aws-route53 v6.11.0 - Check and enforce DNSSEC signing on public hosted zones

Aug 12, 2026GuardrailsMods

What's new?

  • Added a new DNSSEC Signing control and policy on AWS > Route 53 > Hosted Zone to check or enforce DNSSEC signing on your public hosted zones. DNSSEC adds digital signatures to your DNS records so resolvers can verify responses are authentic, protecting your domains against DNS spoofing and cache poisoning. The policy supports Check: Enabled, Check: Disabled, Enforce: Enabled, and Enforce: Disabled, and private hosted zones are skipped automatically. When enforcement enables signing on a zone that has no active key-signing key, Guardrails creates and activates one using the KMS key you define in the new DNSSEC Signing > Customer Managed Key policy — bring your own key (a single key can serve every hosted zone in the account).
  • Hosted zone CMDB records now include the zone's DNSSEC signing status and key-signing key details, kept current in real time as signing configuration changes.

Control Types

Added

  • AWS > Route 53 > Hosted Zone > DNSSEC Signing

Policy Types

Added

  • AWS > Route 53 > Hosted Zone > DNSSEC Signing
  • AWS > Route 53 > Hosted Zone > DNSSEC Signing > Customer Managed Key

Action Types

Added

  • AWS > Route 53 > Hosted Zone > Update DNSSEC Signing