Glossary

    DNS Security

    Network Security

    DNS Security on AWS covers protecting your DNS infrastructure and using DNS as a security control point.

    Route 53 Security

    • DNSSEC Signing: cryptographic signing of DNS records to prevent spoofing and cache poisoning
    • Private Hosted Zones: DNS resolution only within VPCs, not publicly accessible
    • Route 53 Resolver: DNS resolution between VPCs and on-premises networks

    Route 53 Resolver DNS Firewall

    • Filter outbound DNS queries from your VPCs
    • Block resolution of known malicious domains
    • Prevent DNS-based data exfiltration (DNS tunneling)
    • Use AWS-managed domain lists (malware, botnet C&C) or custom lists

    Best Practices

    • Enable DNSSEC for public hosted zones
    • Use DNS Firewall in all VPCs to block malicious domains
    • Log DNS queries with Route 53 Resolver Query Logging
    • Monitor GuardDuty DNS findings for C&C communication

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.