iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Amazon SNS server-side encryption (SSE) protects message bodies at rest with AWS KMS, but it does not encrypt every topic detail or automatically make every subscription work. The most useful troubleshooting order is to check the KMS key and its permissions first, then the request protocol and—if the subscriber is an encrypted SQS queue—the queue’s separate KMS key.
What Amazon SNS encryption protects—and what it leaves visible
SNS encrypts a message when it receives it, stores it encrypted, and decrypts it when delivering it to subscribers. The protection applies to the message body, not every piece of topic or message information. AWS describes the behavior in its server-side encryption guide: “SSE encrypts messages as soon as Amazon SNS receives them.”
Topic name and attributes, message subject, message ID, timestamp and message attributes, data protection policy, and per-topic metrics are outside this SSE encryption scope. Messages already in a topic backlog when SSE is enabled are not encrypted retroactively. Conversely, a message encrypted while SSE was enabled remains encrypted if SSE is later disabled.
Choose the KMS key that fits your access-control needs
SNS supports symmetric KMS keys. The console setup path presents the AWS-managed SNS key, alias/aws/sns, as the default. A customer-managed key is an option when your organization needs direct control over its key policy and authorization. AWS explains the setup choices in its topic-encryption setup guide and key-management and cost guidance.
#1 Best Overall
- OTP Token in card format that provides secure remote access with strong authentication
- Easy to use and easy to carry, same size as a credit card
- Zero footprint; No software on end-user PCs
- Compliant to OATH open standard (time based - 6 digits)
- Expected battery life is 3 years or approximately 15,000 clicks
| Consideration | AWS-managed SNS key | Customer-managed KMS key |
|---|---|---|
| Policy control | Less custom key-policy work to manage. | Customer controls the key policy and authorization. |
| Setup and permissions | Still requires the relevant SNS and publisher/consumer access to work. | Requires policy and IAM authorization to be configured for SNS and relevant publishers and consumers. |
| Best fit | When custom key-policy control is not a requirement. | When organization-specific policy control or auditing is needed. |
Check key permissions before changing the subscription
Encryption turns delivery troubleshooting into an authorization check as well as a subscriber check. For a customer-managed key, verify that the publishers and consumers have the required KMS permissions, and that the key policy or corresponding IAM policies authorize the relevant principals. AWS identifies kms:GenerateDataKey* and kms:Decrypt as publisher permissions to check. The applicable policies must refer to the full key ARN in the key’s Region.
- Identify the key. Confirm which KMS key the topic uses, whether it is the AWS-managed SNS key or a customer-managed key, and that the key ARN is in the Region relevant to the topic.
- Check publisher authorization. Confirm the publishing principal is permitted to use the key for the required KMS actions, including
kms:GenerateDataKey*andkms:Decrypt. - Check consumer and service authorization. Review the key policy and applicable IAM policies for the principals involved in producing and consuming the encrypted messages, including the SNS service as required by the configuration.
- Review alias conditions. If a policy uses the
kms:ResourceAliasescondition key, ensure the selected customer-managed key actually has an associated alias.
These permissions do not guarantee that every subscription failure has the same cause. The actual policy, principal, key, Region, and subscription type determine what needs attention.
Rank #2
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
- Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
Verify HTTPS and Signature Version 4
Requests to an SNS topic with SSE enabled must use HTTPS and Signature Version 4. However, enabling encryption does not by itself make the topic reject HTTP requests. If publishing must be HTTPS-only, enforce that requirement with policy controls. AWS covers transport and related safeguards in its SNS security best practices.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteFor an encrypted SQS subscription, check the queue key too
An encrypted SQS subscription involves two distinct KMS authorization points: the SNS topic’s key and the SQS queue’s key. The queue key policy must allow the SNS service principal the required KMS actions, including kms:GenerateDataKey and kms:Decrypt. A correctly authorized topic key does not replace this queue-key permission. Follow AWS’s procedure for an encrypted SQS queue subscription when reviewing the queue policy.
Rank #3
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- USB TYPE C Connectivity & DONGLE Design: Designed for PCs, Macs, laptops, iPhones, and Android devices that utilize a USB-C port. Plug and stay, or carry it on a keychain. (Item Size: 0.73 x 0.60 x 0.30 inches)
- Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC functionality is not supported.
Estimate KMS request use without mistaking it for a bill
SNS reuses a data key for up to five minutes. AWS provides this estimate for KMS API request volume: R = B / D * (2 * P), where B is the billing period in seconds, D is the data-key reuse period in seconds, and P is the number of publishing principals. This is an estimate of request volume, not a dollar amount; AWS warns that actual usage and charges may be higher because SNS is distributed. A cost estimate also requires current regional KMS pricing and the account’s traffic assumptions. See AWS’s key-management and cost guidance.
Confirm encryption coverage and configuration
AWS Security Hub CSPM documents control SNS.1, which checks for KMS encryption at rest on SNS topics. Security Hub controls may not be available in every Region. Consult the SNS controls reference for the control’s current availability and requirements.
Rank #4
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
For a practical sequence, verify the topic key and authorizations first, then confirm HTTPS and Signature Version 4 for requests, and finally inspect the SQS queue’s KMS key if the subscription uses an encrypted queue. Treat each as a separate configuration boundary rather than assuming that enabling topic SSE configures all of them.
Quick Recap
Best Value
- PHISHING-RESISTANT 2FA: Cryptographically binds to real domains, making phishing attacks impossible unlike SMS codes or authenticator apps.
- 3-SIDE CAPACITIVE TOUCH: Tap the end, left, or right side to authenticate, so it works in any orientation or crowded USB port.
- MULTI-COLOR LED INDICATOR: Blue means ready, blinking blue means tap now, green means success, and red means error for instant status feedback.
- IP68 WATERPROOF & BATTERY-FREE: Crush-resistant one-piece construction survives daily carry on a keychain or in a bag for years without any batteries.
- UNIVERSAL COMPATIBILITY: Works with Google, Microsoft, Apple, GitHub, AWS, and any FIDO2 / U2F / WebAuthn service, storing up to 100 passkeys.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

