Failure states

Setup can stop before the shield is live. The site page says what happened, whether DNS changed, and that nothing was blocked. Each case has one next step: retry, this page, or email Mac. After DNS is live, a high CloudFront 5xx rate can show a card. That card does not change DNS or WAF mode.

Before a site is saved

Enter a domain like example.com. Leave off https:// and any path. Nothing was created.

You already have example.com on this account. Open it from the sites list and continue there. We did not create a second site. DNS was not changed.

CloudFront cannot use an IP address as the origin. Enter the hostname your host gave you. Nothing was created. DNS was not changed.

Enter the hostname only, like origin.example.com. Leave off https:// and any path. Nothing was created.

That origin is a name this shield will answer for. After DNS points here, CloudFront would call itself and the site would loop. Enter the hostname the site lives on now. Nothing was created. DNS was not changed.

That origin is not a hostname CloudFront can call. Use a name like origin.example.com. Nothing was created. DNS was not changed.

Those messages are on the add-a-site form. Nothing is created, DNS is not changed, and nothing is blocked.

On the site page

Needs attention uses the sentences below. A retry reuses a certificate or edge that was already saved. It does not create a second shield, it does not change DNS, and it does not switch any rule to block.

What the site page says
What you seeWhat happenedChanged or blockedNext
This name is already on CloudFrontCloudFront refused the shield because this hostname is already attached to another distribution.We stopped before attaching a second one. DNS was not changed. Nothing is blocked. Rules stay in count until you click Promote.Next: email Mac. Retry will fail until that name is free.
This domain already has a DNS zoneWe could not create a DNS zone because this domain is already attached to another zone.Your registrar was not changed. DNS was not changed. Nothing is blocked. Rules stay in count until you click Promote.Next: email Mac. Retry will not create a second zone while that conflict remains.
Setup hit an account limitAWS refused to finish the shield because an account limit was reached (certificates, web ACLs, or distributions).Setup did not finish. DNS was not changed. Nothing is blocked. Rules stay in count until you click Promote.Next: email Mac. Retry will fail until that limit is raised.
Setup was refusedAWS refused the shield because this app is not allowed to create it.Setup did not finish. DNS was not changed. Nothing is blocked. Rules stay in count until you click Promote.Next: email Mac. Retry will not fix a permission error.
Setup was asked to slow downAWS asked us to slow down before the shield finished.Setup did not finish. DNS was not changed. Nothing is blocked. Rules stay in count until you click Promote.Next: retry setup in a minute.
The validation record is not readyThe certificate was requested, but the SSL validation record was not ready to show yet.We kept that certificate so a retry does not request a second one. DNS was not changed. Nothing is blocked. Rules stay in count until you click Promote.Next: retry setup. The record usually appears within a minute.
The certificate is not issued yetCloudFront refused the certificate because it is not issued for this hostname yet.The certificate request was kept. DNS was not changed. Nothing is blocked. Rules stay in count until you click Promote.Next: retry setup after the certificate shows as issued. If it stays pending, open Failure states.
CloudFront rejected the originCloudFront rejected the origin hostname saved on this site. It needs a hostname, not an IP address and not the public name visitors type.The shield was not attached. DNS was not changed. Nothing is blocked. Rules stay in count until you click Promote.Next: delete this site and add it again with the hostname your host gave you.
Nameservers are not readyWe could not create the DNS zone for this domain, so there are no nameservers to set at your registrar.Your registrar was not changed. DNS was not changed. Nothing is blocked. Rules stay in count until you click Promote.Next: retry setup. If nameservers still do not appear, email Mac.
Setup stopped partwaySetup stopped after part of the shield already existed (a certificate, a web ACL, or a CloudFront distribution).Those stay on this site so a retry reuses them instead of creating a second shield. DNS was not changed. Nothing is blocked. Rules stay in count until you click Promote.Next: retry setup.
Setup needs attentionSetup did not finish. Retry below — that does not change DNS and does not block anything. If it fails again, email Mac. Rules still start in count. Promote Copilot explains what's safe to block, and you click Promote.DNS was not changed. Nothing is blocked. Rules stay in count until you click Promote.Next: retry setup. If it fails again, email Mac.

Managed DNS with no nameservers shows “Nameservers are not ready” even before the status is error. Retry asks for the zone again.

Certificate pending is a wait, not an error. The page says the certificate usually issues within a few minutes, sometimes up to 30, and that no further DNS change is needed. If it is still pending after 30 minutes, open this page and then email Mac.

DNS check

Recheck that cannot reach the checker says: We couldn't reach the checker. Try again, or wait — this tab re-checks on its own. That is not a DNS match and not a failed cutover.

A lookup that cannot read nameservers, or a traffic lookup that is inconclusive, says so and points here. It does not report a match.

Trial not active

The trial or subscription is not active, so we did not stand up or change this shield. DNS was not changed. Nothing is blocked. Next: start checkout on this page, then return to the site and retry.

That line is on Billing when a start or a retry is blocked because the subscription is not active. A shield that is already up is not torn down by that check.

Removing a site that did not finish

Removal did not finish. This site is still here so you can try again. CloudFront can take several minutes to turn off. DNS was not changed. Nothing new was blocked. Next: try delete again shortly, or email Mac.

This site is tied to a platform edge, so it was not removed. DNS was not changed. Next: email Mac if it should be unlinked.

Couldn't remove this site. Nothing else was changed. Next: try again, or email Mac.

Origin errors after DNS is live

We do not call your origin while standing up the shield or after it is live. There is no automatic origin probe and no automatic block. Promote stays a click. We do not change WAF mode from this card.

After DNS is live, the site page reads CloudFront standard metrics for the last hour: Requests and 5xxErrorRate. That is the same CloudWatch GetMetricData call already used for this distribution, in us-east-1, with dimensions DistributionId and Region=Global. Origin latency and per-status rates (401, 403, 404, 502, 503, 504) are additional CloudFront metrics. This product does not turn those on, and the card does not read them.

The card appears when the request-weighted 5xx rate is at least 25% and at least 20 requests were published in minutes that also published a 5xx point, covering at least 80% of requests in that hour. At that floor, while rules are in count, it reads: “Your origin may be returning errors (25% of requests in the last hour were 5xx).” This is the origin responding, not our rules. Rules are in count. Nothing here is blocking. WAF blocks are 403 from the edge, and they only exist after you click Promote. A higher rate uses that sentence with the measured percent.

Next: check that the origin is up. If the site broke when DNS moved, roll the record back.

Minutes without a 5xx point are left out, not counted as zero. If the Requests series or the 5xx series is missing, the card stays hidden and no percent is shown. A published 0% under the threshold also stays hidden. CloudFront metrics lag a few minutes, so the hour is the published points, not the last few seconds.

Standard 5xx mixes an origin that returned 5xx with CloudFront 5xx when the origin could not be reached. The card says the origin may be returning errors and tells you to check that it is up. It does not claim the edge itself is healthy, and it does not split those two causes.

A redirect loop is still not detected. A 403 from the origin is still not detected. 4xxErrorRate is a standard metric and is not used here, because it mixes origin 4xx with WAF 403s after you click Promote. WAF blocks are 403 from the edge. They are not 5xx. While every rule is still in count, the card says nothing here is blocking. If you have already promoted a rule, or saved a block rule, the card does not say that.

Links on the card: Failure states and DNS cutover and rollback.

There is no automatic origin probe and no automatic block. Promote stays a click.

Answers

Does a failed setup block visitors?

No. A failed setup does not switch rules to block, and it does not change DNS.

Do you check that the origin is up before going live?

No. We do not call the origin. After DNS is live, the site page can show a card when CloudFront's standard 5xx rate for the last hour is at least 25% with at least 20 published requests. That card is not a WAF block. A missing series is not shown as zero. A redirect loop and a 403 from the origin are still not detected.

Related guides

More in this section