DNSSECStatus - Amazon Route 53
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).


A string representing the status of DNSSEC signing.



A string that represents the current hosted zone signing status.

Status can have one of the following values:


DNSSEC signing is enabled for the hosted zone.


DNSSEC signing is not enabled for the hosted zone.


DNSSEC signing is in the process of being removed for the hosted zone.


There is a problem with signing in the hosted zone that requires you to take action to resolve. For example, the customer managed key might have been deleted, or the permissions for the customer managed key might have been changed.


There was an error during a request. Before you can continue to work with DNSSEC signing, including with key-signing keys (KSKs), you must correct the problem by enabling or disabling DNSSEC signing for the hosted zone.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 1024.

Required: No


The status message provided for the following DNSSEC signing status: INTERNAL_FAILURE. The status message includes information about what the problem might be and steps that you can take to correct the issue.

Type: String

Length Constraints: Minimum length of 0. Maximum length of 512.

Required: No

See Also

For more information about using this API in one of the language-specific Amazon SDKs, see the following: