What AWS and Palo Alto Networks just changed
AWS has added Palo Alto Networks Advanced DNS Security into Amazon Route 53 Resolver DNS Firewall, giving customers access to more than 30 advanced DNS threat detections directly from the DNS Firewall console. The integration is available under the Advanced rule tier and, according to AWS, it activates in about two minutes with no separate infrastructure to deploy or manage. For APN Partners, this is not just another security feature. It is a simpler way to sell, design, and operationalize DNS-layer protection across AWS and hybrid environments.
The practical takeaway is straightforward: partners can now position DNS security as a fast, native control rather than a separate tool chain. That matters to resellers, MSPs, system integrators, and consultants because it lowers the friction that often slows security adoption, especially for customers already running Route 53 Resolver endpoints for shared services or hybrid DNS forwarding.
Why this matters for partners
DNS is one of the easiest places for attackers to hide command-and-control traffic, domain generation activity, tunneling, phishing callbacks, and newly registered malicious domains. AWS says the Palo Alto Networks integration adds protections for threats such as fast flux, DNS hijacking, domain generation algorithms, and newly registered domains. For partners, the value is not just in the threat list. It is in how quickly those controls can be attached to existing DNS Firewall rule groups and then applied across multiple accounts, VPCs, and hybrid networks.
That means partners can offer a clean upgrade path for customers who already use Route 53 Resolver DNS Firewall but want stronger threat intelligence without redesigning their DNS architecture. It also creates a good entry point for security assessments, because the integration makes it easier to compare current DNS policy coverage against a more advanced baseline.
How partners should package the opportunity
MSPs and managed security providers can turn this into a recurring service by offering DNS threat monitoring, policy tuning, and alert response tied to DNS Firewall Advanced. Because the integration sits inside AWS and uses the console workflow, partners do not need to stand up and maintain a separate appliance just to deliver protection. That reduces operational overhead and makes the service easier to scale across many customer environments.
Resellers and distributors can use the launch to lead with outcomes instead of product complexity. The message to customers is that they can subscribe from the DNS Firewall console through the embedded AWS Marketplace widget, select threat categories, and apply them to existing rule groups. For channel sellers, that short path from evaluation to deployment can help compress sales cycles.
System integrators and consultants should treat this as a design pattern for hybrid DNS security. AWS notes that the protection can be extended across accounts, VPCs, and hybrid environments. In practice, that means partners can build reference architectures for organizations that forward DNS through Route 53 Resolver endpoints from on-premises networks and want one policy model across cloud and data center traffic.
What to do now
Partners should start by identifying customers already using Route 53 Resolver DNS Firewall or Route 53 Resolver endpoints. Those environments are the most obvious fit because the new capability can be layered into existing rule groups rather than forcing a rebuild. Next, review which DNS threat categories each customer actually needs. Palo Alto Networks’ integration is built for selective policy enforcement, so partners can map categories to specific risk profiles instead of turning everything on by default.
Partners should also update their operational runbooks. Because the control is now embedded in AWS, the important work shifts from infrastructure management to policy governance. That means defining who can create or edit rule groups, how alerts will be reviewed, which events should trigger escalation, and how DNS log data will be retained and analyzed.
Finally, this is a good moment to create a standard customer workshop around DNS security. Many organizations still think of DNS as plumbing rather than a security layer. The integration gives partners a practical way to show how DNS controls can catch malicious behavior early, before a threat reaches workloads or users.
Preview and rollout details partners need to know
AWS first announced the capability as a preview in June 2026. The preview is available in these Regions: US East (Ohio), US West (N. California), Europe (London), Europe (Frankfurt), Asia Pacific (Tokyo), Asia Pacific (Mumbai), Asia Pacific (Singapore), and Africa (Cape Town). During preview, AWS said DNS Firewall Advanced customers can add Palo Alto Networks rules to existing rule groups at no additional DNS Firewall charge, and the Palo Alto Networks Marketplace subscription is free during preview.
That pricing detail matters for partner adoption plans. It creates a low-friction window for pilots, proof-of-value engagements, and migrations from older DNS security controls. Partners should move quickly to identify customers in the supported Regions who are already budgeted for security work in 2026, because preview periods are often the easiest time to convert interest into a roadmap item.
A practical partner playbook
For APN Partners, the opportunity is to make DNS security easier to buy, easier to deploy, and easier to manage. A strong go-to-market motion would include the following:
- Audit current Route 53 Resolver DNS Firewall customers for expansion opportunities.
- Build a packaged assessment that maps DNS threats to business risk.
- Offer implementation services for rule group design, logging, and alerting.
- Bundle ongoing managed monitoring for DNS policy and threat events.
- Create hybrid network designs that use Resolver endpoints for consistent protection across cloud and on-premises traffic.
The broader strategic point is that AWS and Palo Alto Networks have removed much of the deployment friction from DNS-layer security. Partners that can translate that into concrete architecture, managed services, and security outcomes will be in the best position to capture demand. This is especially true for customers that want stronger protection without adding another appliance, another firewall layer, or another operational team to maintain it.
If you are an APN Partner, the best move is not to wait for customers to ask about it. Bring this capability into account reviews, security workshops, and renewal conversations now, while the preview economics and low setup effort make it easy to prove value.

