Failing Route 53 health checks that no DNS record references
What does ZopNight detect here?
ZopNight flags an Amazon Route 53 health check whose status from `GetHealthCheckStatus` is failing and which no record in any hosted zone references. Nothing depends on it, so deleting it recovers the full fee, which AWS lists as $0.50 a month for an AWS endpoint and $0.75 for a non-AWS endpoint. ZopNight ships this check switched off by default.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1525 |
| Category | orphan |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | status FAILURE and 0 referencing records |
| Source | ZopNight |
| Permissions used | route53:ListHealthChecks · route53:GetHealthCheckStatus · route53:ListHostedZones · route53:ListResourceRecordSets |
Where it applies
A failing check that nothing uses still costs money
Route 53 pricing charges $0.50 per health check per month for AWS endpoints and $0.75 for non-AWS endpoints, with optional features such as HTTPS and string matching costing extra. Up to 50 health checks for AWS endpoints in the same account are free.
Health checks are usually created alongside failover or weighted records. When the endpoint is decommissioned, the record is often removed but the health check stays, failing every interval against an address that no longer answers.
Finding failing checks and their references
aws route53 list-health-checks \ --query 'HealthChecks[].[Id,HealthCheckConfig.FullyQualifiedDomainName]' --output table
aws route53 get-health-check-status --health-check-id 1234abcd-56ef-78gh-90ij-1234567890kl \ --query 'HealthCheckObservations[].[Region,StatusReport.Status]'
aws route53 list-resource-record-sets --hosted-zone-id Z0123456789ABCDEFGHIJ \ --query 'ResourceRecordSets[?HealthCheckId!=`null`].[Name,Type,HealthCheckId]'Run the last command for each hosted zone to see which records still point at the check.
Failing and unreferenced, right now
ZopNight reads the health check status that Route 53 reports and counts the hosted zone records referencing the check. It fires when the status is failing and the count is zero, which makes the finding a clean delete. There is no age requirement; the check describes the current state. ZopNight ships this finding switched off by default, so it may not appear in your account.
When a failing check is left alone
A failing check that records still reference is not flagged, because deleting it would change how those records route. The right fix there is the endpoint, not the check. The DeleteHealthCheck reference warns that Route 53 does not stop you deleting a check still associated with records, and that the future status of such a check becomes unpredictable. Healthy checks are never considered.
A small, fixed saving
saving = the health check's monthly feecost after fix = 0ZopNight uses your billed rate when billing data is connected. Without it, ZopNight assumes the basic $0.50 fee, which ignores the 50 free checks, the higher non-AWS rate and optional features.
Removing an orphaned health check
- Confirm that no failover, weighted or latency record references the check.
- If the endpoint should be healthy, fix it instead of deleting the check.
- Delete it with
aws route53 delete-health-check --health-check-idand the ID. - Remove any CloudWatch alarm built on the check’s metrics.