BYOC, explained without the marketing
BYOC means bring your own cloud. It is a specific architectural choice with two real benefits and two real costs, and this page states all four.
With BYOC you create one IAM role in your own AWS account. SendFleet assumes it with short-lived credentials for the length of a single send, your SES delivers the mail, and your recipients, subjects and bodies never reach our database. Two costs: your SES must be out of the sandbox before it works, and creating the role correctly takes about ten minutes the first time. Everything runs through the same POST /api/send/ endpoint as our managed mode.
What actually differs
| SendFleet | Managed SES | |
|---|---|---|
| What BYOC is | You create one IAM role in your own AWS account. SendFleet assumes it with short-lived credentials for the length of a send. Your SES does the sending. | Not applicable. |
| What we store | A monthly send counter, so the free tier can be enforced. That is it. No recipient, no subject, no body, no attachment, ever. The BYOC branch of the send path has no code that writes them. | Not applicable. |
| Your sender reputation | Entirely in your SES account. No other SendFleet customer can affect it, because no other customer is in your account. | Not applicable. |
| Your sending limits | AWS sets them, and they apply to you. We do not impose a volume ceiling above your own AWS quota on the $9 plan. | Not applicable. |
| The catch: SES sandbox | Your SES must be out of sandbox. A sandbox account can only send to addresses you have verified in the AWS console. You have to request production access from AWS first. | Not applicable. |
| The catch: one IAM role | Creating it correctly takes about ten minutes. The trust policy needs an <code>sts:ExternalId</code> condition that most people miss on the first attempt; the dashboard shows the exact policy with your ExternalId already filled in, and has a "test my role" button that tells you plainly what is wrong. | Not applicable. |
| Email logs and webhooks | Not available on BYOC, and that is a direct consequence of storing nothing. Your own SES console and CloudWatch have the history. | Not applicable. |
Competitor figures read from 2026-10-04. Background on the AWS side: requesting production access, email authentication.
Where we are not the right answer
- **BYOC is not for everyone.** If you would rather not touch IAM at all, Managed plans send from our infrastructure with no AWS setup, from $5 a month, and you get logs and webhooks.
- **If your AWS SES is in the sandbox, BYOC will not send for you yet.** This is the single most common reason a BYOC setup stalls, and it is an AWS approval rather than anything about SendFleet.
- **BYOC and Managed can coexist.** A domain is bound to one mode when you add it, but you can have one of each, on the same endpoint, with the same API key.
Start here
Create a free account. 50 BYOC emails a month, no card, no expiry. Or read the quickstart first.