How to Self-Host a Newsletter With Listmonk and Amazon SES
Run your own newsletter on listmonk and Amazon SES for under 30 dollars a month at 25,000 subscribers. Full 2026 setup: Docker deploy, SES domain verification, sandbox removal, bounce webhooks, and honest limits.

Mailchimp and its peers charge you more every time your list grows, even if you send the same number of emails. A self-hosted stack of listmonk for list management and Amazon SES for delivery replaces that per-contact bill with a small VPS and per-email pricing, and the whole thing takes an afternoon to set up. This guide walks through the full production path: Docker deployment, SES domain verification, leaving the sandbox, bounce webhooks, and what it actually costs in 2026.
One warning up front: most setup guides for this stack were written before mid-2026 and quote Amazon SES at a flat $0.10 per 1,000 emails. SES pricing changed in July 2026. The current numbers are below, and they are still very cheap.
What listmonk is and what it is not
listmonk is a free, open-source newsletter and mailing list manager licensed under AGPLv3. It ships as a single Go binary with a PostgreSQL database as its only dependency, and the project is actively maintained with more than 23,000 GitHub stars as of late 2026. You get subscriber lists, segmentation, campaigns, templates, a transactional email API, and bounce processing in one dashboard.
Know the boundaries before you commit:
- It is a one-way tool. Newsletters and announcements go out; it is not a helpdesk or a marketing automation suite. There is no visual journey builder, no drag-and-drop drip sequences.
- It does not send email itself. listmonk hands mail to an SMTP relay. Your deliverability is decided by the relay you choose and the DNS records you set, not by listmonk.
- Automation comes from outside. The transactional API and webhooks are the integration points. If you want "subscriber joins list, wait two days, send follow-up", you build that in a workflow tool like n8n against the API, or use our business automation service to wire it up.
If you need complex visual automation, a managed platform is the better tool and you should pay for it. If your need is "send a good newsletter to a growing list without the bill growing faster than the list", read on.
What the stack costs in 2026
Amazon moved SES from pure pay-as-you-go to a plan model in 2026. Per the current SES pricing page:
- Essentials plan: $0.16 per 1,000 emails for the first 10 million a month. New SES accounts, and accounts with no metered SES activity since June 1, 2025, are placed on this plan from July 21, 2026.
- À la carte pricing: still available, and you can switch to it at any time. $0.10 per 1,000 emails outbound, plus $0.12 per GB of attachment data.
- Dedicated IP (standard): $24.95 per month per IP, optional. You do not need one at newsletter volumes.
Worked example, using AWS's own arithmetic. You have 25,000 subscribers and send four campaigns a month: 100,000 emails.
- On Essentials: 100 x $0.16 = $16.00 per month in SES fees.
- On à la carte: 100 x $0.10 = $10.00 per month.
- AWS's published example puts 250,000 emails on Essentials at $40.96 all-in, which confirms the per-1,000 math.
- VPS for listmonk: a 1 vCPU, 1-2 GB RAM machine runs listmonk and Postgres comfortably at this scale. Budget roughly $5 to $15 a month depending on provider. We break down server sizing in Self-Hosting Your Business Stack: Server Sizes and Real Costs.
Total: $15 to $30 a month for a 25,000-subscriber newsletter you fully own.
The comparison point: Mailchimp's Standard plan starts at $20 a month for just 500 contacts and scales by contact count; third-party pricing trackers put Standard around $230 a month at 15,000 contacts (September 2026). We ran the full 25,000-subscriber comparison in Listmonk vs Mailchimp: Real Email Cost at 25,000 Subscribers. The short version: the managed platform costs 10x or more at this size, and the gap widens every time your list grows.
Step 1: Deploy listmonk with Docker Compose
You need a Linux VPS (Ubuntu 22.04 or 24.04), a domain you can edit DNS for, and an AWS account. Thirty to sixty minutes of work if you have used Docker before.
On the server:
mkdir listmonk && cd listmonk
curl -LO https://github.com/knadh/listmonk/raw/master/docker-compose.yml
docker compose up -d
The compose file starts two containers: Postgres and the listmonk app, which listens on port 9000. Two production notes:
- Do not expose port 9000 to the internet. Bind it to localhost and put a reverse proxy (Caddy or Nginx) in front with a real TLS certificate. Caddy is the path of least resistance: point
newsletter.yourdomain.comat the server, add one block to the Caddyfile reverse-proxying tolocalhost:9000, and HTTPS is handled. - Finish the web installer immediately. The first visit to the admin URL creates the admin account. An unconfigured listmonk on a public URL is an open invitation.
If you prefer the binary over Docker, the flow is ./listmonk --new-config, edit config.toml, then ./listmonk --install. The --upgrade flag runs idempotent database migrations on later updates.
Step 2: Connect Amazon SES and verify your domain
This is the most consequential choice in the build. listmonk will happily send through any SMTP relay, but SES is the cheapest credible option at volume.
- Create an IAM user with a tight policy:
ses:SendRawEmailandses:GetSendQuota. Do not reuse your root credentials or a broad admin policy for a newsletter box. - Verify your sending domain in the SES console. SES gives you DKIM CNAME records to add at your DNS provider. Do this before anything else; a verified domain also speeds up sandbox removal later.
- Generate SMTP credentials from the SES SMTP settings panel. These are a separate SMTP-specific username and password, not your IAM access keys.
- Add the SMTP server in listmonk under Settings -> SMTP:
- Host:
email-smtp.<your-region>.amazonaws.com - Port:
587 - Auth protocol:
LOGIN - TLS:
STARTTLS
- Host:
Port matters. SES requires STARTTLS on 587. If you use port 465 or leave TLS off, SES answers with 530 Must issue a STARTTLS command first, and the credential test in the admin panel can still misleadingly report success. Send a real test campaign to an inbox you control before trusting the setup.
Note that listmonk does not sign DKIM itself; the relay does. Your job is the DNS records: the DKIM CNAMEs from SES, an SPF record that includes SES, and a DMARC policy on the sending domain. Skip DMARC and Gmail will increasingly route you to spam.
Step 3: Get out of the SES sandbox
Every new SES account starts in the sandbox, per region. Per AWS's sandbox documentation, sandbox accounts can only send to verified addresses, and are capped at 200 messages per 24 hours and 1 message per second. That is useless for a real list.
Request production access from the SES Account dashboard. The form asks whether your mail is mostly marketing or transactional, what your sending volume looks like, and how you handle bounces and complaints. Answer concretely: mention that you run double opt-in, that bounce and complaint events flow back into listmonk automatically (the next step), and that you honour unsubscribes. Approval typically takes about a business day, but rejections happen, so do this before you migrate a list, not after.
One EC2 footnote: if your VPS is on AWS, port 25 is throttled by default and needs a separate removal request. Sending to SES over port 587 avoids that entirely.
Step 4: Wire bounce and complaint webhooks
This step is what separates a durable setup from one that gets its AWS account paused. AWS actively tracks your bounce and complaint rates and will review or suspend sending if they stay high. You want bad addresses blocklisted automatically, on the first hard bounce.
listmonk has a native SES webhook. Per the official bounce-processing docs:
- In listmonk Settings -> Bounces: enable bounce processing and bounce webhooks. A sane starting policy is soft bounce count 2 with no action, hard bounce count 1 with Blocklist, complaint count 1 with Blocklist.
- In AWS, create an SNS topic (for example
ses-bounces) with an HTTPS subscription pointing athttps://newsletter.yourdomain.com/webhooks/service/ses, with raw message delivery disabled. listmonk confirms the subscription automatically. - On each verified identity in SES, edit Feedback notifications and set both Bounce feedback and Complaint feedback to that SNS topic, with original email headers included.
- Test with the SES simulator addresses before going live: add
bounce@simulator.amazonses.com(hard bounce),ooto@simulator.amazonses.com(soft bounce), andcomplaint@simulator.amazonses.com(complaint) as subscribers, send a test campaign, and confirm the blocklist actions fire.
Why webhooks and not the simpler POP3 bounce mailbox: listmonk's POP3 scanner treats every message in the bounce inbox as a bounce, including vacation replies and out-of-office notices, so your reported bounce rate inflates far above what SES actually sees. The Cloudzy setup guide documents this gap well. Webhook bounces are exact.
Keeping it running: updates, backups and list hygiene
The ongoing work is small but real. This is the honest trade for the 10x cost saving, the same trade we describe in The Real Cost of Replacing SaaS With an Open Source Stack.
- Backups: your entire state is the Postgres database plus the uploads directory. A nightly
pg_dumpto object storage covers you. Test a restore once. - Updates:
docker compose pull && docker compose up -d. Database migrations run automatically and idempotently on startup. Read the release notes first, as with any self-hosted tool. - Reputation monitoring: check the SES reputation dashboard weekly at first, or set CloudWatch alarms on bounce and complaint metrics. Catch a bad import before AWS catches it for you.
- List hygiene: import only confirmed, opted-in addresses. The fastest way to burn a new SES account is importing a purchased or scraped list and tripping spamtraps.
If you would rather not own the pager for this, operating exactly this stack is what our managed open-source stack service does: we deploy listmonk, wire SES or another relay, handle updates, backups and deliverability monitoring, and hand you the dashboard.
When this stack is the wrong choice
Be honest with yourself on these before migrating:
- You need visual marketing automation. Multi-step drip journeys with branching logic are not what listmonk does. Mailchimp, Brevo, or Customer.io earn their fee here.
- Your volume is tiny. Under roughly 10,000 emails a month, a managed free tier costs less than the VPS plus your setup time. Self-hosting starts paying off above that line.
- Nobody on the team can own a server. An unpatched, unmonitored box is worse than a Mailchimp invoice. Either have someone who can run it, or pay someone to run it.
- Your list is cold or purchased. SES will suspend you, and unlike Mailchimp, AWS suspensions can affect other workloads on the same account if you are careless. Keep SES in its own AWS account if your organization runs anything else on AWS.
Common mistakes to avoid
- Sending before production access is granted. The sandbox caps you at 200 messages a day to verified addresses only; a real campaign will silently fail for most recipients.
- Using port 465 or skipping STARTTLS. The admin test can pass while real sends fail. Always send a live test email.
- Relying on POP3 bounce scanning. It counts out-of-office replies as bounces and poisons your list with false positives. Use the SNS webhook.
- Skipping DMARC. DKIM alone is no longer enough for reliable inbox placement at Gmail.
- Buying a dedicated IP too early. At $24.95 a month per IP, a dedicated IP with low, irregular volume never warms up and can hurt more than the shared pool. SES shared IP reputation is fine well past 100,000 emails a month.
- Migrating the list before testing bounces. One bad legacy list can get a fresh SES account reviewed in its first week.
Frequently asked questions
Is listmonk really free? The software is free under the AGPLv3 license with no subscriber or campaign limits. You pay for the server it runs on and the SMTP relay that sends the mail, which is where the $15 to $30 a month figure in this guide comes from.
How many subscribers can listmonk handle? Far more than most newsletters will ever have. It is built by Zerodha, an Indian stockbroker that sends to millions of subscribers, and a 1 vCPU, 2 GB RAM server handles lists in the low hundreds of thousands when paired with SES. The relay rate limit, not listmonk, is usually the bottleneck.
What if AWS rejects my production access request? It happens, usually when the use-case description is vague. Resubmit with specifics: list source, opt-in method, expected volume, and your bounce handling. If SES stays closed to you, Postmark, Brevo, and Mailgun all work as listmonk relays over the same SMTP settings, at higher per-email cost.
Can I send transactional email through the same setup? Yes. listmonk has a transactional API for templated one-to-one messages like password resets or receipts. Keep transactional and marketing streams on separate subdomains so a marketing complaint spike never touches your receipts.
Does self-hosting hurt deliverability? No, because deliverability lives at the relay and DNS layer, not the app layer. A properly configured SES domain with DKIM, SPF, DMARC, and working bounce processing delivers as well as any managed platform, because the mail physically comes from Amazon's infrastructure either way.
Can I migrate my existing Mailchimp list? Yes. Export subscribers as CSV from Mailchimp and import them in listmonk, mapping custom fields to subscriber attributes. Only import contacts with a recorded opt-in, and send a re-confirmation campaign first if the list is old.
Where to go from here
If your newsletter bill is growing faster than your list, this stack is the highest-leverage change you can make: an afternoon of setup, under $30 a month at 25,000 subscribers, and full ownership of your subscriber data. If you want it done for you, we deploy and operate listmonk alongside Twenty, Chatwoot, Cal.com, Plausible, and Formbricks as part of our managed open-source stack service - book a call and we will tell you plainly whether self-hosting makes sense for your list.
About AI Agents Plus Editorial
AI automation expert and thought leader in business transformation through artificial intelligence.



