Palo Alto Networks and AWS Bring Advanced DNS Security to Amazon Route 53 DNS Firewall

Source: Palo Alto Networks Blog•

Palo Alto Networks and AWS Bring Advanced DNS Security to Amazon Route 53 DNS Firewall

Delivering real-time DNS threat protection natively within Amazon Web Services Palo Alto Networks is excited to announce the general availability Advanced DNS Security with Amazon Route 53 Resolver DNS Firewall, bringing enterprise-grade …

Delivering real-time DNS threat protection natively within Amazon Web Services

Palo Alto Networks is excited to announce the general availability Advanced DNS Security with Amazon Route 53 Resolver DNS Firewall, bringing enterprise-grade DNS threat protection directly into AWS environments.

As organizations accelerate cloud adoption, DNS has become a foundational layer for how applications connect and communicate. It has also become one of the most consistently exploited attack surfaces.

Threat actors increasingly use DNS for command-and-control, data exfiltration, and malware delivery. These techniques often bypass traditional defenses that lack the visibility and real-time inspection needed to detect and stop threats early. At the same time, security teams are under pressure to protect rapidly expanding cloud environments without introducing complexity or impacting performance.

This announcement reflects a shift in how DNS security is delivered in the cloud.

Closing a Critical Visibility Gap

Traditional approaches to DNS security were not designed for cloud scale or modern attack techniques.

Many organizations still rely on static or reputation-based controls that cannot detect new or evasive threats. Others depend on external security layers that introduce latency and increase architectural complexity. As environments grow, maintaining consistent visibility across distributed workloads becomes more difficult.

These limitations create a persistent visibility gap, one that attackers continue to exploit.

Integrating Advanced DNS Security directly into Amazon Route 53 Resolver DNS Firewall helps close this gap by enabling continuous inspection of DNS activity across environments. This allows threats to be identified and stopped earlier in the attack lifecycle.

A Simpler, More Effective Approach to DNS Security

Palo Alto Networks Advanced DNS Security is now integrated with Amazon Route 53 Resolver DNS Firewall, enabling organizations to apply it natively within the DNS Firewall policies in AWS.

Protection is applied inline within the cloud environment, allowing organizations to secure DNS traffic as part of their existing architecture. This approach removes the need for additional infrastructure or traffic redirection, while keeping operations simple and efficient.

With a cloud-native solution, organizations can configure DNS security policies directly within the Amazon Route 53 interface, without managing separate tools or consoles.

Security teams can activate the solution through AWS Marketplace and begin applying advanced DNS threat detection immediately. This combines AWS-native simplicity with real-time, AI-driven security.

Real-Time Protection, Built for Cloud Scale

This integration brings together Amazon Route 53 Resolver DNS Firewall within customer VPCs and Palo Alto Networks threat intelligence to deliver real-time DNS protection at scale. DNS activity is analyzed across both requests and responses, providing deeper visibility and more accurate detection of both known and unknown threats.

Organizations benefit from:

  • Over 30 advanced DNS threat detection techniques
  • Coverage across six major DNS threat categories
  • Inline inspection within AWS enables low-latency DNS security, helping organizations strengthen protection without impacting application performance.

What This Means for Your Security Teams

This integration is designed to remove the tradeoffs that security teams have historically faced between protection and operational simplicity.

DNS security can now be applied consistently across AWS environments without deploying additional infrastructure or introducing complexity. Protection scales with the environment, enabling teams to strengthen security while maintaining performance and efficiency.

With this approach, organizations can:

  • Secure AWS workloads without deploying additional infrastructure
  • Stop command and control activity before threats escalate
  • Detect and prevent DNS-based data exfiltration and tunneling
  • Extend DNS protection to hybrid environments
  • Simplify DNS security operations within AWS
  • Monitor DNS activity and security events directly within AWS-native services such as Amazon CloudWatch and AWS Security Hub
  • Gain centralized visibility through dashboards and insights within the Amazon Route 53 console

A New Model for Cloud Security

This collaboration between Palo Alto Networks and Amazon Web Services (AWS) represents a broader shift in how security is delivered in the cloud.

Security is no longer something that needs to be layered on top of infrastructure. It is becoming embedded into the platforms organizations already rely on.

For customers, this means stronger protection and the ability to scale securely without compromise.

Get Started Today

Organizations can get started in minutes by activating Palo Alto Networks Advanced DNS Security through AWS Marketplace.

Once enabled, Advanced DNS Security can be applied within Amazon Route 53 DNS Firewall, allowing teams to secure DNS traffic without changing their architecture or adding operational overhead.

Whether you're ready to deploy or still evaluating, we have resources to help:

Start your free trial on Amazon Web Services (AWS) Marketplace Today.

What this article says