aws-route53 v6.11.0 - Check and enforce DNSSEC signing on public hosted zones
Aug 12, 2026•GuardrailsMods
What's new?
- Added a new DNSSEC Signing control and policy on AWS > Route 53 > Hosted Zone to check or enforce DNSSEC signing on your public hosted zones. DNSSEC adds digital signatures to your DNS records so resolvers can verify responses are authentic, protecting your domains against DNS spoofing and cache poisoning. The policy supports Check: Enabled, Check: Disabled, Enforce: Enabled, and Enforce: Disabled, and private hosted zones are skipped automatically. When enforcement enables signing on a zone that has no active key-signing key, Guardrails creates and activates one using the KMS key you define in the new DNSSEC Signing > Customer Managed Key policy — bring your own key (a single key can serve every hosted zone in the account).
- Hosted zone CMDB records now include the zone's DNSSEC signing status and key-signing key details, kept current in real time as signing configuration changes.
Control Types
Added
- AWS > Route 53 > Hosted Zone > DNSSEC Signing
Policy Types
Added
- AWS > Route 53 > Hosted Zone > DNSSEC Signing
- AWS > Route 53 > Hosted Zone > DNSSEC Signing > Customer Managed Key
Action Types
Added
- AWS > Route 53 > Hosted Zone > Update DNSSEC Signing