# Low Cache Hit Ratio on CloudFront Distributions

Canonical: https://www.pointfive.co/efficiency-hub/inefficiencies/low-cache-hit-ratio-on-cloudfront-distributions

A CloudFront distribution only saves origin cost when it serves responses from cache.

By: PointFive

Updated: 2026-09-28

[Cloud Efficiency Hub](https://www.pointfive.co/efficiency-hub) 

The short version

A CloudFront distribution only saves origin cost when it serves responses from cache.

PointFive Research

Cloud cost research at PointFive

AWS service

[AWS CloudFront](https://www.pointfive.co/efficiency-hub/cloud-services/aws-cloudfront)

Category

[Networking](https://www.pointfive.co/efficiency-hub/service-category/networking)

Reference

CER-0351

Type

Inefficient Configuration

## Explanation

Why the waste happens and who it affects.

When cache behaviors include all query strings, all cookies or high-cardinality headers such as User-Agent in the cache key, or when objects carry short Cache-Control max-age values, CloudFront treats near-identical requests as distinct objects and forwards most of them to the origin. The CDN is in place, but the origin still handles close to the full request volume.

Each miss is paid for at the origin: S3 GET requests, load balancer capacity units, EC2, container or Lambda compute, and for origins outside AWS, the other provider's egress charges. CloudFront bills every viewer request whether it is a hit or a miss. The pattern is common on distributions created with a single default behavior that forwards everything so the application works, and it matters most on busy websites, APIs and media delivery.

## Billing model

The pricing dimensions that drive this cost.

A cache miss is billed twice: once by CloudFront for the viewer request and delivery, and again by the origin for serving the request.

CloudFront requests and delivery

Billed per 10,000 requests and per GB delivered to viewers, for both cache hits and cache misses

Origin request cost

Each miss generates an origin request billed by the origin service, such as S3 request charges or load balancer and compute usage

Origin fetch data transfer

Free from AWS origins to CloudFront, but billed by the other provider when the origin is outside AWS

Origin Shield requests

Optional extra caching layer billed per 10,000 requests that reach Origin Shield from other regional caches

## How to detect

4 checks to find it in your estate.

- Turn on the additional distribution metrics (billed as a fixed monthly CloudWatch charge per metric) and review Cache hit rate, the percentage of cacheable requests served from cache, alongside Requests and Origin latency on the CloudFront Monitoring page

- Use the CloudFront cache statistics report or the x-edge-result-type field in standard access logs to see the share of Hit, RefreshHit and Miss results by path

- Inspect each cache behavior's cache policy for cache keys that include all query strings, all cookies or headers with many unique values such as User-Agent

- Check Cache-Control max-age on static objects served by the origin, and compare origin request volume (for example S3 GET requests or ALB request count) with CloudFront Requests

## How to fix

5 ways to remove the waste.

- Include in the cache key only the query strings, cookies and headers that actually change the response, and normalize parameter case and order in the application

- Split static and dynamic content into separate cache behaviors, forwarding cookies only on the dynamic paths, and use managed cache policies such as CachingOptimized for static assets

- Set the longest practical max-age on static objects, and use stale-while-revalidate and stale-if-error where the origin supports them

- Replace User-Agent in the cache key with CloudFront device-type headers when responses vary only by device class

- Enable Origin Shield for origins that serve many edge locations when its per-request fee is lower than the origin load it removes; for fully personalized responses that cannot be cached, accept the lower hit rate rather than risk serving wrong content

## Documentation

Vendor references for pricing and configuration.

- [Increase the proportion of requests that are served directly from the CloudFront caches (cache hit ratio)  docs.aws.amazon.com](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/cache-hit-ratio.html)

- [View CloudFront and edge function metrics  docs.aws.amazon.com](https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/viewing-cloudfront-metrics.html)

- [Amazon CloudFront pay-as-you-go pricing  aws.amazon.com](https://aws.amazon.com/cloudfront/pricing/pay-as-you-go/)

- [COST08-BP03 Implement services to reduce data transfer costs  docs.aws.amazon.com](https://docs.aws.amazon.com/wellarchitected/latest/framework/cost_data_transfer_implement_services.html)

## Related inefficiencies

[Browse the library](https://www.pointfive.co/efficiency-hub)

- AWS CloudFront  CER-0350

### [Internet Traffic Served Directly from S3 or EC2 Instead of CloudFront](https://www.pointfive.co/efficiency-hub/inefficiencies/internet-traffic-served-directly-from-s3-or-ec2-instead-of-cloudfront)

Public websites, static assets, software downloads, media and APIs are often served straight from an S3 bucket, an EC2 instance or an internet-facing load balancer. Every byte then leaves AWS as regional data transfer out to the internet,...

Networking

- AWS CloudFront  CER-0352

### [CloudFront Price Class Broader Than the Audience](https://www.pointfive.co/efficiency-hub/inefficiencies/cloudfront-price-class-broader-than-the-audience)

By default, a CloudFront distribution delivers content from its entire global network of edge locations, which is Price Class All. CloudFront pay-as-you-go rates depend on the geography of the edge that serves the request, and data...

Networking

- AWS S3  CER-0161

### [Missing S3 Gateway Endpoint for Intra-Region EC2 Access](https://www.pointfive.co/efficiency-hub/inefficiencies/missing-s3-gateway-endpoint-for-intra-region-ec2-access)

When EC2 instances in private subnets access Amazon S3 in the same region without a Gateway VPC Endpoint, traffic is routed through a NAT Gateway to the public S3 endpoint. Data transfer from S3 to EC2 in the same region is free, but every...

Networking

---
Source: the public page above. Product screenshots and illustrative interfaces are examples, not live customer data.

