INSERTCART AWS WEB · HOSTING GUIDE
Connect a custom domain to an AWS static website with HTTPS
Configure ACM domain validation and connect Route 53 or another DNS provider to a CloudFront website.
Start with a working CloudFront website
Publish your website and confirm that its CloudFront URL works before changing DNS. You also need control over the domain’s DNS records. Buying a domain is separate from hosting a website; changing DNS does not transfer domain ownership or registration.
Request HTTPS for your domain
Open Manage websites, select the website, and expand Custom domain & HTTPS. Enter a domain such as www.example.com, without a protocol, path, or wildcard. The connection role needs its optional domain permissions. If you excluded them, update the connection stack in AWS to enable them first.
The deployment requests an ACM certificate in us-east-1, which is the required region for CloudFront viewer certificates, even when your website’s S3 bucket is elsewhere. ACM must confirm that you control the domain before CloudFront can use the certificate. See AWS’s certificate requirements.
Use Route 53 for automatic DNS setup
If your domain uses a public Route 53 hosted zone in the connected AWS account, enter that zone’s ID. The service checks that the requested domain belongs inside the zone. It adds the certificate-validation CNAME and, after certificate issuance, creates A and AAAA alias records pointing to CloudFront. This operation can replace existing records at the domain you entered, so choose a domain you intend to use for this website.
Use another DNS provider
Leave the hosted zone field blank. The job displays a certificate validation CNAME name and value. Copy both into your DNS provider’s record editor. Providers differ in whether they expect the full hostname or only the part before your zone name. Avoid accidentally entering your domain twice. Keep the validation record in place so ACM can renew the certificate.
For a subdomain, add a separate CNAME pointing to the displayed CloudFront hostname. Certificate validation and website routing are two different records. If you want to use the root domain, your DNS provider must support an ALIAS, ANAME, or equivalent flattening feature. Do not invent a fixed CloudFront IP address for an ordinary A record.
Allow time for validation and propagation
The job waits for certificate issuance and CloudFront’s updated configuration. DNS changes may take additional time outside AWS. If validation takes longer than the job window, check your records and submit the domain setup again; the service reuses the pending certificate for that website and domain.
This interface connects one domain per website at a time. Connecting a different domain replaces the distribution’s existing alias. Old external DNS records and unused certificates remain under your control and may need manual cleanup. If you use a DNS proxy, check that its TLS and DNS settings match your desired setup.
Ready to publish?
Bring your static website files and connect your own AWS account.
Open the launch workspace ↗Browse hosting guides · Connection security · Understand costs