certbot-dns-route53
Route53 DNS Authenticator plugin for Certbot
Decision gist · record as of 2026-08-14
Yes. This is a mature, actively maintained plugin (active status, recent release) with no known vulnerabilities, low install friction, and a permissive license. Install it if you host domains on Route53 and want to automate Let's Encrypt certificate provisioning without manual DNS or web server configuration. Requires AWS credentials and Certbot already installed.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires AWS credentials (via environment variables or IAM role) with Route53 permissions, and Certbot must run on a system with network access to Route53 API.
- Low friction install with a pure-Python wheel.
- Maintenance is active with a recent release (30 days ago) and the parent Certbot project shows strong community backing (33202 stars).
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use with minimal restrictions, making it suitable for production deployments.
last release 2026-07-15 (30 days) · last repo commit 2026-08-12 · 33,202 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 201,127 downloads/mo, #9,678 on PyPI
Alternatives
Verify before relying
pip install certbot-dns-route53
certbot certonly --dns-route53 -d example.com- Whether the plugin supports wildcard certificate issuance via Route53 DNS validation.
- Whether automatic certificate renewal is supported and how it integrates with system schedulers.
- Performance characteristics when managing many domains or frequent validation cycles.
What it is and what it does
This package is a plugin for Certbot that extends its certificate provisioning workflow to use AWS Route53 for DNS-based domain validation. Instead of requiring web server access or manual DNS record creation, it automates the ACME DNS challenge by programmatically creating and removing Route53 records on your behalf. The plugin depends on boto3 for AWS API interaction, acme for ACME protocol handling, and certbot as its host framework.
It is designed for teams managing domains on Route53 who want to automate Let's Encrypt certificate issuance without exposing web servers or managing manual DNS updates. The plugin handles the full validation flow: it creates temporary DNS records to prove domain ownership, waits for propagation, and cleans up after the challenge completes. This is particularly useful for infrastructure-as-code workflows and CI/CD pipelines where certificates need to be provisioned programmatically.
Use it for
- Automate HTTPS certificate provisioning for Route53-hosted domains in AWS infrastructure.
- Enable certificate renewal in CI/CD pipelines without manual DNS intervention or web server access.
- Issue wildcard or multi-domain certificates for Route53 domains via fully automated DNS validation.
- Integrate Let's Encrypt certificate management into infrastructure-as-code deployments on AWS.
- Provision certificates for internal or non-public domains where HTTP validation is not feasible.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
This is a mature, actively maintained plugin (active status, recent release) with no known vulnerabilities, low install friction, and a permissive license. Install it if you host domains on Route53 and want to automate Let's Encrypt certificate provisioning without manual DNS or web server configuration. Requires AWS credentials and Certbot already installed.
Install
certbot-dns-route53 on PyPI
Before you install
Low friction install with a pure-Python wheel. Maintenance is active with a recent release (30 days ago) and the parent Certbot project shows strong community backing (33202 stars). Supports modern Python versions (3.10–3.14).
Requires AWS credentials (via environment variables or IAM role) with Route53 permissions, and Certbot must run on a system with network access to Route53 API.
License in practice
Apache-2.0 permissive license allows commercial and private use with minimal restrictions, making it suitable for production deployments.
Quickstart
pip install certbot-dns-route53
certbot certonly --dns-route53 -d example.com
Verify before relying
- Whether the plugin supports wildcard certificate issuance via Route53 DNS validation.
- Whether automatic certificate renewal is supported and how it integrates with system schedulers.
- Performance characteristics when managing many domains or frequent validation cycles.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 3 packagesboto3acmecertbot |
| Maintenance | Actively maintained 30 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 201,127 / month, #9,678 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableEnvironment :: PluginsIntended Audience :: System AdministratorsOperating System :: POSIX :: LinuxProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Internet :: WWW/HTTPTopic :: SecurityTopic :: System :: Installation/SetupTopic :: System :: NetworkingTopic :: System :: Systems AdministrationTopic :: Utilities |
Evidence: certbot_dns_route53-5.7.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “certbot route53 dns validation”
- certbot-dns-route53A Certbot plugin that automates DNS validation for Let's Encrypt…
- certbot-dns-multiA Certbot DNS plugin that automates ACME DNS challenges across 117+…
- certbot-dns-cloudflareAutomates DNS validation for Let's Encrypt certificate issuance by…
Give your agent the search over MCP, or paste the wish link into any chat.
More WWW/HTTP packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.
HTTPX is a fully featured HTTP client library for Python that provides both sync and async APIs, with support for HTTP/1.1 and HTTP/2, plus an integrated command-line client.
Install it if you are building new projects or modernizing existing ones that rely on HTTP.
A minimal low-level HTTP client library that sends HTTP requests with thread-safe and task-safe connection pooling, supporting HTTP/1.1, HTTP/2, proxies, and both sync and async interfaces.
aiohttp is an async HTTP client and server framework built on asyncio, supporting both WebSockets and middleware-based routing for building concurrent web applications.
Install it if you need async HTTP client or server capabilities in asyncio-based applications.
See also certbot-dns-cloudflare · certbot-dns-multi · certbot-nginx · certbot · certbot-dns-duckdns · certbot-dns-directadmin · acme · fqdn · aws-cdk.aws-route53 · aws-cdk.aws-route53-targets