---
title: CloudFront distributions should encrypt traffic to custom origins
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > CloudFront distributions should encrypt
  traffic to custom origins
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# CloudFront distributions should encrypt traffic to custom origins
 
## Description{% #description %}

This check verifies if Amazon CloudFront distributions are securing traffic to custom origins. Failure occurs when a custom origin uses the `http-only` origin protocol policy, or uses `match-viewer` while the default cache behavior or any ordered cache behavior that routes to it, directly or through an origin group, uses the `allow-all` viewer protocol policy. This check matches AWS Security Hub control CloudFront.9. Deprecated origin SSL protocols are evaluated separately by CloudFront.10.

Using HTTPS (TLS) can enhance security by safeguarding against eavesdropping or manipulation of network traffic. It is advisable to only allow encrypted connections through HTTPS (TLS).

## Remediation{% #remediation %}

For instructions on how to mandate encryption for communication between CloudFront and your custom origin by updating the Origin Protocol Policy, refer to [Requiring HTTPS for communication between CloudFront and your custom origin](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/using-https-cloudfront-to-custom-origin.html) in the Amazon CloudFront Developer Guide.
