Implement https://aws.amazon.com/blogs/aws/how-to-get-started-with-amazon-route-53-resolver-dns-firewall-for-amazon-vpc/ to only resolve some domains from our VPC Look at https://github.com/hashicorp/terraform-provider-aws/issues/18520