{
  "slug": "amazon-route-53",
  "category": "dns-hosting",
  "name": "Amazon Route 53",
  "description": "Authoritative DNS hosting and domain registration service from Amazon Web Services, with health checks, routing policies and pay-per-use pricing.",
  "website": "https://aws.amazon.com/route53/",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 52,
  "coverage": 100,
  "summary": "Amazon Route 53 scores 52 out of 100 (grade D) on the DNS hosting criteria. It meets 6 of 11 criteria: transparency report, tells users about requests, TLS configuration, security headers, API access and two-factor login. It partly meets independent audit and DNSSEC. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
  "url": "https://privacyratings.com/dns-hosting/amazon-route-53/",
  "markdown": "https://privacyratings.com/dns-hosting/amazon-route-53/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://aws.amazon.com/legal/cookies/",
      "note": "AWS websites set cookies from third parties including The Trade Desk, Oracle BlueKai and LinkedIn."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "no",
      "evidence": "https://aws.amazon.com/privacy/",
      "note": "The privacy notice says cookies and identifiers are used to advertise to visitors on third-party websites."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/whitepapers/compliance/AWS_SOC3_Report.pdf",
      "note": "Only the SOC 3 summary report is public; SOC 1 and SOC 2 reports are available to customers in AWS Artifact."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/security/pdfs/Amazon_Government_Request_Report_H1_2026.pdf",
      "note": "Semi-annual reports with counts of government requests to Amazon and AWS and how they were answered."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://www.amazon.com/gp/help/customer/display.html?nodeId=GYSDRGWQ2C2CRYEF",
      "note": "Amazon notifies customers before disclosing content unless prohibited or there is clear indication of illegal conduct."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=console.aws.amazon.com&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=console.aws.amazon.com",
      "note": "Grade A+ (105/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "dnssec": {
      "title": "DNSSEC",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/dns-configuring-dnssec.html",
      "note": "DNSSEC signing is supported but needs a customer-managed AWS KMS key for the key-signing key."
    },
    "api_access": {
      "title": "API access",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://docs.aws.amazon.com/Route53/latest/APIReference/Welcome.html",
      "note": "Every AWS account can manage hosted zones and records through the Route 53 API."
    },
    "two_factor": {
      "title": "Two-factor login",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa.html",
      "note": "Passkeys, security keys and authenticator apps are supported."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "A+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T06:38:34.099Z"
  },
  "last_modified": "2026-10-01T06:56:31Z"
}