Is your AWS bill higher than it should be?Free 32-point self-audit checklist.
Get the checklist

Home/Articles

AWSCost

Why Is My AWS Bill So High? The Usual Causes and How to Find Yours

By Al Bunch · · 5 min read

Your AWS bill is high because AWS charges for what you’ve provisioned, not what you use, and it never sends a reminder. A server sized for a launch three years ago, a NAT Gateway shuttling logs, snapshots nobody remembers: each one bills every hour, quietly.

The good news is that the causes are predictable. Here’s where the money usually goes, and how to find out which ones are on your bill.

Start in Cost Explorer, Not the Invoice

The invoice tells you which service costs money. Cost Explorer tells you why.

  1. Open Billing and Cost Management > Cost Explorer
  2. Set the range to the last 3 months, monthly granularity
  3. Group by: Service to see the big buckets
  4. Filter to the biggest service and group by: Usage type

The usage type is the real answer. NatGateway-Bytes, BoxUsage:m5.xlarge, TimedStorage-SnapshotUsage, PublicIPv4:InUseAddress each name a specific thing you can go and fix.

While you’re there, turn on Cost Anomaly Detection. It’s free and emails you when spend jumps, instead of you finding out at the end of the month.

1. Oversized or Idle Compute

The most common cause. Instances, containers and databases are sized for peak traffic that never comes, or left running after a project ends.

  • Check: CloudWatch CPU and memory over 2–4 weeks. A server averaging 5% CPU is paying for 20x what it uses. Compute Optimizer (free) gives rightsizing recommendations for EC2, ECS on Fargate, Lambda and EBS.
  • Fix: downsize, move to Graviton (ARM) instance types where your software supports it, which are usually cheaper for the same work, and shut down non-production environments outside working hours.

2. NAT Gateway Data Processing

If your workloads run in private subnets, every byte they send to the internet or to other AWS services goes through the NAT Gateway, at $0.045 per GB on top of about $33 a month per gateway (us-east-1 pricing). Container logs, image pulls and S3 traffic add up fast.

  • Check: Cost Explorer usage type NatGateway-Bytes, and the gateway’s BytesOutToDestination metric. A flat, steady line 24/7 usually means log shipping.
  • Fix: add the free S3 gateway endpoint, and interface endpoints for the services that send the most traffic. Full walkthrough: Your NAT Gateway Is Billing You for Traffic That Should Be Free.

3. Forgotten Storage

Storage is cheap per GB and expensive in aggregate, because nothing ever deletes it.

  • EBS snapshots from old backups and AMIs, at $0.05/GB-month
  • Unattached EBS volumes left behind when instances were terminated
  • gp2 volumes that could be gp3, which is about 20% cheaper with better baseline performance
  • S3 buckets with no lifecycle rules, keeping every version of every object forever

Fix: delete what isn’t needed, set retention on snapshots with AWS Backup or Data Lifecycle Manager, convert gp2 to gp3 (no downtime), and add S3 lifecycle rules that move old data to cheaper storage classes or delete it.

4. CloudWatch Logs Kept Forever

New log groups default to never expire. Ingestion costs $0.50 per GB, and years of debug logs sit in storage.

  • Check: CloudWatch Logs, sort log groups by stored bytes.
  • Fix: set a retention period on every log group (30–90 days covers most needs), stop logging health checks and other noise, and lower log levels in production.

5. Public IPv4 Addresses

Since February 2024, AWS charges $0.005 per hour for every public IPv4 address, attached or not. That’s about $3.65 a month each. Load balancers, NAT Gateways, instances with public IPs and idle Elastic IPs all count.

  • Check: Cost Explorer usage type PublicIPv4, or the Public IP Insights view in VPC IP Address Manager.
  • Fix: release unused Elastic IPs, keep instances in private subnets behind a load balancer, and consolidate load balancers where you can.

6. Too Many Load Balancers

Each Application Load Balancer costs about $16 a month before traffic, plus its public IPs. Teams often end up with one per app, per environment.

Fix: one ALB can route many services by hostname or path. Consolidate small services and delete load balancers with no healthy targets.

7. Cross-AZ and Internet Data Transfer

Traffic between Availability Zones costs $0.01 per GB in each direction, and internet egress starts at $0.09 per GB after the first 100 GB a month. Chatty services split across zones, and media served straight from EC2 or S3, add up.

Fix: serve static content and downloads through CloudFront, and keep high-traffic service-to-service calls in the same zone where availability allows.

8. Old Database Versions and Oversized Databases

RDS charges Extended Support fees for engine versions past their standard support date, like older MySQL and PostgreSQL major versions, and the fee is per vCPU per hour. Databases are also often sized for peak and left that way.

Fix: upgrade engine versions on a schedule, rightsize instances using CloudWatch metrics, and consider Aurora Serverless v2 for spiky workloads.

9. Paying On-Demand for Steady Workloads

If the same servers run 24/7 all year, you’re paying the highest possible rate. Savings Plans and Reserved Instances cut that by committing to a level of usage for one or three years.

Fix: commit to your steady baseline, not your peak. See Savings Plans vs Reserved Instances for which to buy and how much.

The Pattern Behind All of These

None of these are mistakes, exactly. Each is a reasonable default that nobody revisited: log groups that never expire, a NAT Gateway in the reference architecture, a server sized for a launch. The bill grows because nobody’s job is to look at it.

A one-hour monthly habit catches most of it: Cost Explorer by usage type, anomaly alerts on, and one question for every line that grew, “what is this, and do we still need it?”

Want someone else to find the savings?Fixed-price AWS cost audit, priced by your spend, with a refund guarantee.
See the audit

Rather have someone else look? Our AWS cost audit is a fixed price based on your monthly spend, ranks every saving by dollars and effort, and refunds the difference if the first-year savings don’t beat the fee.

FAQ

Frequently Asked Questions

Why is my AWS bill so high?

Usually because AWS bills for what you provision, not what you use. The common causes are oversized or idle instances and databases, NAT Gateway data processing, forgotten snapshots and volumes, CloudWatch Logs kept forever, public IPv4 addresses, and steady workloads paying on-demand rates instead of using Savings Plans.

How do I find out what's costing me money on AWS?

Open Cost Explorer, group by service, then by usage type, for the last three months. The usage type names the actual charge, like NatGateway-Bytes or TimedStorage-SnapshotUsage. Turn on Cost Anomaly Detection so you hear about new spikes.

How much can I save on my AWS bill?

Accounts that have never been reviewed usually have meaningful waste in idle resources, storage and missing commitment discounts. The only way to know is to look at your own usage data.

Free download

The AWS Bill Self-Audit Checklist

32 places AWS quietly charges you, where to find each one in Cost Explorer, and what to do about it.

Get the free PDF

Ready to Get Your Systems Connected?

Tell us what tools you're using and what's not working.