Advanced DNS Security for Route 53
Focus
Focus
Advanced DNS Security Powered by Precision AI®

Advanced DNS Security for Route 53

Table of Contents

Advanced DNS Security for Route 53

Learn how Advanced DNS Security integrates with Amazon Route 53 Resolver DNS Firewall to protect VPC DNS query traffic from advanced threats.
Where Can I Use This?What Do I Need?
  • Amazon Route 53 Resolver DNS Firewall
  • Advanced DNS Security subscription (AWS Marketplace)
  • AWS account with Route 53 DNS Firewall access
Palo Alto Networks® Advanced DNS Security for Amazon Route 53 delivers cloud-native DNS threat protection for your Amazon VPCs by integrating Palo Alto Networks threat intelligence directly into Route 53 Resolver DNS Firewall. This integration eliminates the need to deploy separate firewalls, manage VPC routing configurations, or forward DNS traffic to external inspection points—you enforce Palo Alto Networks DNS protections through the same DNS Firewall rules and rule groups you already use to manage DNS security in AWS. For a list of available deployment locations, see Supported AWS Regions.
The integration addresses two operational challenges. First, it provides access to 30+ DNS threat detections beyond what AWS Managed Domain Lists offer natively, including fast flux detection, DNS rebinding, domain generation algorithm (DGA) detection, and identification of newly registered domains. Second, it eliminates the infrastructure overhead of deploying Palo Alto Networks firewalls (such as Cloud NGFW for AWS) across multiple VPCs and accounts solely for DNS inspection—reducing both cost and operational complexity while maintaining the same threat efficacy.
Advanced DNS Security for Route 53 uses three classes of threat detection models that work together to identify malicious domains:
  • Inline detectors—Evaluate DNS queries in the resolution path and provide instant verdicts. These detectors identify known malicious domains from the Palo Alto Networks threat signature database, detect DGA patterns, and identify inline DNS tunneling attempts. DGA detection operates with a fail-open architecture—if a verdict isn't returned within 4 milliseconds, the query resolves normally to ensure workload availability.
  • Real-time detectors—Monitor DNS queries off-path and generate threat signals within seconds. These detectors identify advanced tunneling, DNS rebinding, fast-flux patterns, and misconfigured domains by analyzing query patterns and DNS response behavior in real-time.
  • Offline detectors—Analyze domain patterns passively to identify threats that require longer observation windows. These detectors identify domain squatting, strategically-aged domains, stockpiled domains, domain shadowing, malicious traffic distribution systems, phishing domains, and ransomware domains.
When any detection model identifies a malicious domain, the finding is stored in a central threat database and applied to one or more DNS security categories that you select when creating DNS Firewall rules. The following categories are available:
  • Command and Control Domains—Domains used by malware to communicate with attacker-controlled infrastructure for receiving instructions, exfiltrating data, or downloading additional payloads. Blocking C2 domains disrupts an attacker's ability to maintain persistence in your environment.
  • Malware Domains—Domains that host, distribute, or facilitate the delivery of malicious software, including exploit kits, ransomware droppers, and trojan delivery networks. These domains are identified through a combination of signature matching and behavioral analysis.
  • Phishing Domains—Domains that impersonate legitimate organizations to steal credentials, personal information, or financial data. Detection covers domains that mimic login pages, payment portals, and other trusted services through typosquatting, homograph attacks, or domain shadowing techniques.
  • Dynamic DNS (DDNS) Hosted Domains—Domains registered with dynamic DNS providers that allow rapid IP address changes. Threat actors frequently use dynamic DNS services to host malicious infrastructure because these services enable rapid rotation of hosting addresses to evade IP-based blocking.
  • Newly Registered Domains—Domains registered within the past 32 days. Attackers often register fresh domains for campaigns because newly registered domains have no reputation history, making them harder to detect through traditional reputation-based methods.
  • Grayware Domains—Domains associated with applications that are not directly malicious but exhibit unwanted behavior such as excessive tracking, unsolicited advertising, browser hijacking, or bundled software installation. Grayware domains often operate in a legal gray area while degrading user experience and security posture.
  • Parked Domains—Domains that display placeholder content, advertising, or "for sale" pages rather than legitimate services. Attackers purchase expired or abandoned parked domains to leverage their residual reputation and redirect visitors to malicious content.
  • Proxy Avoidance and Anonymizers—Domains that provide services designed to bypass network security controls, including web proxies, VPN services, and anonymizing networks. Endpoints contacting these domains may indicate attempts to circumvent your organization's security policies.
  • Ad Tracking Domains—Domains used by advertising networks and third-party trackers to monitor user activity across websites and applications. While not inherently malicious, these domains create privacy risks and can serve as vectors for malvertising campaigns that deliver malware through compromised ad networks.
These categories represent a subset of the full Advanced DNS Security detection capabilities. Additional categories may become available over time. For the complete and current list of DNS threat signatures and detections across all Palo Alto Networks platforms, refer to Cloud-Delivered DNS Signatures.
Palo Alto Networks continuously updates the threat detection models that feed these categories—updates propagate automatically to DNS Firewall without requiring any action on your part.
You subscribe to Advanced DNS Security directly from the Route 53 DNS firewall console through AWS Marketplace. After subscribing, you create DNS Firewall rules by selecting one or more Palo Alto Networks security categories, specifying a block or alert action, and assigning a priority. You then add the rules to a rule group and associate it with your VPCs. For multi-account organizations, you can distribute subscriptions through AWS License Manager and share rule groups across accounts using AWS Resource Access Manager (RAM), Route 53 Profiles, or AWS Firewall Manager.
The integration protects internet-bound DNS queries (public domains) from your VPCs through Route 53 Resolver. Internal domains resolved within a VPC are not evaluated by Advanced DNS Security.
For questions related to Advanced DNS Security functionality, contact adns-support@paloaltonetworks.com.