Route53

AWS Route 53 manages DNS, with risks including domain hijacking, misconfigured records, and lack of DNS security controls.

Route 53 controls domain resolution. Mismanagement can lead to traffic redirection, outages, or exposure. Strong controls around DNS changes and domain protection are critical.

Route53 Documentation

SPF Record Does Not Start with SPF Statement
low
aws r53

SPF Record Does Not Start with SPF Statement

An SPF record must start with the format v=spf1; otherwise, it will be disregarded.

Private Zones using local TLD
low
aws r53

Private Zones using local TLD

Private VPC Hosted Zone is using .local TLD

MX Records Without Corresponding DKIM Record
moderate
aws r53

MX Records Without Corresponding DKIM Record

Domains used for sending emails should have a corresponding DKIM record that validates the signatures in each official email. This provides clear validation of legitimate emails and helps identify …

MX Records with Multiple Corresponding SPF Records
moderate
aws r53

MX Records with Multiple Corresponding SPF Records

RFC 7208 requires a single SPF record for SPF validation. Multiple records will lead to the disregard of domain checks.

ICANN Domain Status is Pending Deletion
high
aws r53

ICANN Domain Status is Pending Deletion

Domains marked by ICANN as pending deletion will be available for re-registration by third parties within 30 days

ICANN Domain Status is Indicating a Transfer
high
aws r53

ICANN Domain Status is Indicating a Transfer

Domains marked as ‘pendingTransfer’ should have their transfer request confirmed as legitimate or cancelled and the domain locked if not intended

ICANN Domain Status is Inactive
high
aws r53

ICANN Domain Status is Inactive

Domains marked as ‘inactive’ may be missing vital configuration and are effectively useless

ICANN Domain Status has Server Renew Prohibited
critical
aws r53

ICANN Domain Status has Server Renew Prohibited

Domains with the ICANN EPP status serverRenewProhibited cannot be renewed and requires action to rescue the domain or otherwise migrate away from it

ICANN Domain Status has Domain on Hold
advisory
aws r53

ICANN Domain Status has Domain on Hold

A ‘serverHold’ ICANN EPP Status Code can indicate an issue with your domain requiring action

ICANN Domain Status has Domain Deletion Prohibited
advisory
aws r53

ICANN Domain Status has Domain Deletion Prohibited

A domain with the status of “serverDeleteProhibited” prevents a domain from becoming unregistered. This is potentially a lock but may also stem from legal contests and should be determined

Hosted Zones with Default Registrar Comment
advisory
aws r53

Hosted Zones with Default Registrar Comment

Hosted Zones for domains purchased through the Route53 Registrar come with a default comment. This default comment forfeits the opportunity for labelling and control.

Found MX records without corresponding SPF Record
moderate
aws r53

Found MX records without corresponding SPF Record

The Sender Policy Framework (SPF) offers a straightforward method for specifying the origins of valid emails, helping to protect your domain from fraud. Domains without SPF records available face …

Domains Without DMARC Declaration
low
aws r53

Domains Without DMARC Declaration

DMARC policies allow the opportunity to advice external email services how to handle spoofed email for your domain

Domains with Lax DMARC Policies
advisory
aws r53

Domains with Lax DMARC Policies

Lax DMARC policies do not explicitly advertise to mail servers that fraudulent emails should be either quarantined or rejected, guarding your domain’s reputation and allowing for spoofing …

Domains Missing Transfer Lock
moderate
aws r53

Domains Missing Transfer Lock

Domains without a transfer lock are missing a key gating tool preventing the theft or sale of domains

Domains Due to Expire Within 90 Days
high
aws r53

Domains Due to Expire Within 90 Days

Expiring Domains without Autorenew lead to service downtime and signal operational risk. Expired domains can also be captured by malicious parties.

DKIM Records with Small Key Size
high
aws r53

DKIM Records with Small Key Size

DKIM encryption using key sizes under 1024 bits are trivial to brute force. As DKIM DNS records are public, weak email signatures are discoverable