amazonaws.com sub-domain delegation and resolution

0

A customer is currently in the process of approving R53 Resolver for use in their organization. Their current design is to resolve all *amazonaws.com sub-domains on AWS using a R53 Resolver system rule shared with spoke VPCs. Everything else is forwarded to on-premises resolvers via a dot rule.

They have a concern around data exfiltration using encoded DNS queries to "malicious" AWS sub-domains. I am confident this is not a concern for the following reasons but need some confirmation that I can make this statement to the customer:

  1. *amazonaws.com sub-domains are never delegated to a non-AWS entity/3rd party.
  2. *amazonaws.com sub-domains are only authoritatively resolved on Amazon owned Name Servers.

Are both of these statements correct?

Thank you.

AWS
已提問 4 年前檢視次數 372 次
1 個回答
0
已接受的答案

Former Route 53 DNS here.

Your assumptions are correct. Those are not allowed by policy but sometimes a dangling CNAME or delegation can happen albeit rarely.

已回答 4 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南