Skip to main content
orphan · aws

Failing Route 53 health checks that no DNS record references

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags an Amazon Route 53 health check whose status from `GetHealthCheckStatus` is failing and which no record in any hosted zone references. Nothing depends on it, so deleting it recovers the full fee, which AWS lists as $0.50 a month for an AWS endpoint and $0.75 for a non-AWS endpoint. ZopNight ships this check switched off by default.

Signal and threshold

How ZopNight evaluates Failing Route 53 health checks that no DNS record references.
Field Value
Rule IDsRC-1525
Categoryorphan
Severitymedium
Metricnone — pure configuration read
Thresholdstatus FAILURE and 0 referencing records
SourceZopNight
Permissions usedroute53:ListHealthChecks · route53:GetHealthCheckStatus · route53:ListHostedZones · route53:ListResourceRecordSets

A failing check that nothing uses still costs money

Route 53 pricing charges $0.50 per health check per month for AWS endpoints and $0.75 for non-AWS endpoints, with optional features such as HTTPS and string matching costing extra. Up to 50 health checks for AWS endpoints in the same account are free.

Health checks are usually created alongside failover or weighted records. When the endpoint is decommissioned, the record is often removed but the health check stays, failing every interval against an address that no longer answers.

Finding failing checks and their references

Terminal window
aws route53 list-health-checks \
--query 'HealthChecks[].[Id,HealthCheckConfig.FullyQualifiedDomainName]' --output table
aws route53 get-health-check-status --health-check-id 1234abcd-56ef-78gh-90ij-1234567890kl \
--query 'HealthCheckObservations[].[Region,StatusReport.Status]'
aws route53 list-resource-record-sets --hosted-zone-id Z0123456789ABCDEFGHIJ \
--query 'ResourceRecordSets[?HealthCheckId!=`null`].[Name,Type,HealthCheckId]'

Run the last command for each hosted zone to see which records still point at the check.

Failing and unreferenced, right now

ZopNight reads the health check status that Route 53 reports and counts the hosted zone records referencing the check. It fires when the status is failing and the count is zero, which makes the finding a clean delete. There is no age requirement; the check describes the current state. ZopNight ships this finding switched off by default, so it may not appear in your account.

When a failing check is left alone

A failing check that records still reference is not flagged, because deleting it would change how those records route. The right fix there is the endpoint, not the check. The DeleteHealthCheck reference warns that Route 53 does not stop you deleting a check still associated with records, and that the future status of such a check becomes unpredictable. Healthy checks are never considered.

A small, fixed saving

Terminal window
saving = the health check's monthly fee
cost after fix = 0

ZopNight uses your billed rate when billing data is connected. Without it, ZopNight assumes the basic $0.50 fee, which ignores the 50 free checks, the higher non-AWS rate and optional features.

Removing an orphaned health check

  1. Confirm that no failover, weighted or latency record references the check.
  2. If the endpoint should be healthy, fix it instead of deleting the check.
  3. Delete it with aws route53 delete-health-check --health-check-id and the ID.
  4. Remove any CloudWatch alarm built on the check’s metrics.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·