certslothcertsloth
SAP-C02/Topic 08

AWS / Professional

Route 53

7 min read5 recall promptsReviewed 2026-10-10

Memory hook: DNS chooses an answer that clients may cache; it does not inspect or balance every application request.

Must remember

Resolution, records and ownership

  • A recursive resolver finds an answer on a client's behalf, following cached information and authoritative DNS as needed. An authoritative hosted zone contains the records for its namespace.
  • A maps a name to IPv4; AAAA to IPv6; CNAME to another hostname; NS identifies authoritative name servers; MX identifies mail servers; TXT carries text/verification data; SOA carries zone metadata.
  • TTL controls how long a DNS answer may be cached. Lower TTL can improve the responsiveness of future changes but increases queries and cannot instantly invalidate previously cached answers.
  • Domain registration and DNS hosting are separate services. A third-party registrar can delegate a domain to Route 53 by using the correct Route 53 name servers. Moving DNS does not necessarily require transferring registration.
  • Creating a same-named public hosted zone does not configure delegation; resolvers need the correct authoritative chain.
  • A CNAME cannot occupy a zone apex alongside its required SOA/NS records. Route 53 Alias A/AAAA can map an apex to supported targets such as an ALB or CloudFront distribution.
  • Alias is an AWS DNS feature with supported target rules, not permission to point any apex record at an arbitrary hostname. Its TTL/health behavior depends on the target.

Every routing policy answers a different question

Requirement or clue Routing policy and meaning
Ordinary answer for one service Simple: basic response without specialized selection
Gradual rollout or relative distribution Weighted: choose among records according to relative weights
Best response latency among configured Regions Latency: use measured latency information, not just map distance
Primary/standby DNS recovery Failover: prefer healthy primary, otherwise secondary
Country/continent or location-specific content Geolocation: select by user location; define a default
Shift a geographic catchment boundary Geoproximity: resource/user location with adjustable bias
Known client-source CIDR requirements IP-based: use CIDR collections to choose destinations
Several healthy IP answers Multivalue: return a small set of healthy answers; not a full load balancer
  • Weights are relative, not required to total 100. Resolver caching and client reuse mean a 90/10 policy does not guarantee nine of each ten HTTP requests use one endpoint.
  • Latency and geography differ: the geographically nearest endpoint need not have the lowest measured network latency.
  • Geolocation is not authorization or residency enforcement; storage locations, cache distribution and access controls need separate policies.
  • Geoproximity bias changes the area attracted to a resource; it is not the same as changing an exact percentage weight.
  • Traffic Flow can compose visual traffic policies, with separate pricing/management considerations. It is a configuration facility rather than another universal per-request proxy.

Health and failover

  • An endpoint health check probes a supported publicly reachable endpoint using its configured protocol and conditions.
  • A calculated health check combines child checks using a threshold; a CloudWatch alarm-based health check derives health from supported alarm/metric behavior instead of a direct public probe.
  • Route 53 public health checkers cannot directly reach an ordinary private-only IP. A suitable metric/alarm integration is one way to express private resource health.
  • Health checks are separate resources and must be correctly associated with the DNS design. Supported Alias targets may provide Evaluate Target Health behavior instead of needing a duplicate direct endpoint probe.
  • Failover depends on detection time, DNS answers, resolver caches and application reconnection. A small TTL is not a promise that all clients switch instantly.
  • Secondary endpoints still need usable capacity and sufficiently current data; health checks preserve neither transactions nor state.

Private zones and hybrid DNS

  • Private hosted zones answer within associated VPCs through the appropriate resolver context. Required VPC DNS attributes, associations and application resolver configuration must be correct.
  • Split-view DNS uses the same namespace with different internal and external answers. A private zone can intentionally shadow public names.
  • If an associated matching private zone lacks the requested name/type, resolution can return NXDOMAIN, rather than automatically falling back to the public zone.
  • Route 53 VPC Resolver is the current name for the VPC service historically called Route 53 Resolver. Its inbound endpoints receive queries from on-premises/other connected networks.
  • Outbound endpoints and forwarding rules send matching VPC queries to external DNS servers. Think “inbound to the VPC” and “outbound from the VPC.”
  • Endpoints do not create the underlying VPN/Direct Connect route. DNS ports, security groups, routes, forwarding rules and resilient endpoint placement are separate requirements.
  • Private zones do not support every public-zone routing policy.

Choose under exam pressure

Situation Decision and reason
Apex domain must reach an eligible AWS load balancer Alias A/AAAA, not apex CNAME
Keep registrar but use Route 53 DNS Update authoritative delegation
Hybrid clients must resolve AWS private names Inbound Resolver endpoint and private connectivity
VPC clients must resolve corporate names Outbound endpoint with matching forwarding rules
Internal name exists publicly but fails inside VPC Inspect private-zone shadowing and record/type
Exact request-level canary split required DNS weighting alone cannot guarantee it
Private backend needs failover health Appropriate alarm/metric-based health integration

Traps

  • Resolution is not connectivity. A correct address does not open a firewall or establish a route.
  • Caching limits immediate control. DNS updates do not terminate established connections or flush every resolver.
  • Private and public evidence differ. A laptop using public DNS cannot prove a VPC-only record is absent.

Active recall

1. A company keeps its domain at another registrar but wants Route 53 routing. Must it buy the domain again?

No. Configure Route 53 records and update authoritative delegation at the existing registrar/parent. DNS hosting and registration are separate services.

2. A 90/10 rollout sends most observed traffic to one deployment during a short test. Does that prove weighted DNS is broken?

No. Small samples, shared caches and connection reuse skew application requests. DNS weights select answers; exact per-request control needs an appropriate application-layer mechanism.

3. A public record resolves on a laptop but returns NXDOMAIN inside a VPC. What hidden configuration can explain it?

A matching private zone may lack the requested record/type without falling back publicly. Inspect private-zone shadowing and forwarding rules before changing public DNS.

4. On-premises clients need private AWS names, while EC2 needs corporate names. Which Resolver directions are required?

Inbound endpoints accept queries into the VPC resolver context; outbound endpoints with forwarding rules send corporate-domain queries out. Both need suitable private connectivity and access rules. Choosing an endpoint direction does not establish the network path.

5. The nearest geographic Region has higher measured latency. Which routing policy follows latency, and which follows location?

Latency routing follows the service's latency information among configured Regions. Geolocation selects by user geography, while geoproximity uses locations and bias. They serve different business requirements; “closest” is not a universal substitute for “fastest.”

Terraform anchor: Record identifiers, routing-policy blocks, health associations and optional hosted zones are separate objects in the dependency graph.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.