Home icon

Improving security and performance with additional DNS resource record types in Amazon Route 53

Networking & Content Delivery Blog



This article discusses four new DNS resource record types added to Amazon Route 53: SVCB, HTTPS, TLSA, and SSHFP. These record types allow additional data to be supplied through DNS responses to improve application security and performance.

Specifically, the article covers:

  • SVCB and HTTPS records - Allowing application owners to bind endpoint-specific information into DNS replies, enabling improved performance for protocols like HTTP/3 and encrypted client hello support.
  • TLSA record - Supporting DNS-based Authentication of Named Entities (DANE) for improved TLS certificate validation through DNS, particularly useful for SMTP over TLS.
  • SSHFP record - Providing SSH fingerprints in DNS responses, allowing clients to validate SSH server keys against trusted fingerprints for enhanced security.
  • Conclusion - Get started with these new record types in Amazon Route 53 to improve application security and performance.


Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Oct 30
2024
Amazon Route 53 announces HTTPS, SSHFP, SVCB, and TLSA DNS resource record support
Nov 15
2024
Introducing Amazon Route 53 Resolver DNS Firewall Advanced
Jul 24
2024
DNS best practices for Amazon Route 53
Sep 2
2025
Protect your Amazon Route 53 DNS zones and records

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.