Amazon Route 53
Amazon Route 53 is AWS's highly available DNS service, domain registrar and health-checking service. Its routing policies make it a core building block for availability, latency optimisation and disaster recovery.
DNS in brief
DNS translates names (shop.example.com) into IP addresses. A hosted zone holds the records for a domain:
- Public hosted zone — answers queries from the internet.
- Private hosted zone — answers only within associated VPCs (internal names like
db.internal.example.com).
Common record types
| Type | Maps |
|---|---|
| A / AAAA | Name → IPv4 / IPv6 address |
| CNAME | Name → another name (not allowed at the zone apex, e.g. example.com) |
| MX | Mail servers |
| TXT | Text, e.g. domain verification |
| NS / SOA | Delegation and zone authority |
TTL (time to live) controls how long resolvers cache an answer — lower TTLs make changes and failovers take effect faster, at the cost of more queries.
Alias records
An AWS-specific extension that points a name at an AWS resource:
- Works at the zone apex (
example.com→ load balancer) — CNAME can't. - Targets: ELB, CloudFront, API Gateway, S3 website endpoints, Global Accelerator, other Route 53 records, VPC interface endpoints, and more.
- No charge for alias queries to AWS resources.
- Automatically follows the resource's IP changes.
Pointing the root domain at a load balancer or CloudFront distribution → alias record.
Routing policies
| Policy | Behaviour | Typical use |
|---|---|---|
| Simple | One record, one or more values (random order) | Single resource |
| Weighted | Split traffic by weight (e.g. 90/10) | Canary releases, A/B tests, gradual migrations |
| Latency | Route to the Region with lowest latency for the user | Multi-Region apps for performance |
| Failover | Primary/secondary based on health checks | Active-passive DR |
| Geolocation | Route by the user's continent/country/state | Localised content, legal restrictions |
| Geoproximity | Route by geographic distance, with a bias to shift traffic | Fine-grained geographic traffic shifting (uses traffic flow) |
| IP-based | Route by the client's source IP ranges (CIDRs) | Route known networks/ISPs to specific endpoints |
| Multivalue answer | Return up to several healthy records | Simple client-side load balancing with health checks |
Health checks
- Monitor an endpoint (HTTP/HTTPS/TCP) from locations worldwide.
- Calculated health checks combine others (e.g. healthy if 2 of 3 are healthy).
- Monitor a CloudWatch alarm — useful for private resources that Route 53 health checkers can't reach.
- Combined with failover, weighted, latency and other policies to stop routing to unhealthy endpoints.
DNS failover for disaster recovery
example.com → Failover policy
├── Primary: ALB in ap-south-1 (health check)
└── Secondary: ALB in eu-west-1 (or S3 static "maintenance" site)
When the primary's health check fails, Route 53 answers with the secondary.
Domain registration
Route 53 can register domains and automatically create a hosted zone. Domains registered elsewhere can still use Route 53 by updating the registrar's name servers to the hosted zone's NS records.
Exam patterns
- "Send users to the closest Region for the best performance" → latency routing.
- "Shift 10% of traffic to a new version" → weighted routing.
- "Show a static error page from S3 if the main site is down" → failover routing with health checks.
- "Content must only be served to users in specific countries" → geolocation routing (or CloudFront geo restriction).
- "Resolve on-premises hostnames from the VPC" → Route 53 Resolver outbound endpoint with forwarding rules.