Loading...


Updated 30 Sep 2026 • 5 mins read

AWS charges $0.005 per hour for every public IPv4 address, including Elastic IPs, whether in use or idle, which adds up fast across instances, load balancers, and NAT Gateways. This guide explains exactly what is billed, what is exempt, what it costs at scale in US dollars, and eight ways to cut it.
For most of AWS's history, a public IP address was something you got with an instance and never thought about. That ended on February 1, 2024, when AWS began charging for every public IPv4 address in every account, attached or not. The rate is small, half a cent an hour, which is exactly why it is dangerous: it is too small to notice on any single resource and large enough, multiplied across a fleet of instances, load balancers, NAT Gateways, and forgotten Elastic IPs, to become one of the fastest-growing lines on a bill nobody audits.
This guide explains what AWS actually bills for, which addresses are exempt, what the charge costs at realistic scale in US dollars, how to find every address you are paying for, and the eight changes that reduce the bill. All rates are from the official Amazon VPC pricing page and the AWS announcement of the charge, current as of September 2026.
The short answer: AWS charges $0.005 per hour for every public IPv4 address, about $3.65 a month or $43.80 a year, whether the address is in use or idle. The charge applies to Elastic IPs and to every Amazon-provided public IP on EC2 instances, load balancers, NAT Gateways, RDS endpoints, Global Accelerator, and Site-to-Site VPN. IPv6 addresses and addresses you bring yourself (BYOIP) are exempt, and new accounts get 750 free in-use hours a month for the first year. A fleet of 100 public addresses costs about $365 a month; the fix is to release idle Elastic IPs, move workloads behind shared load balancers and NAT Gateways in private subnets, and adopt IPv6 where possible.
The rule is simpler than the billing line items suggest: if an address is a public IPv4 address and it exists in your account, it bills $0.005 for every hour it exists. AWS applies this through two usage types. PublicIPv4:InUseAddress covers addresses attached to a running resource, including the Amazon-provided public IP an EC2 instance receives automatically, an Elastic IP associated with a running instance, and the addresses behind load balancers, NAT Gateways, and other services. PublicIPv4:IdleAddress covers Elastic IPs that are allocated but not associated with anything, or associated with a stopped instance. Both bill at the same rate. The Elastic IP documentation describes the mechanics; the table below shows what that means per resource.
| Resource | Public IPv4 addresses | Approx. monthly IP charge |
|---|---|---|
| EC2 instance with a public IP or Elastic IP | 1 | $3.65 |
| Elastic IP, idle or on a stopped instance | 1 | $3.65 |
| Application or Network Load Balancer | 1 per Availability Zone (typically 2 or 3) | $7.30 to $10.95 |
| NAT Gateway | 1 per gateway | $3.65 (plus the gateway's own hourly and per-GB fees) |
| RDS instance with a public endpoint | 1 | $3.65 |
| Amazon-provided contiguous IPv4 block | Every address in the block, from provisioning | $0.008 per address-hour, about $5.84 each |
| IPv6 address (any resource) | n/a | Free |
| BYOIP or customer-owned IP | n/a | Exempt from the public IPv4 charge |
Two details in that table catch teams out. Load balancers use at least one address per Availability Zone, so a three-AZ ALB pays for three addresses even when it is idle. And Elastic IPs bill from the moment they are allocated, not from the moment they are used, so an address reserved for a future project or left behind by a deleted instance costs the same as one serving production traffic.
Half a cent an hour is easy to dismiss until it is multiplied. The arithmetic is address count times $0.005 times 730 hours.
| Resource | Public IPv4 addresses | Approx. monthly IP charge |
|---|---|---|
| EC2 instance with a public IP or Elastic IP | 1 | $3.65 |
| Elastic IP, idle or on a stopped instance | 1 | $3.65 |
| Application or Network Load Balancer | 1 per Availability Zone (typically 2 or 3) | $7.30 to $10.95 |
| NAT Gateway | 1 per gateway | $3.65 (plus the gateway's own hourly and per-GB fees) |
| RDS instance with a public endpoint | 1 | $3.65 |
| Amazon-provided contiguous IPv4 block | Every address in the block, from provisioning | $0.008 per address-hour, about $5.84 each |
| IPv6 address (any resource) | n/a | Free |
| BYOIP or customer-owned IP | n/a | Exempt from the public IPv4 charge |
The cost is rarely the largest line on an AWS bill, but it is among the least justified, because a large share of the addresses behind it are not doing anything a private address or a shared endpoint could not do. That makes it a classic case of the cloud waste that accumulates because it is small per item and invisible per resource, and a good first target in any AWS cost optimization pass.
Three carve-outs matter. The EC2 free tier includes 750 hours a month of in-use public IPv4 for the first 12 months of a new account, enough for one address running continuously, and it does not cover idle addresses at all. IPv6 addresses are free on every resource, without limit, which is the exemption AWS most wants you to use. And addresses you bring to AWS yourself through Bring Your Own IP, or customer-owned addresses on Outposts, are exempt from the per-address charge, although IPAM and related services can still bill. For an organization that already owns IPv4 space, BYOIP removes the fee entirely; for one that does not, the market price of IPv4 addresses generally makes buying them to avoid a $3.65 monthly fee a poor trade.
Before reducing the charge, inventory it. In Cost Explorer or the Cost and Usage Report, filter on the two PublicIPv4 usage types to see in-use and idle spend separately, by region and, with the resource-level report, by resource ID. Amazon VPC IP Address Manager offers a free-tier Public IP Insights view that lists every public IPv4 address in the account with its type and attachment, which is the fastest way to find idle Elastic IPs and load balancers with no healthy targets. Because the charge is billed against the network interface rather than the instance, tag network interfaces with the same owner tags as the resources they belong to, or the cost will land in an unattributed bucket. That attribution step is the difference between a number and an owner, which is the whole subject of our guide to allocating cloud costs to teams.
Consider a mid-size estate with 40 EC2 instances carrying public IPs, six three-AZ Application Load Balancers, four NAT Gateways, three RDS instances with public endpoints, and 15 idle Elastic IPs left over from decommissioned projects. That is 40 plus 18 plus 4 plus 3 plus 15, or 80 public IPv4 addresses, costing about $292 a month, roughly $3,500 a year, before any data transfer.
Now apply the levers. Releasing the 15 idle Elastic IPs removes $55 a month at no risk. Moving 30 of the 40 instances into private subnets, since they only serve traffic through the load balancers, removes another $110. Consolidating six load balancers into two removes about $44. Moving the RDS endpoints private, which they almost certainly should be for security reasons anyway, removes $11. The estate now runs on about 20 addresses at roughly $73 a month, a 75 percent reduction, with no loss of function and a smaller attack surface as a side effect. The remaining $73 is the legitimate cost of the public endpoints that genuinely need to exist.
Not every public address is waste. Internet-facing load balancers need their addresses. A NAT Gateway serving a busy private subnet is cheaper than the per-instance addresses it replaces. Bastion alternatives require Systems Manager setup that some teams have not done. And some workloads, particularly legacy applications and third-party integrations that whitelist a fixed source IP, need a stable Elastic IP that cannot be replaced by anything else. The goal is not zero public IPv4 addresses; it is zero public IPv4 addresses that are not earning their $3.65.
Elastic IP charges are a small rate applied to a large and usually unexamined count. The rate is fixed at $0.005 an hour and the exemptions are narrow, so the bill is decided entirely by how many public IPv4 addresses exist in your account, and most estates carry far more than they need: idle Elastic IPs, auto-assigned public IPs on instances that never see inbound traffic, and load balancers serving nothing. Inventory them, release what is idle, move what can move into private subnets, share what can be shared, and reach for IPv6 where clients allow. Then keep watching, because addresses accumulate the same way every other small cloud charge does, which is why per-resource visibility of the kind Opslyft's cost visibility provides matters more for charges like this one than for the large lines everyone already tracks. For the wider set of small charges that inflate AWS bills, see our guide to AWS cost management mistakes.
An Elastic IP costs $0.005 per hour, about $3.65 a month or $43.80 a year, whether it is attached to a running resource or sitting idle. Since February 1, 2024, AWS applies this rate to every public IPv4 address in your account, including Amazon-provided public IPs on EC2 instances, load balancers, NAT Gateways, and RDS endpoints, not only Elastic IPs. IPv6 addresses are free.
Not any more. Before February 2024, an Elastic IP attached to a running instance was free and only idle ones were charged. Now every public IPv4 address costs $0.005 per hour in use or idle. The only exception is the EC2 free tier, which includes 750 hours a month of in-use public IPv4 for the first 12 months of a new account, and it does not cover idle addresses.
Because idle Elastic IPs have always been billed, and since February 2024 they cost the same $0.005 per hour as in-use ones. An Elastic IP allocated to your account but not associated with a running resource, or attached to a stopped instance, bills every hour it exists. Releasing it stops the charge immediately.
In AWS Cost Explorer or the Cost and Usage Report, filter on the usage types PublicIPv4:InUseAddress and PublicIPv4:IdleAddress, which separate active from idle charges. Amazon VPC IP Address Manager (IPAM) offers a free Public IP Insights view that lists every public IPv4 address in your account, its type, and what it is attached to.
Release idle Elastic IPs, move instances that do not need inbound internet access into private subnets behind a NAT Gateway or load balancer, use EC2 Instance Connect Endpoint or Systems Manager instead of a public IP for administrative access, consolidate services behind a shared load balancer, and adopt IPv6 where clients support it, since IPv6 addresses carry no charge.
Yes. AWS charges only for public IPv4 addresses; IPv6 addresses are free. Dual-stack or IPv6-only architectures eliminate the per-address fee for traffic that can use IPv6, which is why AWS positioned the charge partly as an incentive to accelerate IPv6 adoption.
Yes. Addresses you bring to AWS through Bring Your Own IP (BYOIP), or customer-owned IPs on Outposts, are exempt from the $0.005 per hour public IPv4 charge, though IPAM and other related charges can still apply. For organizations that already own IPv4 space, BYOIP removes the fee entirely; for those that do not, the cost of leasing or buying addresses usually exceeds it.