Review service records in a Route 53 hosted zone

Check that a Route 53 hosted zone contains the DNS records required by its services.

Description

Creating an AWS::Route53::HostedZone creates default NS and SOA records, but does not automatically connect an application’s domain name to its service endpoint. Manage the required A, CNAME, or other records separately.

Potential impact

Missing records or incorrect targets can prevent users from reaching a service by its DNS name.

Remediation

Check that required records point to the intended targets and manage changes with resources such as AWS::Route53::RecordSet or AWS::Route53::RecordSetGroup. If another stack or tool manages the records, retain clear ownership and avoid duplicate creation. For a public zone, also verify name server delegation from the parent domain.

Examples

Supply a domain you own. Supply the zone name without a trailing dot as HostedZoneName, a subdomain label such as www as DomainName, and the actual target hostname as DnsEndpoint. The revised record belongs to the created HostedZone.

Before

yaml
Parameters:
  HostedZoneName:
    Type: String
Resources:
  HostedZone:
    Type: AWS::Route53::HostedZone
    Properties:
      Name: !Ref HostedZoneName

After

yaml
Parameters:
  HostedZoneName:
    Type: String
  DomainName:
    Type: String
  DnsEndpoint:
    Type: String
Resources:
  HostedZone:
    Type: AWS::Route53::HostedZone
    Properties:
      Name: !Ref HostedZoneName
  RecordSet:
    Type: AWS::Route53::RecordSet
    Properties:
      HostedZoneId: !Ref HostedZone
      Name: !Sub '${DomainName}.${HostedZoneName}.'
      Type: CNAME
      TTL: '900'
      ResourceRecords:
        - !Ref DnsEndpoint

References