create a pool and choose the mode at creation time: ``` aws sesv2 create-dedicated-ip-pool \ --pool-name transactional --scaling-mode MANAGED ``` ## Pools and stream isolation A pool is assigned through a configuration set's delivery options, so each sending stream can use its own pool. This is the strongest architectural argument in the whole topic: put password resets and receipts on one pool and bulk marketing on another, and a marketing campaign that draws complaints cannot degrade the address your security email leaves from. Note the limit of that isolation — account-level bounce and complaint rates are still account-level, so a bad marketing stream can still put the whole account under review. Pools isolate *receiver-side IP reputation*, not your standing with AWS. ## When the answer is genuinely yes - Consistent, high daily volume — the order of hundreds of thousands of messages a month, sent steadily rather than in occasional bursts. - A partner or enterprise recipient requires a fixed address to allow-list. - You need hard separation between streams whose reputations must not mix. - You have a team that will actually monitor per-IP reputation and blocklists. If none of those hold, staying shared is the correct engineering answer and saying so confidently is the correct interview answer. ## Instrumenting the decision Whatever you choose, turn on Virtual Deliverability Manager. Its dashboard breaks delivery down by ISP and gives per-configuration-set visibility, and its advisor flags configuration problems — missing authentication, records that would hurt placement. It is how you find out whether an IP change actually helped, instead of arguing about it. Being able to name it, and to say you would measure before and after, is what makes this a principal-level answer rather than an opinion.
- A team sends one large campaign a month and wants dedicated IPs. What do you tell them?That the pattern argues against it. Reputation is a rolling window, so an IP that is idle for three weeks is partly cold when the campaign starts, and the burst then looks like exactly the traffic shape receivers distrust. Shared IPs absorb spiky volume because they stay warm on other traffic. If they need dedicated addresses for another reason, spread the sending across the month.
- What is the difference between standard and managed dedicated IPs in SES?With standard you request the addresses and own the warm-up plan and capacity decisions. With managed, SES performs warm-up automatically and scales the number of IPs to your sending volume. Managed is the better default when the goal is owning your reputation; standard makes sense when you need specific, stable addresses a partner will allow-list.
- Does putting marketing on its own dedicated IP pool protect your transactional mail completely?Only at the receiver's end. Pools isolate IP reputation, so a complaint-heavy campaign does not degrade the address your password resets leave from. But account-level bounce and complaint rates are still account-wide, so a bad marketing stream can still put the entire account under review and pause all sending. Pool separation is a mitigation, not immunity.
- How would you tell whether moving to dedicated IPs actually improved delivery?Instrument first, move second. Enable Virtual Deliverability Manager for per-ISP delivery visibility and per-configuration-set breakdown, and hold a baseline for a few weeks before the change. Then compare the same ISPs on the same stream. Without that, the discussion collapses into anecdote — someone's mail landed in spam once, and nobody can say whether the change helped.
saying these in an interview costs you the question
- Recommending dedicated IPs as the default professional choice
- Sending full volume from a new IP on day one
- Assuming an IP stays warm through long idle periods
- Thinking pool separation shields you from account-level review
- Treating dedicated IPs as a fix for a poor recipient list