Amazon Route 53 Health Checks: IPs & Locations
Verified Amazon Route 53 Health Checks IP Addresses. Copy-Paste Firewall-Setups.
Every official Amazon Route 53 Health Checks monitoring IP—verified in real-time against the canonical source, featuring ready-to-use firewall templates. Stop false downtime alerts caused by blocked checking nodes on your infrastructure.
Made and Hosted in the
European Union
GDPR-Compliant Hosting
in Germany
GEO-Redundant Replica
across the EU
Three-Step Activation & Frictionless Firewall Alignment
Bring your perimeter security rules up to date in three simple steps. Our production-ready configuration templates for common server architectures eliminate fragmented routing filters and costly check flapping.
31 IPv4 and 26 IPv6 ranges from health checkers across AWS regions — one click below copies everything as a plain list or as ready-to-paste UFW, nginx, or Apache config.
Add every address to your allow list — UFW, nginx, Apache, or a Cloudflare/WAF skip rule. Partial lists cause flapping checks and false alerts.
Amazon Route 53 Health Checks updates its list occasionally. This page was verified on 2026-06-12 against the official source — re-check after unexplained alerts or automate the sync.
Official Amazon Route 53 Health Checks Monitoring IPs
AWS publishes every range in ip-ranges.json — health-checker traffic is the ROUTE53_HEALTHCHECKS service.
Amazon Route 53 health checks probe your endpoints from health checkers in multiple AWS regions to drive DNS failover. If your firewall blocks those checkers, Route 53 marks healthy endpoints as unhealthy — and fails traffic over even though nothing is wrong.
Whitelist the ranges below exactly as listed; they come from the ROUTE53_HEALTHCHECKS service entries of the official AWS ip-ranges.json.
This list contains 31 IPv4 and 26 IPv6 ranges, verified against the official source on 2026-06-12.
IPv4 addresses 31
- 51.0.252.0/24
- 15.177.0.0/18
- 15.177.108.0/24
- 52.80.197.0/25
- 52.80.197.128/25
- 52.80.198.0/25
- 52.83.34.128/25
- 52.83.35.0/25
- 52.83.35.128/25
- 18.253.167.0/25
- 18.253.167.128/25
- 18.253.168.0/25
- 160.1.55.0/25
- 160.1.55.128/25
- 160.1.56.0/25
- 54.248.220.0/26
- 54.250.253.192/26
- 54.251.31.128/26
- 54.255.254.192/26
- 54.252.254.192/26
- 54.252.79.128/26
- 176.34.159.192/26
- 54.228.16.0/26
- 177.71.207.128/26
- 54.232.40.64/26
- 107.23.255.0/26
- 54.243.31.192/26
- 54.183.255.128/26
- 54.241.32.64/26
- 54.244.52.192/26
- 54.245.168.0/26
IPv6 addresses 26
- 2600:f0f0:30f::/48
- 2600:f0f0:30e::/48
- 2600:f0f0:300:100::/56
- 2001:3fc6:100::/48
- 2400:7fc0:83cc:cc00::/56
- 2400:7fc0:83cc:cd00::/56
- 2400:7fc0:83cc:ce00::/56
- 2404:c2c0:83cc:cc00::/56
- 2404:c2c0:83cc:cd00::/56
- 2404:c2c0:83cc:ce00::/56
- 2406:da14:7ff:f800::/56
- 2406:da14:fff:f800::/56
- 2406:da18:7ff:f800::/56
- 2406:da18:fff:f800::/56
- 2406:da1c:7ff:f800::/56
- 2406:da1c:fff:f800::/56
- 2a05:d018:7ff:f800::/56
- 2a05:d018:fff:f800::/56
- 2600:1f1e:7ff:f800::/56
- 2600:1f1e:fff:f800::/56
- 2600:1f18:3fff:f800::/56
- 2600:1f18:7fff:f800::/56
- 2600:1f1c:7ff:f800::/56
- 2600:1f1c:fff:f800::/56
- 2600:1f14:7ff:f800::/56
- 2600:1f14:fff:f800::/56
Last verified: 2026-06-12
Official source: https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/route-53-ip-addresses.html
Where Amazon Route 53 Health Checks Checks From
Official location data from the provider — addresses grouped by check location.
| Location | IP addresses |
|---|---|
| GLOBAL | 15.177.0.0/18 |
| ap-northeast-1 | 54.248.220.0/26 · 54.250.253.192/262406:da14:7ff:f800::/56 · 2406:da14:fff:f800::/56 |
| ap-southeast-1 | 54.251.31.128/26 · 54.255.254.192/262406:da18:7ff:f800::/56 · 2406:da18:fff:f800::/56 |
| ap-southeast-2 | 54.252.254.192/26 · 54.252.79.128/262406:da1c:7ff:f800::/56 · 2406:da1c:fff:f800::/56 |
| cn-north-1 | 52.80.197.0/25 · 52.80.197.128/25 · 52.80.198.0/252400:7fc0:83cc:cc00::/56 · 2400:7fc0:83cc:cd00::/56 · 2400:7fc0:83cc:ce00::/56 |
| cn-northwest-1 | 52.83.34.128/25 · 52.83.35.0/25 · 52.83.35.128/252404:c2c0:83cc:cc00::/56 · 2404:c2c0:83cc:cd00::/56 · 2404:c2c0:83cc:ce00::/56 |
| eu-central-1 | 2600:f0f0:30f::/48 |
| eu-west-1 | 176.34.159.192/26 · 54.228.16.0/262a05:d018:7ff:f800::/56 · 2a05:d018:fff:f800::/56 |
| eusc-de-east-1 | 51.0.252.0/242001:3fc6:100::/48 |
| sa-east-1 | 177.71.207.128/26 · 54.232.40.64/262600:1f1e:7ff:f800::/56 · 2600:1f1e:fff:f800::/56 |
| us-east-1 | 107.23.255.0/26 · 54.243.31.192/262600:1f18:3fff:f800::/56 · 2600:1f18:7fff:f800::/56 |
| us-gov-east-1 | 18.253.167.0/25 · 18.253.167.128/25 · 18.253.168.0/25 |
| us-gov-west-1 | 160.1.55.0/25 · 160.1.55.128/25 · 160.1.56.0/25 |
| us-south-1 | 15.177.108.0/24 |
| us-west-1 | 54.183.255.128/26 · 54.241.32.64/262600:1f1c:7ff:f800::/56 · 2600:1f1c:fff:f800::/56 |
| us-west-2 | 54.244.52.192/26 · 54.245.168.0/262600:f0f0:30e::/48 · 2600:f0f0:300:100::/56 · 2600:1f14:7ff:f800::/56 · 2600:1f14:fff:f800::/56 |
Whitelisting Amazon Route 53 Health Checks-Monitoring IPs
Pick a format — the block below contains the complete config for every address in the list above. The plain list is also available as a .txt download.
ufw allow from 51.0.252.0/24 ufw allow from 15.177.0.0/18 ufw allow from 15.177.108.0/24 ufw allow from 52.80.197.0/25 ufw allow from 52.80.197.128/25 ufw allow from 52.80.198.0/25 ufw allow from 52.83.34.128/25 ufw allow from 52.83.35.0/25 ufw allow from 52.83.35.128/25 ufw allow from 18.253.167.0/25 ufw allow from 18.253.167.128/25 ufw allow from 18.253.168.0/25 ufw allow from 160.1.55.0/25 ufw allow from 160.1.55.128/25 ufw allow from 160.1.56.0/25 ufw allow from 54.248.220.0/26 ufw allow from 54.250.253.192/26 ufw allow from 54.251.31.128/26 ufw allow from 54.255.254.192/26 ufw allow from 54.252.254.192/26 ufw allow from 54.252.79.128/26 ufw allow from 176.34.159.192/26 ufw allow from 54.228.16.0/26 ufw allow from 177.71.207.128/26 ufw allow from 54.232.40.64/26 ufw allow from 107.23.255.0/26 ufw allow from 54.243.31.192/26 ufw allow from 54.183.255.128/26 ufw allow from 54.241.32.64/26 ufw allow from 54.244.52.192/26 ufw allow from 54.245.168.0/26 ufw allow from 2600:f0f0:30f::/48 ufw allow from 2600:f0f0:30e::/48 ufw allow from 2600:f0f0:300:100::/56 ufw allow from 2001:3fc6:100::/48 ufw allow from 2400:7fc0:83cc:cc00::/56 ufw allow from 2400:7fc0:83cc:cd00::/56 ufw allow from 2400:7fc0:83cc:ce00::/56 ufw allow from 2404:c2c0:83cc:cc00::/56 ufw allow from 2404:c2c0:83cc:cd00::/56 ufw allow from 2404:c2c0:83cc:ce00::/56 ufw allow from 2406:da14:7ff:f800::/56 ufw allow from 2406:da14:fff:f800::/56 ufw allow from 2406:da18:7ff:f800::/56 ufw allow from 2406:da18:fff:f800::/56 ufw allow from 2406:da1c:7ff:f800::/56 ufw allow from 2406:da1c:fff:f800::/56 ufw allow from 2a05:d018:7ff:f800::/56 ufw allow from 2a05:d018:fff:f800::/56 ufw allow from 2600:1f1e:7ff:f800::/56 ufw allow from 2600:1f1e:fff:f800::/56 ufw allow from 2600:1f18:3fff:f800::/56 ufw allow from 2600:1f18:7fff:f800::/56 ufw allow from 2600:1f1c:7ff:f800::/56 ufw allow from 2600:1f1c:fff:f800::/56 ufw allow from 2600:1f14:7ff:f800::/56 ufw allow from 2600:1f14:fff:f800::/56
Cloudflare / WAF: create an IP Access Rule (or custom WAF skip rule) with action Allow for the addresses above, so bot fight mode and managed challenges never block probe traffic.
Whitelisting only exempts these addresses from blocking and rate-limiting rules — it grants no access beyond what your site already serves publicly.
Frequently Asked Questions
From the official AWS ip-ranges.json, filtered to the ROUTE53_HEALTHCHECKS service. AWS also offers SNS notifications for ip-ranges.json changes — ideal to automate your allow list.
Route 53 needs a quorum of checkers to see your endpoint as healthy. Blocked checkers vote "unhealthy", which can trigger DNS failover away from a perfectly fine endpoint.
Yes — ip-ranges.json publishes IPv6 ranges for ROUTE53_HEALTHCHECKS as well. Whitelist both lists if your endpoints are dual-stacked.
Both — wherever requests can be blocked. If your site sits behind a CDN or WAF (Cloudflare, AWS WAF, Akamai…), add an allow/skip rule there so probes are never challenged; if your origin firewall also filters traffic, whitelist them there too. A single missed layer is enough to cause false alerts.
Most providers expose a machine-readable source (linked above). Fetch it on a schedule — a small cron job that pulls the list and updates your firewall ruleset — instead of hardcoding addresses by hand. This page is re-verified against the official source regularly, but automation on your side is the most reliable option.
No. Allow-listing only exempts known monitoring addresses from blocking and rate-limiting rules — it grants no access beyond what your site already serves publicly, and authentication, authorization, and TLS are unchanged. You are simply telling your firewall "these are not attackers".
A blocklist keeps known-bad addresses out; an allow/whitelist makes sure known-good addresses — here, the monitoring probes — never end up caught in a block or rate-limit rule. The two coexist: you keep blocking attackers while explicitly exempting the probes.
The IP addresses on this page belong to Amazon Route 53 Health Checks and are published by Amazon Route 53 Health Checks for whitelisting purposes. List verified on 2026-06-12 against the official source. Always cross-check with the official documentation before locking down production firewalls. All product names and trademarks are the property of their respective owners; Uptimeify is not affiliated with Amazon Route 53 Health Checks. Uptimeify's own worker IPs are published at /ips.txt; a feature comparison is on our comparison page.
Monitoring Without IP Guesswork.
Protect your clients' digital assets and lock down your webserver routing. Leverage our verified network catalogs for clean whitelist setups, or migrate directly to the rock-solid, EU-only architecture of Uptimeify.