# Route53 dnsChallenge with multiple domains

**URL:** <https://community.traefik.io/t/route53-dnschallenge-with-multiple-domains/1744>\
**Category:** Traefik v2\
**Tags:** letsencrypt-acme\
**Created:** [September 19, 2019, 8:25pm UTC](https://community.traefik.io/t/route53-dnschallenge-with-multiple-domains/1744 "2019-09-19T20:25:04Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![waffleProOps](https://avatars.discourse-cdn.com/v4/letter/w/b38774/32.png) [@waffleProOps](https://community.traefik.io/u/waffleProOps)\
**Post date:** [December 31, 2024, 9:24pm UTC](https://community.traefik.io/t/route53-dnschallenge-with-multiple-domains/1744/5 "2024-12-31T21:24:59Z")

</div>

The real question is why does traefik/lego throw this error when the permissions granted to it allows it to list hosted zones by name? [Amazon Route 53 :: Let’s Encrypt client and ACME library written in Go.](https://go-acme.github.io/lego/dns/route53/#least-privilege-policy-for-production-purposes)

Assuming one is just using a single provider, with multiple hosted zones, each one's zone id should be able to be fetched. As the same doc says:

> If AWS\_HOSTED\_ZONE\_ID is not set, Lego tries to determine the correct public hosted zone via the FQDN.

---

_[View the full topic](https://community.traefik.io/t/route53-dnschallenge-with-multiple-domains/1744)._
