Charged on the AWS Free Tier? The 11 Places It Leaks

Logeshwaran
—

If AWS charged you while you thought you were safely inside the Free Tier, do not start by blaming the EC2 instance you can see. The leak is often beside it: a public IPv4 address, EBS volume, snapshot, NAT gateway, load balancer, Route 53 hosted zone, CloudWatch logs, database backup, KMS key, or another resource created by the tutorial. The counterintuitive part is that a newer AWS Free Plan can show real billable usage while your out-of-pocket charge is still $0 because Free Tier credits are absorbing it. A $0 payment today does not prove that your architecture costs $0. Open Bills, check the charge by service, Region and usage type, then delete the one resource behind it.

⚡ Quick Answer

• Console → Billing and Cost Management → Bills → Charges by service → expand the charged service → expand the Region → read the usage type.

• Free Tier → Billing and Cost Management → Free Tier → check the offer, actual usage, limit, and percentage used.

• CLI → aws freetier get-free-tier-usage for eligible Free Tier usage, then aws ce get-cost-and-usage to identify actual spend.

Start with the bill itself. Do not randomly delete resources until you know which service, Region, and usage type produced the money.

AWS now has two Free Tier histories living side by side. Accounts created before July 15, 2025 can still be dealing with the older service-specific Free Tier model. Newer customers use the redesigned Free Tier with credits and a Free or Paid account plan. That distinction changes what “free” means, so an article that treats every AWS account as a 12-month EC2 trial is already out of date.

The practical rule is simpler than the marketing language: Free Tier applies to specific eligible usage, not to everything connected to an eligible resource. Your job is to identify the meter that moved. Once you know the meter, the surprise bill normally stops being mysterious.

First find out which AWS Free Tier you actually have

Before troubleshooting a charge, find the account's Free Tier model. Otherwise you can spend half an hour proving that your t3.micro fits an allowance that does not apply to the account you are using.

Accounts created before July 15, 2025: these accounts can still fall under the legacy AWS Free Tier model. The familiar pattern was a collection of service-specific allowances, some available for the first 12 months and some available continuously. EC2 and RDS are common examples beginners remember from this model.

Accounts created under the newer Free Tier experience: a new customer can receive $100 in AWS credits and earn up to another $100 by completing eligible activities. The Free account plan is intended for experimentation without charges and ends after its allowed period or when the available Free Tier credits are consumed, whichever happens first. A Paid account plan continues operating and uses normal pay-as-you-go billing after applicable credits and free usage are exhausted.

There is another detail worth checking directly in your account rather than memorizing from an old tutorial: the current signup experience displays the credit balance and expiration information for your specific account. AWS changed the Free Tier program in 2025 and has continued changing the signup and account-plan experience since then. The date shown in your own account is therefore more useful than somebody's screenshot from a two-year-old YouTube tutorial.

Account situation What “free” means Where money can appear
Legacy account Specific service allowances with their own limits and expiry rules Exceeding an allowance, using an ineligible configuration, or using an adjacent paid resource
New Free account plan Eligible costs can consume Free Tier credits without an out-of-pocket charge Credits fall even though the payment due remains $0
Paid account plan Eligible credits apply first, then ordinary pay-as-you-go billing continues Usage beyond credits or free allowances becomes a normal charge

🙋‍♂️ Jake's Reality Check

"If AWS says I still have $62 of credit, why should I care that yesterday's experiment cost $4? I didn't pay the $4."

The straight answer. Because you just learned that the experiment has a $4 cost structure. If you leave it unchanged, your credits are paying a bill that eventually becomes yours.

Find the exact AWS charge before touching the resources

The most useful AWS billing troubleshooting habit is also the least dramatic: start with the bill.

Do not begin on the EC2 Instances page just because EC2 is the service you remember creating. A public IPv4 address can appear under Amazon Virtual Private Cloud. A load balancer has its own service line. CloudWatch logging has its own meter. EBS storage can remain after compute stops. Route 53 can keep billing after the web server disappears.

  1. Open Billing and Cost Management.
  2. Choose Bills.
  3. Select the billing month that contains the unexpected amount.
  4. Open Charges by service.
  5. Expand the service with a non-zero amount.
  6. Expand the Region when the service is Regional.
  7. Read the usage description or usage type under that Region.
  8. Write down the service, Region, amount, and usage type before opening another console page.

That last step matters. A charge is easier to chase when you have four pieces of evidence instead of one vague idea that “AWS charged my EC2.”

After Bills, open Cost Explorer. Start by grouping by Service. Then narrow the suspicious service and group by Usage type. If you have used more than one Region, add Region to the investigation. Cost Explorer also supports dimensions such as Availability Zone, API operation, instance type, purchase option, and linked account.

For CLI users, the first pass can be:

aws ce get-cost-and-usage \
  --time-period Start=2026-10-01,End=2026-11-01 \
  --granularity DAILY \
  --metrics UnblendedCost \
  --group-by Type=DIMENSION,Key=SERVICE

Then repeat the query with USAGE_TYPE after filtering to the suspicious service. The difference between those two views is the difference between “VPC cost me money” and “this particular VPC meter cost me money.”

✅ Why this is the one to use

Trace invoice → service → Region → usage type → resource. Starting from the resource you remember creating reverses the process and is how people miss the thing that actually billed them.

The Free Tier page answers a different question from the Bills page

Bills answers, “What cost money?” Free Tier tracking answers, “How much of an eligible free allowance have I used?” Do not treat those as interchangeable screens.

Open Billing and Cost Management and choose Free Tier. Depending on your account plan and active offers, the page can show the service, usage type, Free Tier limit, actual usage, forecasted usage, and how much of the allowance you have consumed.

The CLI equivalent is:

aws freetier get-free-tier-usage

The response can include the service, operation, usage type, actual usage, forecasted usage, Free Tier limit, and offer type. That makes it useful for a script that checks whether a lab account is approaching the edge of an allowance.

There is one easy mistake here. If the thing costing you money does not appear as an active Free Tier offer, that does not prove the charge is wrong. The service might not have a Free Tier offer for that usage type. The offer might have expired. Your account plan might expose a different set of benefits. Organizations and billing arrangements can also change what cost and credit information you see from a particular account.

Free Tier usage alerts can notify you when tracked usage reaches 85 percent of a service's Free Tier limit. That is valuable, but it is not a universal “your AWS bill can never rise above $0” switch. A resource outside the tracked offer can still have a perfectly valid price.

Leak #1: the server looks free, but its public IPv4 address has a meter

If the Bills page shows Amazon Virtual Private Cloud and the amount is small but persistent, public IPv4 is one of the first things to inspect.

As of October 2026, the price for an in-use public IPv4 address is $0.005 per hour. An idle public IPv4 address is also $0.005 per hour. Billing uses one-second increments with a 60-second minimum.

The legacy EC2 Free Tier includes an allowance for public IPv4 usage associated with qualifying EC2 Free Tier usage. That allowance is not a magic umbrella over every public IP in the account. A public IPv4 address attached to a NAT gateway, load balancer, RDS configuration, or another service can generate a charge even while your EC2-related IPv4 usage remains inside its allowance.

That creates a confusing bill. You can see some IPv4 hours priced at $0 and another group of IPv4 hours priced at $0.005. The natural conclusion is “AWS miscounted my EC2 hours.” The better question is “Which service owns the charged address?”

Start with:

aws ec2 describe-addresses

That finds Elastic IP allocations, but do not stop there. Public IPv4 can also be associated with network interfaces managed by other AWS services.

aws ec2 describe-network-interfaces \
  --query "NetworkInterfaces[*].{
    ENI:NetworkInterfaceId,
    Type:InterfaceType,
    Description:Description,
    PublicIP:Association.PublicIp,
    Status:Status
  }"

Look at the description and interface type. A service-managed network interface can tell you that the public address belongs to something other than the EC2 instance you were staring at.

IPv4 clue What it probably means Next check
Free EC2 IPv4 hours and paid IPv4 hours both appear At least one address may belong to a non-EC2 resource Network interfaces, NAT gateways, load balancers, RDS
Idle IPv4 usage An allocated address is not attached to an active resource Elastic IP addresses
No Elastic IP is visible A service-managed public address may be involved Network interfaces and service ownership

At $0.005 per hour, one continuously billed public IPv4 address over 730 hours is about $3.65. That is not a frightening bill. It is exactly the kind of bill people ignore for six months because it looks too small to investigate.

Leak #2: stopping EC2 does not stop the attached EBS volume

An EC2 instance is compute. An EBS volume is storage. They are connected in your architecture, but they are separate billable resources.

When you stop an EC2 instance, the compute stops running. Its EBS volumes normally continue to exist. EBS volume storage is billed for the capacity you provision until you release the storage.

The legacy EBS Free Tier includes 30 GB of eligible storage, 2 million I/O operations, and 1 GB of snapshot storage. Newer customers can have eligible EBS costs covered through the newer credit model instead. The key point is that the storage resource still has a price even when credits or an allowance are currently masking that price.

List volumes:

aws ec2 describe-volumes \
  --query "Volumes[*].{
    Volume:VolumeId,
    SizeGiB:Size,
    Type:VolumeType,
    State:State,
    Attachments:Attachments
  }"

A volume in the available state is not attached to an instance, but it still exists. “Available” does not mean “free.” It means the volume is available to attach.

A volume attached to a stopped instance also still exists. If the instance was a temporary lab and you want to eliminate storage charges, decide whether you need the data. If not, delete the volume. If you do need the data, preserving it has a storage cost somewhere: either on the volume or in a snapshot.

⚠️ What this actually breaks

Deleting an EBS volume deletes the data stored on that volume. A billing cleanup is not permission to remove an unknown disk because its monthly amount looks annoying. Identify the volume and decide whether its data matters first.

This is also where “terminate” and “stop” get mixed up. Stopping an instance is reversible and leaves its storage in place. Terminating an instance is intended to remove the instance, but whether a specific EBS volume is deleted with termination depends on that volume's delete-on-termination behavior. A preserved volume can therefore survive the instance that originally used it.

Leak #3: snapshots can survive every compute cleanup you perform

Snapshots are a perfect beginner billing leak because they do not look active. There is no green “running” indicator to remind you that stored backup data has a price.

An EBS snapshot is independent from the original instance. Delete the instance and the snapshot remains. Delete the original EBS volume and the snapshot remains. Move on to a completely different project and the snapshot remains until you remove it.

EBS snapshots are incremental after the first snapshot, so later snapshots store blocks that changed rather than copying the entire volume again. That makes the relationship between “my disk was 30 GB” and “how much snapshot storage am I paying for?” less obvious than a beginner expects.

List snapshots owned by your account:

aws ec2 describe-snapshots \
  --owner-ids self \
  --query "Snapshots[*].{
    Snapshot:SnapshotId,
    Volume:VolumeId,
    SizeGiB:VolumeSize,
    Created:StartTime,
    State:State
  }"

Standard EBS snapshot storage is commonly represented in AWS's current pricing examples at $0.05 per GB-month. Snapshot Archive is priced lower at $0.0125 per GB-month, but the archive tier has a 90-day minimum storage period and restoring data from archive has a separate per-GB charge.

That makes “archive everything because it is cheaper” bad advice for a temporary lab. If you delete or permanently restore an archived snapshot before the minimum archive period is complete, the remaining minimum-period storage can still be billed on a prorated basis.

Cross-Region copies add another branch. The copy can create data-transfer cost, and the destination snapshot then becomes storage in the destination Region. If you copied a snapshot while following a disaster-recovery tutorial, checking only the original Region can leave the copy behind.

Leak #4: a NAT gateway can cost more than the tiny instance it serves

A NAT gateway gives resources in a private subnet outbound connectivity without making those resources directly reachable from the public internet. In a production design that can be exactly what you need. In a beginner lab, it can be the most expensive rectangle on the diagram.

A public NAT gateway has an hourly charge while it is provisioned and a data-processing charge for the bytes that pass through it. AWS's current US pricing examples use $0.045 per NAT gateway-hour and $0.045 per GB processed. A NAT gateway also uses a public IPv4 address, so networking cost can contain more than one line.

List NAT gateways:

aws ec2 describe-nat-gateways \
  --filter Name=state,Values=available,pending \
  --query "NatGateways[*].{
    NatGateway:NatGatewayId,
    State:State,
    Vpc:VpcId,
    Subnet:SubnetId,
    Addresses:NatGatewayAddresses
  }"

Worked example: the forgotten NAT gateway

Use 730 hours for a rough full-month estimate:

730 hours × $0.045 = $32.85 for the gateway-hour component.

If 100 GB passes through it:

100 GB × $0.045 = $4.50 in NAT data processing.

The two NAT components total $37.35. That still does not necessarily represent the complete networking bill because public IPv4 and applicable data-transfer charges can be separate.

Now compare that with Jake's mental model: “I launched one tiny machine to test a private subnet.” The NAT gateway can easily become the cost story instead of the machine.

🙋‍♂️ Jake's Reality Check

"But the NAT gateway barely did anything. My test server downloaded two packages and then I forgot about it."

Ethan: "Traffic is only half the story. The gateway has an hourly meter just for being there. Never judge an AWS resource by how busy it looks."

If your architecture needs private workloads to reach only services such as Amazon S3, investigate whether the appropriate VPC endpoint can avoid sending that service traffic through the NAT gateway. Do not blindly replace networking components for cost alone, though. Security requirements and the destinations your workload needs still decide the architecture.

Leak #5: your Application Load Balancer bills before your app becomes popular

An Application Load Balancer is another resource beginners mentally attach to EC2 even though AWS bills it separately.

The ALB price has two important pieces: the hourly load-balancer charge and Load Balancer Capacity Unit consumption. Current AWS US East examples use an hourly ALB charge of $0.0225 and $0.008 per LCU-hour.

That means “nobody visited my site” does not automatically equal “my load balancer cost $0.” The load balancer itself has an hourly component.

At 730 hours, the base hourly portion alone is roughly:

730 × $0.0225 = $16.425

LCU consumption is additional. ALB LCU calculations consider dimensions such as new connections, active connections, processed bytes, and rule evaluations, with the applicable maximum driving the capacity-unit charge for the period.

List version 2 load balancers:

aws elbv2 describe-load-balancers \
  --query "LoadBalancers[*].{
    Name:LoadBalancerName,
    Type:Type,
    State:State.Code,
    Scheme:Scheme,
    DNS:DNSName
  }"

A load balancer might also have public IPv4 implications, CloudWatch metrics and logs, certificates, WAF configuration, or targets behind it. The correct cleanup question is therefore not “Can I delete this ALB?” It is “What created it, and does deleting the parent environment make more sense?”

Elastic Beanstalk, container environments, infrastructure templates, and other workflows can create load balancers for you. If you delete only the child resource while the higher-level service still believes it owns the architecture, you can create a broken deployment or a resource that comes back later.

Leak #6: CloudWatch quietly remembers what your deleted app said

CloudWatch is where many “serverless should be free” projects acquire a second bill.

Your Lambda function might remain comfortably inside its free request and compute allowances while the function writes logs on every invocation. Another service may stream application logs into CloudWatch. A load balancer or network feature may deliver logs. A debugging session might generate far more log volume than the application itself.

Current AWS examples use a Free Tier allowance around the first 5 GB for relevant CloudWatch Logs usage and a $0.50 per GB example rate for standard log ingestion after that allowance. The exact bill depends on which CloudWatch feature you use, so do not treat “CloudWatch” as one price.

List log groups:

aws logs describe-log-groups \
  --query "logGroups[*].{
    LogGroup:logGroupName,
    StoredBytes:storedBytes,
    RetentionDays:retentionInDays
  }"

Pay special attention to retention. If you created a temporary application and its log group retains data indefinitely, deleting the compute does not automatically make the historical logs disappear.

Do not solve that by setting a tiny retention value on production logs without checking your operational, security, and compliance needs. The right retention setting is a data decision first and a cost decision second.

CloudWatch also changed meaningfully during 2026. Intelligent storage tiering for CloudWatch Logs can move older log data through storage tiers based on access patterns. That can reduce the cost profile of long-retained logs, but it does not turn ingestion or every CloudWatch operation into a free service.

If the CloudWatch bill suddenly rises rather than slowly accumulating, Cost Explorer grouped by usage type is especially useful. “CloudWatch cost increased” can mean ingestion, storage, queries, metrics, alarms, dashboards, or another billable feature. Each one sends you to a different fix.

Leak #7: RDS is not one meter called “database”

RDS can produce charges from database instance hours, storage, backups and snapshots, data transfer, public IPv4 use, and configuration choices. Looking only at the database class is the RDS version of looking only at EC2 compute.

For legacy Free Tier accounts created before July 15, 2025, the RDS Free Tier includes up to 750 hours per month for eligible select Single-AZ databases during the applicable 12-month period. The legacy allowance also includes 20 GB of General Purpose SSD storage and 20 GB of automated backup storage per month. Eligible engines include MySQL, MariaDB, PostgreSQL, and SQL Server Express under the legacy offer.

Newer Free Tier customers use the credit-based model instead, so the safer question for a new account is not “Is this exact DB class one of the old free ones?” It is “How much eligible credit is this RDS architecture consuming, and what will its standard price be when the credit is gone?”

List RDS instances:

aws rds describe-db-instances \
  --query "DBInstances[*].{
    DB:DBInstanceIdentifier,
    Class:DBInstanceClass,
    Engine:Engine,
    StorageGiB:AllocatedStorage,
    MultiAZ:MultiAZ,
    Public:PubliclyAccessible,
    Status:DBInstanceStatus
  }"

Then inspect manual snapshots:

aws rds describe-db-snapshots \
  --snapshot-type manual \
  --query "DBSnapshots[*].{
    Snapshot:DBSnapshotIdentifier,
    DB:DBInstanceIdentifier,
    SizeGiB:AllocatedStorage,
    Created:SnapshotCreateTime,
    Status:Status
  }"

Manual snapshots deserve attention because they are intentionally durable. You can delete a database and preserve a final snapshot, which is useful when the data matters. It also means “the DB is gone” and “all database-related storage cost is gone” are different statements.

Cross-Region automated backups add another path. Copying backup data to another Region can create transfer charges, and destination snapshots use storage in that destination Region.

Public RDS networking can also involve standard public IPv4 charges. If the bill line sits under VPC rather than RDS, do not dismiss it just because you did not launch an EC2 instance in that Region.

Leak #8: tiny persistent resources — Route 53, KMS, and secrets

Some AWS bills survive because the remaining resource is too small to feel like infrastructure.

Route 53 hosted zones: a hosted zone is independent of the EC2 instance, S3 bucket, or load balancer its records point to. Current Route 53 pricing is $0.50 per hosted zone per month for the first 25 hosted zones and $0.10 per hosted zone per month after that. Hosted-zone pricing is generally not prorated for a partial month, although a hosted zone deleted within the short AWS testing window after creation has a specific exception.

List hosted zones:

aws route53 list-hosted-zones \
  --query "HostedZones[*].{
    Id:Id,
    Name:Name,
    Private:Config.PrivateZone
  }"

Route 53 is a global service. Do not waste time cycling through Regions looking for a hosted zone.

KMS customer managed keys: a customer managed KMS key currently has a $1 monthly key-storage charge, prorated hourly. AWS managed and AWS owned keys do not use that same customer-managed-key monthly fee. KMS also has request pricing, with 20,000 eligible requests per month in its request Free Tier across supported Regions; not every KMS operation qualifies for that allowance.

A single forgotten key is therefore a classic $1-ish mystery line. It is small, persistent, and easy to leave after the application that needed it is gone.

List keys:

aws kms list-keys

Do not immediately schedule deletion just because the key costs money. A KMS key can protect data stored elsewhere. Removing access to the encryption key can make encrypted data unusable. Find what uses the key first.

Secrets Manager: a secret is also a separately priced resource. Automatic rotation can involve Lambda. Encrypting the secret with your own customer managed KMS key introduces the KMS cost model as well. One “store my database password securely” step can therefore touch several billing systems.

Leak #9: Lambda can remain free while the serverless application costs money

Lambda's Free Tier currently includes 1 million requests and 400,000 GB-seconds of compute per month for Lambda Functions. That is enough for many small experiments to show $0 for Lambda itself.

The mistake is turning that into “my serverless app is free.”

A typical serverless application can contain:

  • Lambda for compute
  • API Gateway for HTTP requests
  • CloudWatch Logs for function output
  • S3 for object storage
  • DynamoDB for data
  • Secrets Manager for credentials
  • KMS for encryption
  • VPC networking for private resources
  • EventBridge, SQS, or SNS for events and messaging

Each service has its own meter and its own Free Tier rules.

That is why a Lambda dashboard showing 12,000 invocations tells you almost nothing about an unexpected VPC or CloudWatch charge.

For API Gateway specifically, eligible legacy trial-style offers can include free request allowances during their applicable period, while newer accounts can apply the credit model to eligible API Gateway usage. When those benefits end or are exceeded, normal API request and data-transfer pricing applies.

If the function is connected to a VPC, investigate the path it uses to reach the internet or other services. A NAT gateway added to “make Lambda internet access work” can turn a tiny function into a $30-plus monthly architecture even though Lambda itself remains inside its free compute allowance.

This is why Ethan's serverless rule for Jake is simple: “Serverless means you do not manage servers. It does not mean every service in the diagram has a $0 price.”

Leak #10: “Free plan” can mean a service bundle, not a free AWS account

AWS now uses the word “Free” in more than one context. Do not mix the AWS account Free Plan with a service-specific free pricing plan.

CloudFront flat-rate pricing plans are a useful example. The CloudFront Free flat-rate plan is $0 per month and bundles specific CloudFront delivery, AWS WAF protection, Route 53 DNS, CloudWatch Logs ingestion, TLS, edge features, and monthly S3 storage credits within the plan's rules. It has published request and data-transfer allowances, but traffic beyond those allowances does not turn into ordinary usage overage charges for the plan.

That sounds like a protective bubble, but only for the features actually included in the plan.

Additional features can still have separate pricing. Examples include some logging destinations or formats, Route 53 features outside the bundled DNS coverage, Lambda@Edge behavior where applicable, and other AWS resources behind the CloudFront distribution.

The distinction matters because “CloudFront Free plan” does not mean “every origin resource and every optional feature in my AWS account is free.”

CloudFront's pricing-plan model also changed during 2026. AWS added broader programmatic management through CLI, SDK, CloudFormation, CDK, and a pricing-plan API in September 2026. If you are following an older walkthrough that says these plans can only be managed manually in the console, that part of the walkthrough is stale.

The correct troubleshooting method does not change: look at the Bills page. If the supposedly bundled CloudFront distribution shows $0 but another AWS service has a charge, investigate that other service instead of arguing with the word “Free” in the CloudFront plan name.

Leak #11: the resource is in another Region — or another service created it

“I checked EC2 and nothing is running” is not an account-wide inventory.

The console normally shows you one Region at a time for Regional services. You can have no EC2 instances in us-east-1 and still have an RDS snapshot, load balancer, NAT gateway, EBS volume, or another resource in a Region you used last month.

Get the available Regions from the CLI:

aws ec2 describe-regions \
  --query "Regions[*].RegionName" \
  --output text

Use Cost Explorer grouped by Region before writing a giant inventory script. If only one Region shows spend for the suspicious service, you have narrowed the search immediately.

The second trap is ownership. You may genuinely never have clicked “Create load balancer,” yet still have a load balancer. Higher-level services and infrastructure tools can create resources on your behalf.

CloudFormation is the cleanest example. List stacks:

aws cloudformation list-stacks \
  --stack-status-filter \
  CREATE_COMPLETE \
  UPDATE_COMPLETE \
  UPDATE_ROLLBACK_COMPLETE

Then inspect the resources owned by a stack:

aws cloudformation list-stack-resources \
  --stack-name YOUR_STACK_NAME

If the entire stack was a lab, removing it through the owning infrastructure workflow is often cleaner than manually deleting individual children. The important word is often. A stack can contain data you intended to retain, and deletion policies can preserve specific resources. Read the resource list before deleting.

Managed environments, container platforms, databases, and deployment tools can follow the same pattern. A resource you do not remember creating is not automatically an unauthorized resource. First find its owner.

What the AWS bill line is trying to tell you

Service on bill First things to inspect Beginner mistake
Amazon Virtual Private Cloud Public IPv4, NAT gateway, network-related usage Assuming every VPC feature is free because the VPC itself was easy to create
Amazon EC2 / EC2-Other Compute, EBS volumes, snapshots, transfer, related usage Stopping the instance and assuming the whole project stopped billing
Elastic Load Balancing ALB/NLB/GWLB hours and capacity units Thinking low traffic means $0
Amazon CloudWatch Logs, metrics, alarms, queries, dashboards Looking only at Lambda because Lambda produced the logs
Amazon RDS DB hours, storage, backup, manual snapshots, transfer Checking only the DB instance class
Amazon Route 53 Hosted zones, queries, health checks and optional features Deleting the website but leaving its DNS zone
AWS KMS Customer managed keys and request usage Treating every encryption key as the same type
AWS Secrets Manager Stored secrets, API calls, rotation workflow Thinking a secret is just a setting inside Lambda or RDS

If your exact line is not in that table, do not force it into the nearest category. Read the service name and usage type literally. AWS has hundreds of separately priced features, and a billing investigation gets worse the moment you decide what the charge “must be” before reading it.

The safest order for stopping an unexpected AWS bill

A panic cleanup can cost more than the original bill if it destroys data you needed. Use a boring order.

  1. Record the charge. Service, Region, usage type, amount, and billing period.
  2. Check the account's Free Tier model. Legacy allowance, newer Free Plan, or Paid plan.
  3. Use Cost Explorer. Confirm whether the cost is historical, stable, or still increasing.
  4. Identify the actual resource. Use the service console or CLI.
  5. Find its owner. Determine whether CloudFormation or another managed service created it.
  6. Decide whether data must survive. Volumes, databases, secrets, and keys deserve special care.
  7. Delete, stop, resize, or reconfigure the correct resource.
  8. Repeat the check in other Regions.
  9. Check global services separately. Route 53 and IAM are examples of services that do not follow the same Regional hunting pattern.
  10. Return to Billing. Make sure you understand any amount that remains as historical usage.

Notice what is not in that list: “Close the AWS account immediately.” Account closure is an option when you genuinely no longer need AWS, but it is not the first troubleshooting step. You still need to understand final charges and any retained resources or data implications.

Also notice what is not there: “Take a snapshot of everything.” Snapshots cost money. Preserve data intentionally, not automatically.

How to stop the next Free Tier leak before it becomes a surprise

AWS Budgets is the practical next step after you fix the current leak.

Basic budget monitoring and notifications are available without a charge. Action-enabled budgets have separate pricing after the first two action-enabled budgets each month. Current pricing is $0.10 per day for each additional action-enabled budget. Budget Reports cost $0.01 per delivered report.

For a learning account, you do not need an elaborate FinOps setup. Create a small monthly cost budget with alerts well below the amount that would upset you.

Then keep Free Tier usage alerts enabled. They can warn when tracked Free Tier usage reaches 85 percent of a service limit. A zero-spend budget is also useful when the goal is to notice the first non-zero eligible cost as early as possible.

Cost Anomaly Detection is another useful layer when spending changes rather than simply crossing a fixed monthly threshold. In 2026 AWS expanded anomaly investigation with AI-assisted root-cause analysis that can correlate cost changes with service, account, Region, and relevant activity. That is most useful after you have enough AWS usage for “normal” spending to exist.

For Jake's little phone-shop booking page, a $5 alert is more useful than a 47-page cost-governance policy. He needs to know when the experiment stops behaving like an experiment.

The other prevention rule is procedural: every tutorial ends with cleanup. “Application deployed successfully” is not the end of the exercise. The final task is:

  • Open Bills or Cost Explorer
  • List the resources created
  • Delete temporary resources
  • Verify dependent resources
  • Check the next day for continuing cost

Do that consistently and AWS billing becomes much less surprising.

When you deleted everything and AWS still shows money

Deleting the resource and making the bill disappear are not the same event.

Possibility one: the amount is historical. If a NAT gateway existed for ten days and you delete it today, charges for the ten days it existed remain on the current bill. Deletion prevents new usage; it does not rewrite the earlier part of the month.

Possibility two: a dependent resource survived. EBS volumes, snapshots, log groups, hosted zones, public IPv4 allocations, database snapshots, KMS keys, and other resources can survive the obvious parent.

Possibility three: you cleaned the wrong Region. Cost Explorer grouped by Region is the fastest way to rule this out.

Possibility four: another service owns the resource. A higher-level deployment may have created the component or may recreate it if you delete only the child.

Possibility five: you are looking at a final charge after account closure. Closing an account does not erase usage that already occurred before closure. A final bill can still contain the month's earlier usage.

Possibility six: the bill and resource state are being treated like the same clock. Billing and cost-management views are not a live “resource exists right this second” dashboard. Use the service console to determine whether a resource currently exists and billing tools to understand recorded cost.

If the charge still cannot be mapped, prepare a support case with evidence rather than a general complaint. Include:

  • Billing month
  • Exact service name
  • Region
  • Usage type
  • Amount
  • Resource ID if identified
  • Date and approximate time you deleted or changed the resource
  • Whether the account is legacy Free Tier, Free account plan, or Paid account plan

Billing Support is the correct route for a bill you cannot explain or a request concerning an unexpected charge. Support can discuss the account's charge. It cannot make an actually consumed billable resource retroactively become part of a Free Tier offer that never covered it.

AWS Free Tier unexpected billing FAQ

Why did AWS charge me when I am on the Free Tier?

Because AWS Free Tier covers defined services, usage types, limits, credits, or offer periods. It is not a blanket promise that every resource in an AWS account costs $0. You can exceed a free allowance, use a configuration that is outside an allowance, consume eligible usage against credits, or create a separate paid resource beside the service you expected to be free.

How do I find exactly what AWS charged me for?

Open Billing and Cost Management, choose Bills, select the month, expand Charges by service, expand the charged service, then expand the Region and inspect the usage description. Use Cost Explorer grouped by Service and then Usage type to see which meter produced the amount.

Why is my free EC2 instance showing a VPC charge?

The VPC charge may come from a public IPv4 address, NAT gateway, or another networking feature rather than EC2 compute. The legacy EC2 Free Tier IPv4 allowance covers qualifying EC2 usage, not every public IPv4 address used by every AWS service.

Why am I charged $0.005 per hour for a public IPv4 address?

Public IPv4 addresses currently cost $0.005 per hour when in use and $0.005 per hour when idle. If you are seeing paid IPv4 hours beside free EC2 IPv4 hours, investigate whether another service such as a load balancer, NAT gateway, or database owns the charged address.

Does stopping an EC2 instance stop all AWS charges?

No. Stopping EC2 stops the instance compute from running, but attached EBS volumes continue to exist. Snapshots, public IPv4 resources, load balancers, NAT gateways, CloudWatch resources, DNS, and other services are separate and can continue to generate cost.

Why am I charged for EBS when my EC2 instance is stopped?

EBS is provisioned storage. Stopping compute does not delete the disk. An attached volume on a stopped instance can still have a storage cost, and an unattached volume in the available state can also continue to have a storage cost until you release it.

Why am I still paying for EBS after terminating EC2?

Check whether the EBS volume was preserved when the instance terminated, then check snapshots. A snapshot is independent of the instance and remains until deleted. Cross-Region snapshot copies can also leave storage in another Region.

Is a NAT gateway free on AWS Free Tier?

Do not treat a NAT gateway as part of the EC2 Free Tier. A public NAT gateway has an hourly price and a separate data-processing price. Current AWS US pricing examples use $0.045 per gateway-hour and $0.045 per GB processed, with other networking costs potentially applying as well.

Can a load balancer charge me even with almost no traffic?

Yes. An Application Load Balancer has a base hourly charge in addition to Load Balancer Capacity Unit usage. Low traffic can keep the LCU component small, but it does not remove the hourly load-balancer component.

Can CloudWatch charge me even when Lambda is inside the Free Tier?

Yes. Lambda and CloudWatch are separately priced services. A function can remain inside Lambda's 1 million monthly free requests and 400,000 GB-seconds while its logging or other CloudWatch usage creates a separate cost.

Can Route 53 charge me after I delete my website?

Yes. A hosted zone is independent of the EC2 instance, load balancer, or bucket that your DNS records referenced. Deleting the application does not automatically delete the Route 53 hosted zone.

Can one KMS key really create a monthly AWS charge?

Yes. A customer managed AWS KMS key currently has a $1 per-month key-storage price, prorated hourly. Do not delete the key solely to remove the bill until you know which encrypted resources depend on it.

Why does AWS still show charges after I deleted everything?

Charges already incurred earlier in the month remain. You might also have a surviving child resource, a resource in another Region, a global resource, or a resource created by another AWS service. Use the bill's service, Region, and usage type rather than assuming deletion failed.

How do I check AWS Free Tier usage with the CLI?

Run aws freetier get-free-tier-usage. It can return the service, operation, usage type, actual usage, forecasted usage, applicable limit, and Free Tier offer information for trackable benefits on the account.

Does AWS automatically stop resources before I get charged?

Do not rely on AWS Free Tier as an account-wide automatic shutdown system. Paid accounts can continue using services and incur ordinary charges after applicable free benefits or credits are exhausted. The newer Free account plan has its own account-expiration behavior, but that is different from a hard spending cap on a Paid account.

Can AWS Support remove an unexpected Free Tier charge?

You can contact AWS Billing Support to ask about an unexpected bill or appeal a charge. Provide the billing month, service, Region, usage type, amount, and resource ID when available. A refund or adjustment should never be assumed in advance, so stop continuing usage first and then discuss the existing charge.

The five-minute AWS Free Tier leak check

If you opened this page because a real charge is staring at you right now, ignore the temptation to inspect every AWS service you have ever heard of.

Go to Bills. Find the non-zero service. Open the Region. Read the usage type.

If the service is VPC, look for public IPv4 and NAT resources first. If it is EC2-related storage, list EBS volumes and snapshots. If it is Elastic Load Balancing, list load balancers and find the service that created them. If it is CloudWatch, inspect log groups, retention, metrics, alarms, and query usage. If it is RDS, inspect the database, storage, backups, snapshots, and networking. If it is Route 53, list hosted zones. If it is KMS, find customer managed keys and what depends on them.

Then check Region. A spotless us-east-1 console proves nothing about us-west-2.

Then check ownership. A CloudFormation stack, managed environment, or deployment tool can be the reason a resource exists even when you never created that child resource manually.

Finally, remember what the Free Tier actually promises. It gives you specific free usage or credits. It does not erase the underlying price of your architecture.

Jake eventually stopped asking Ethan, “Why is AWS charging my free server?” He started asking, “Which meter on this month's bill moved?” That second question is not as dramatic, but it gets him to the answer much faster.

If you find a charge this article does not explain, save the exact service name and usage type before contacting Support. Those two lines are more useful than twenty screenshots of an empty EC2 Instances page. I hope your leak turns out to be one forgotten resource, you shut off the right meter without losing anything important, and tomorrow's cost graph is boring again.

📌 If you keep one line from this page

Free Tier covers specific usage; it does not make everything connected to a free resource free.

Read the bill's usage type before you decide which resource is guilty.

Revision note. Written October 3, 2026, with the credit-based Free Plan in place. A few cents you can't explain are worth chasing today; find the service and Region once, and the next surprise has fewer places to hide.

Related