AWS Cloudfront 403 Error When Using Netlify DNS as NS for Domain on Route53

Hey @Mwpereira

NS is (supposedly) pointing to Netlify

$ dig surgeri.ca NS
surgeri.ca.		4261	IN	NS	dns4.p07.nsone.net.
surgeri.ca.		4261	IN	NS	dns3.p07.nsone.net.
surgeri.ca.		4261	IN	NS	dns2.p07.nsone.net.
surgeri.ca.		4261	IN	NS	dns1.p07.nsone.net.

however whois says otherwise

$ whois surgeri.ca | grep 'Name Server'
Name Server: ns-1480.awsdns-57.org
Name Server: ns-1543.awsdns-00.co.uk
Name Server: ns-42.awsdns-05.com
Name Server: ns-576.awsdns-08.net

and SOA agrees

$ dig surgeri.ca SOA
surgeri.ca.		933	IN	SOA	ns-1480.awsdns-57.org. awsdns-hostmaster.amazon.com. 1 7200 900 1209600 86400

A records are not showing Netlify IPs either

$ dig surgeri.ca A
surgeri.ca.		77	IN	A	99.84.238.122
surgeri.ca.		77	IN	A	99.84.238.213
surgeri.ca.		77	IN	A	99.84.238.117
surgeri.ca.		77	IN	A	99.84.238.177

compared to what Netlify provides

$ dig surgeri.ca A @dns1.p07.nsone.net
surgeri.ca.		20	IN	A	54.206.231.79
surgeri.ca.		20	IN	A	54.206.202.192

Have you followed in advice in [Support Guide] I changed my name servers / DNS on AWS Route53 but I’m still having issues?