Key Capabilities
1. Unified Resolution for Public and Private Domains
Global Resolver enables clients, from data centers to remote devices, to resolve:
• Public internet domains
• Private hosted zone records across Regions
This removes the need for custom DNS forwarders or complex split-DNS architectures.
2. Built-In Security and Filtering
Administrators can enforce DNS policies using features also found in Route 53 DNS Firewall, including:
• Allow, block, or alert rules
• AWS-maintained Managed Domain Lists (malware, phishing, spam, adult content, gambling, etc.)
• Custom domain lists
• Detection of advanced DNS threats such as:
→Domain Generation Algorithms (DGA)
→DNS tunneling
Blocked queries can return NXDOMAIN, NODATA, or custom DNS responses. Logging options allow all DNS activity to be retained for audit and compliance.
3. Global Reach With Automatic Failover
Global Resolver can be instantiated in multiple AWS Regions. Using anycast routing, queries are served from the closest available Region, with automatic failover if a Region becomes unavailable.
Supports:
• Do53 (DNS-over-UDP)
• DNS-over-TLS
• DNS-over-HTTPS
4. Flexible Client Authentication
Global Resolver supports two authentication approaches:
• Token-based authentication for DoH and DoT
• IP or CIDR allowlisting for Do53, DoH, and DoT
Tokens can be created, revoked, rotated, and set to expire, giving administrators granular access control.
5. DNSSEC Validation
Optional DNSSEC validation ensures DNS responses have not been tampered with, protecting against spoofing and cache-poisoning attacks.
6. EDNS Client Subnet Support
With EDNS Client Subnet enabled, clients can receive geographically optimized DNS responses. This is useful for CDNs and latency-sensitive workloads.