# Amazon Route 53 privacy rating

Authoritative DNS hosting and domain registration service from Amazon Web Services, with health checks, routing policies and pay-per-use pricing.

## Summary

Amazon Route 53 scores 52 out of 100 (grade D) on the DNS hosting criteria. It meets 6 of 11 criteria: transparency report, tells users about requests, TLS configuration, security headers, API access and two-factor login. It partly meets independent audit and DNSSEC. It does not meet open source, no trackers or telemetry and no ads or data sales. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.

- Website: https://aws.amazon.com/route53/
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Home page trackers: none found
- Category: [DNS hosting](https://privacyratings.com/dns-hosting/)
- Also rated: [Amazon SES](https://privacyratings.com/email-sending/amazon-ses/) (Email sending services), [AWS End User Messaging SMS](https://privacyratings.com/communications-apis/aws-end-user-messaging-sms/) (SMS and voice APIs), [Amazon Web Services](https://privacyratings.com/server-hosting/amazon-web-services/) (Server hosting), [Kindle](https://privacyratings.com/ebook-readers/kindle/) (Ebook readers), [Amazon Alexa](https://privacyratings.com/smart-home/amazon-alexa/) (Smart home), [Amazon Music](https://privacyratings.com/music-streaming/amazon-music/) (Music streaming), [Amazon Photos](https://privacyratings.com/photo-management/amazon-photos/) (Photo management)
- Grade: D (52/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | No | Closed source. |  |
| No trackers or telemetry | No | AWS websites set cookies from third parties including The Trade Desk, Oracle BlueKai and LinkedIn. | https://aws.amazon.com/legal/cookies/ |
| No ads or data sales | No | The privacy notice says cookies and identifiers are used to advertise to visitors on third-party websites. | https://aws.amazon.com/privacy/ |
| Independent audit | Partial | Only the SOC 3 summary report is public; SOC 1 and SOC 2 reports are available to customers in AWS Artifact. | https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/whitepapers/compliance/AWS_SOC3_Report.pdf |
| Transparency report | Yes | Semi-annual reports with counts of government requests to Amazon and AWS and how they were answered. | https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/security/pdfs/Amazon_Government_Request_Report_H1_2026.pdf |
| Tells users about requests | Yes | Amazon notifies customers before disclosing content unless prohibited or there is clear indication of illegal conduct. | https://www.amazon.com/gp/help/customer/display.html?nodeId=GYSDRGWQ2C2CRYEF |
| TLS configuration | Yes | Grade A+ | https://www.ssllabs.com/ssltest/analyze.html?d=console.aws.amazon.com&hideResults=on |
| Security headers | Yes | Grade A+ (105/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=console.aws.amazon.com |
| Modern web standards | Not tested yet | Not tested yet. |  |
| DNSSEC | Partial | DNSSEC signing is supported but needs a customer-managed AWS KMS key for the key-signing key. | https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/dns-configuring-dnssec.html |
| API access | Yes | Every AWS account can manage hosted zones and records through the Route 53 API. | https://docs.aws.amazon.com/Route53/latest/APIReference/Welcome.html |
| Two-factor login | Yes | Passkeys, security keys and authenticator apps are supported. | https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_mfa.html |

Source: https://privacyratings.com/dns-hosting/amazon-route-53/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/dns-hosting/amazon-route-53.md
