certslothcertsloth
ANS-C01/Topic 07

AWS / Specialty

Hybrid DNS and Resolver Design

3 min read5 recall promptsReviewed 2026-10-10

Memory hook: Inbound lets external clients ask AWS; outbound lets AWS forward selected questions elsewhere.

Must remember

  • A recursive resolver obtains answers for clients; authoritative servers host zone records. Public delegation uses NS records at the parent. Private hosted-zone answers depend on VPC association and resolver context. A DNS name can have different public and private answers.
  • Route 53 Resolver inbound endpoints accept queries from reachable external networks for the associated resolver context. Outbound endpoints send queries matching forwarding rules to configured target resolvers. Associate/share rules deliberately across VPCs; a network attachment does not automatically share DNS zones.
  • Use multiple endpoint IPs across AZs for availability and allow required UDP/TCP DNS traffic. TCP is needed for cases such as large/truncated responses. Hybrid routing, security groups and return paths are required in addition to DNS configuration.
  • Match the most-specific relevant domain/rule. Avoid forwarding loops such as AWS forwarding a zone on-premises while the on-premises server forwards the same unresolved name back. Split-horizon DNS needs clear ownership and deliberate public/private records.
  • A private zone that matches a queried namespace but lacks the record may return a negative answer rather than falling back to an unrelated public answer. Negative caching and TTL can prolong an apparent failure after a fix. Test from the same network and resolver context as the application.
  • Resolver DNS Firewall filters supported resolver queries. Query logs help identify resolution behaviour; DNSSEC validation verifies supported signed answers, not confidentiality. Encryption in transit and DNS answer authenticity are different requirements.
  • Use dig/nslookup to inspect record type, answer, authority, TTL and status. Trace public delegation where relevant; query the intended resolver directly when diagnosing split DNS. A cached success from your laptop is not proof a workload VPC resolves identically.

Choose under exam pressure

Requirement Choice and reason
On-premises clients resolve AWS private names Inbound Resolver endpoints plus private-zone association and network access.
VPC workloads resolve a corporate suffix Outbound endpoints and a forwarding rule.
Repeated NXDOMAIN after adding a record Inspect negative caching and the queried resolver/zone.

Traps

  • Transit Gateway connectivity alone does not share private hosted zones.
  • DNSSEC does not encrypt DNS traffic.
  • An Alias and a CNAME have different allowed targets and apex behaviour.

Active recall

1. Which direction uses an outbound Resolver endpoint?

Queries leaving the VPC resolver for configured external DNS servers.

2. Why permit TCP as well as UDP 53?

Some DNS responses and protocol operations require TCP, including fallback after truncation.

3. How does a forwarding loop arise?

Resolvers send the same unresolved namespace back to each other.

4. Why test DNS from the workload network?

Private zones, forwarding associations and caches differ across resolver contexts.

5. Does a healthy DNS endpoint guarantee the answer points to a healthy application?

No. Resolution, health-based routing and application health are separate layers.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.