Description
Creating an AWS::Route53::HostedZone creates default NS and SOA records, but does not automatically connect an application’s domain name to its service endpoint. Manage the required A, CNAME, or other records separately.
Potential impact
Missing records or incorrect targets can prevent users from reaching a service by its DNS name.
Remediation
Check that required records point to the intended targets and manage changes with resources such as AWS::Route53::RecordSet or AWS::Route53::RecordSetGroup. If another stack or tool manages the records, retain clear ownership and avoid duplicate creation. For a public zone, also verify name server delegation from the parent domain.
Examples
Supply a domain you own. Supply the zone name without a trailing dot as HostedZoneName, a subdomain label such as www as DomainName, and the actual target hostname as DnsEndpoint. The revised record belongs to the created HostedZone.
Before
Parameters:
HostedZoneName:
Type: String
Resources:
HostedZone:
Type: AWS::Route53::HostedZone
Properties:
Name: !Ref HostedZoneName
After
Parameters:
HostedZoneName:
Type: String
DomainName:
Type: String
DnsEndpoint:
Type: String
Resources:
HostedZone:
Type: AWS::Route53::HostedZone
Properties:
Name: !Ref HostedZoneName
RecordSet:
Type: AWS::Route53::RecordSet
Properties:
HostedZoneId: !Ref HostedZone
Name: !Sub '${DomainName}.${HostedZoneName}.'
Type: CNAME
TTL: '900'
ResourceRecords:
- !Ref DnsEndpoint