Memory hook: DNS chooses an answer that clients may cache; it does not inspect or balance every application request.
Must remember
Resolution, records and ownership
- A recursive resolver finds an answer on a client's behalf, following cached information and authoritative DNS as needed. An authoritative hosted zone contains the records for its namespace.
- A maps a name to IPv4; AAAA to IPv6; CNAME to another hostname; NS identifies authoritative name servers; MX identifies mail servers; TXT carries text/verification data; SOA carries zone metadata.
- TTL controls how long a DNS answer may be cached. Lower TTL can improve the responsiveness of future changes but increases queries and cannot instantly invalidate previously cached answers.
- Domain registration and DNS hosting are separate services. A third-party registrar can delegate a domain to Route 53 by using the correct Route 53 name servers. Moving DNS does not necessarily require transferring registration.
- Creating a same-named public hosted zone does not configure delegation; resolvers need the correct authoritative chain.
- A CNAME cannot occupy a zone apex alongside its required SOA/NS records. Route 53 Alias A/AAAA can map an apex to supported targets such as an ALB or CloudFront distribution.
- Alias is an AWS DNS feature with supported target rules, not permission to point any apex record at an arbitrary hostname. Its TTL/health behavior depends on the target.
Every routing policy answers a different question
| Requirement or clue | Routing policy and meaning |
|---|---|
| Ordinary answer for one service | Simple: basic response without specialized selection |
| Gradual rollout or relative distribution | Weighted: choose among records according to relative weights |
| Best response latency among configured Regions | Latency: use measured latency information, not just map distance |
| Primary/standby DNS recovery | Failover: prefer healthy primary, otherwise secondary |
| Country/continent or location-specific content | Geolocation: select by user location; define a default |
| Shift a geographic catchment boundary | Geoproximity: resource/user location with adjustable bias |
| Known client-source CIDR requirements | IP-based: use CIDR collections to choose destinations |
| Several healthy IP answers | Multivalue: return a small set of healthy answers; not a full load balancer |
- Weights are relative, not required to total 100. Resolver caching and client reuse mean a 90/10 policy does not guarantee nine of each ten HTTP requests use one endpoint.
- Latency and geography differ: the geographically nearest endpoint need not have the lowest measured network latency.
- Geolocation is not authorization or residency enforcement; storage locations, cache distribution and access controls need separate policies.
- Geoproximity bias changes the area attracted to a resource; it is not the same as changing an exact percentage weight.
- Traffic Flow can compose visual traffic policies, with separate pricing/management considerations. It is a configuration facility rather than another universal per-request proxy.
Health and failover
- An endpoint health check probes a supported publicly reachable endpoint using its configured protocol and conditions.
- A calculated health check combines child checks using a threshold; a CloudWatch alarm-based health check derives health from supported alarm/metric behavior instead of a direct public probe.
- Route 53 public health checkers cannot directly reach an ordinary private-only IP. A suitable metric/alarm integration is one way to express private resource health.
- Health checks are separate resources and must be correctly associated with the DNS design. Supported Alias targets may provide Evaluate Target Health behavior instead of needing a duplicate direct endpoint probe.
- Failover depends on detection time, DNS answers, resolver caches and application reconnection. A small TTL is not a promise that all clients switch instantly.
- Secondary endpoints still need usable capacity and sufficiently current data; health checks preserve neither transactions nor state.
Private zones and hybrid DNS
- Private hosted zones answer within associated VPCs through the appropriate resolver context. Required VPC DNS attributes, associations and application resolver configuration must be correct.
- Split-view DNS uses the same namespace with different internal and external answers. A private zone can intentionally shadow public names.
- If an associated matching private zone lacks the requested name/type, resolution can return NXDOMAIN, rather than automatically falling back to the public zone.
- Route 53 VPC Resolver is the current name for the VPC service historically called Route 53 Resolver. Its inbound endpoints receive queries from on-premises/other connected networks.
- Outbound endpoints and forwarding rules send matching VPC queries to external DNS servers. Think “inbound to the VPC” and “outbound from the VPC.”
- Endpoints do not create the underlying VPN/Direct Connect route. DNS ports, security groups, routes, forwarding rules and resilient endpoint placement are separate requirements.
- Private zones do not support every public-zone routing policy.
Choose under exam pressure
| Situation | Decision and reason |
|---|---|
| Apex domain must reach an eligible AWS load balancer | Alias A/AAAA, not apex CNAME |
| Keep registrar but use Route 53 DNS | Update authoritative delegation |
| Hybrid clients must resolve AWS private names | Inbound Resolver endpoint and private connectivity |
| VPC clients must resolve corporate names | Outbound endpoint with matching forwarding rules |
| Internal name exists publicly but fails inside VPC | Inspect private-zone shadowing and record/type |
| Exact request-level canary split required | DNS weighting alone cannot guarantee it |
| Private backend needs failover health | Appropriate alarm/metric-based health integration |
Traps
- Resolution is not connectivity. A correct address does not open a firewall or establish a route.
- Caching limits immediate control. DNS updates do not terminate established connections or flush every resolver.
- Private and public evidence differ. A laptop using public DNS cannot prove a VPC-only record is absent.
Active recall
1. A company keeps its domain at another registrar but wants Route 53 routing. Must it buy the domain again?
No. Configure Route 53 records and update authoritative delegation at the existing registrar/parent. DNS hosting and registration are separate services.
2. A 90/10 rollout sends most observed traffic to one deployment during a short test. Does that prove weighted DNS is broken?
No. Small samples, shared caches and connection reuse skew application requests. DNS weights select answers; exact per-request control needs an appropriate application-layer mechanism.
3. A public record resolves on a laptop but returns NXDOMAIN inside a VPC. What hidden configuration can explain it?
A matching private zone may lack the requested record/type without falling back publicly. Inspect private-zone shadowing and forwarding rules before changing public DNS.
4. On-premises clients need private AWS names, while EC2 needs corporate names. Which Resolver directions are required?
Inbound endpoints accept queries into the VPC resolver context; outbound endpoints with forwarding rules send corporate-domain queries out. Both need suitable private connectivity and access rules. Choosing an endpoint direction does not establish the network path.
5. The nearest geographic Region has higher measured latency. Which routing policy follows latency, and which follows location?
Latency routing follows the service's latency information among configured Regions. Geolocation selects by user geography, while geoproximity uses locations and bias. They serve different business requirements; “closest” is not a universal substitute for “fastest.”
Terraform anchor: Record identifiers, routing-policy blocks, health associations and optional hosted zones are separate objects in the dependency graph.
Sources
- Route 53 routing policies — selection policies and their purposes.
- Route 53 Alias versus non-Alias records — supported targets and apex behavior.
- Health-check types — endpoint, calculated and alarm-based checks.
- Private hosted-zone considerations — private resolution, shadowing and policy support.
- Route 53 VPC Resolver — current naming and hybrid query directions.