Sendy/Amazon SES Fix & Secure Cleanup
Budget: $30 – $250 USD
Project Title
Urgent Fix: Sendy + Amazon SES “Sending stuck” on Contabo VPS (Cloudflare DNS/WAF) + Secure Cleanup
Background
We run a self-hosted Sendy installation on a Contabo VPS (Ubuntu) using Amazon SES (API). DNS/proxy/WAF is managed via Cloudflare.
Recently, campaigns get stuck in “Sending” and emails are not being delivered (or campaigns remain queued). This setup worked correctly until recently.
Tech Stack
VPS: Contabo (Ubuntu)
App: Sendy (self-hosted)
Email: Amazon SES (us-east-1 / N. Virginia)
DNS/WAF/Proxy: Cloudflare
Web server: Unknown (Nginx or Apache) — must confirm during diagnosis
PHP + MySQL/MariaDB
Goal
Restore normal sending and ensure the system is stable, monitorable, and secure. Provide documentation of what was changed.
Scope of Work (Must Do)
1) Sendy Sending Engine / Cron / Queue
Audit current cronjobs (crontab for root/www-data + /etc/cron.*) and confirm whether Sendy’s scheduler is running properly.
Fix “stuck sending” by ensuring the correct execution of Sendy scheduling mechanism.
Preferred approach: Run Sendy schedule via CLI (e.g., php /path/to/sendy/schedule.php) instead of calling a URL through Cloudflare.
Confirm campaigns move from “Sending” to “Sent” and that emails are actually delivered.
2) Server Diagnostics
Check web server + PHP logs for errors/timeouts (Nginx/Apache, PHP-FPM, syslog).
Confirm PHP version and required extensions for Sendy.
Validate permissions, file paths, and any required services running.
3) Amazon SES Verification
Validate IAM credentials and required permissions for SES.
Verify SES quota, throttling, sandbox vs production status.
Check bounce/complaint/suppression indicators if relevant.
4) Cloudflare Checks (Important)
Verify Cloudflare is not blocking or challenging any endpoint used by the cron/trigger (WAF/Bot Protection/Rate limiting).
If any URL-trigger must remain, create a secure Cloudflare exception for that specific endpoint (least exposure).
Best solution remains: CLI cron execution with no dependency on Cloudflare.
5) Deliverability Basics
Validate SPF/DKIM/DMARC are not broken (only fix if misconfigured; no full deliverability consulting required).
Deliverables
Working sending flow (test email + successful small campaign).
Correct cron configuration documented (exact cron line and schedule).
Summary of changes made (files edited, services restarted, commands used).
Short troubleshooting checklist for future incidents.
Access & Security Requirements (Non-Negotiable)
To be considered, you must agree to the following:
Temporary Access Only
Access will be provided via SSH key or temporary user.
No permanent credentials will be shared.
No Data Exfiltration
You may not copy, export, download, or store subscriber lists, campaign content, or any sensitive business data outside the server.
Access Removal & Cleanup Clause
Immediately upon completion and confirmation of deliverables, you must:
Remove any SSH keys you added
Remove any temporary users you created
Remove any tokens, API keys, or credentials stored locally on your machine
Revert any firewall allowlists created specifically for your IP (unless explicitly requested to keep)
You must provide a written confirmation that all access paths and stored credentials have been deleted.
Credential Hygiene
If any AWS keys were used or revealed during the work, you must support key rotation and ensure old keys are disabled/deleted.
Required Experience
Proven experience with Sendy + Amazon SES troubleshooting
Strong Linux admin skills (cron, PHP, Nginx/Apache, MySQL)
Ability to document changes clearly
When Applying, Answer These 4 Questions
Have you fixed “Sendy stuck on Sending” before? Describe briefly.
What are the first 5 things you would check on the VPS?
Do you recommend CLI cron execution over URL triggers behind Cloudflare? Why?
Your pricing: fixed cost for diagnosis+fix + optional monthly maintenance rate.
Urgent Fix: Sendy + Amazon SES “Sending stuck” on Contabo VPS (Cloudflare DNS/WAF) + Secure Cleanup
Background
We run a self-hosted Sendy installation on a Contabo VPS (Ubuntu) using Amazon SES (API). DNS/proxy/WAF is managed via Cloudflare.
Recently, campaigns get stuck in “Sending” and emails are not being delivered (or campaigns remain queued). This setup worked correctly until recently.
Tech Stack
VPS: Contabo (Ubuntu)
App: Sendy (self-hosted)
Email: Amazon SES (us-east-1 / N. Virginia)
DNS/WAF/Proxy: Cloudflare
Web server: Unknown (Nginx or Apache) — must confirm during diagnosis
PHP + MySQL/MariaDB
Goal
Restore normal sending and ensure the system is stable, monitorable, and secure. Provide documentation of what was changed.
Scope of Work (Must Do)
1) Sendy Sending Engine / Cron / Queue
Audit current cronjobs (crontab for root/www-data + /etc/cron.*) and confirm whether Sendy’s scheduler is running properly.
Fix “stuck sending” by ensuring the correct execution of Sendy scheduling mechanism.
Preferred approach: Run Sendy schedule via CLI (e.g., php /path/to/sendy/schedule.php) instead of calling a URL through Cloudflare.
Confirm campaigns move from “Sending” to “Sent” and that emails are actually delivered.
2) Server Diagnostics
Check web server + PHP logs for errors/timeouts (Nginx/Apache, PHP-FPM, syslog).
Confirm PHP version and required extensions for Sendy.
Validate permissions, file paths, and any required services running.
3) Amazon SES Verification
Validate IAM credentials and required permissions for SES.
Verify SES quota, throttling, sandbox vs production status.
Check bounce/complaint/suppression indicators if relevant.
4) Cloudflare Checks (Important)
Verify Cloudflare is not blocking or challenging any endpoint used by the cron/trigger (WAF/Bot Protection/Rate limiting).
If any URL-trigger must remain, create a secure Cloudflare exception for that specific endpoint (least exposure).
Best solution remains: CLI cron execution with no dependency on Cloudflare.
5) Deliverability Basics
Validate SPF/DKIM/DMARC are not broken (only fix if misconfigured; no full deliverability consulting required).
Deliverables
Working sending flow (test email + successful small campaign).
Correct cron configuration documented (exact cron line and schedule).
Summary of changes made (files edited, services restarted, commands used).
Short troubleshooting checklist for future incidents.
Access & Security Requirements (Non-Negotiable)
To be considered, you must agree to the following:
Temporary Access Only
Access will be provided via SSH key or temporary user.
No permanent credentials will be shared.
No Data Exfiltration
You may not copy, export, download, or store subscriber lists, campaign content, or any sensitive business data outside the server.
Access Removal & Cleanup Clause
Immediately upon completion and confirmation of deliverables, you must:
Remove any SSH keys you added
Remove any temporary users you created
Remove any tokens, API keys, or credentials stored locally on your machine
Revert any firewall allowlists created specifically for your IP (unless explicitly requested to keep)
You must provide a written confirmation that all access paths and stored credentials have been deleted.
Credential Hygiene
If any AWS keys were used or revealed during the work, you must support key rotation and ensure old keys are disabled/deleted.
Required Experience
Proven experience with Sendy + Amazon SES troubleshooting
Strong Linux admin skills (cron, PHP, Nginx/Apache, MySQL)
Ability to document changes clearly
When Applying, Answer These 4 Questions
Have you fixed “Sendy stuck on Sending” before? Describe briefly.
What are the first 5 things you would check on the VPS?
Do you recommend CLI cron execution over URL triggers behind Cloudflare? Why?
Your pricing: fixed cost for diagnosis+fix + optional monthly maintenance rate.