Introduction

DNS is the backbone of modern applications, yet it's often overlooked until something goes wrong. When infrastructure scales across multiple environments, consolidating all records into a single hosted zone creates unnecessary risk and complexity. Subdomain delegation offers a cleaner, more secure alternative.

What Happened

Instead of dumping every record for every environment into one giant hosted zone, each environment gets its own zone. The parent zone, such as example.com, simply points to the authoritative name servers of the child zones. This means dev.example.com and other subdomains become independent zones that live under the same domain, but remain logically separated.

Why This Matters

The benefits are immediate and practical. A smaller blast radius means a bad record, misconfigured TTL, or a fat-fingered change in the dev zone cannot affect production, because they are literally different zones with different record sets. IAM becomes more sane, since you can grant a team or CI pipeline access to the dev zone alone, without handing over the keys to production DNS. For infrastructure as code users, separate zones usually mean separate state, so changes to one environment do not require locking or touching the state of another. When something goes wrong, the change history for a single small zone is much easier to reason about than digging through a zone with hundreds of unrelated records.

Key Takeaways

  • Delegation is achieved by adding NS records to the parent zone that reference the child zone's name servers.
  • Route 53 automatically assigns a set of name servers to the new dev zone the moment it's created; you just need to grab them and hand them over to the parent.
  • Once that applies, anything under dev.example.com gets resolved by asking the parent zone, which says not my problem, go ask these name servers instead, and the child zone takes it from there.
  • Any record you create inside the dev zone from that point on is completely isolated from the parent and from every other environment's zone.

Conclusion

Splitting hosted zones by environment and delegating them properly is a small amount of work that pays off the first time someone needs isolated permissions, a cleaner audit trail, or wants to nuke and recreate a dev zone without holding their breath. It's one of those changes that feels unnecessary until the day it very much isn't.