Egress
Egress is the volume of data leaving a network, metered per gigabyte in volume-stepped tiers as "data transfer out" (AWS) or "internet egress" (Azure). It is not bandwidth (a rate, not a volume) and not ingress (inbound, listed free). A CDN splits it across two or three separate meters.
Also known as Data transfer out, Internet egress.
Full Explanation
Egress is the volume of data that crosses a network boundary outward. In cloud and CDN billing, it is the meter that counts those bytes. Providers name it data transfer out (AWS) or internet egress (Azure). They price it per gigabyte in volume-stepped tiers, so on a high-volume delivery bill it is normally the largest line. Egress is not bandwidth. Bandwidth is a rate in bits per second. Egress is a quantity of bytes per month. Vendors blur the words: Azure's page is headed "Bandwidth pricing" and Fastly's delivery line item is called "Bandwidth". But what both meter is gigabytes per month, which is egress. It is not ingress either. Ingress is the inbound direction. AWS, Azure ("Data Transfer In | Free") and Cloudflare all list ingress at zero. It is also not one number on one bill. Putting a CDN in front of an origin creates two or three independent egress meters. Different parties own them, and they point in different directions. Reading them apart is the whole skill. An unrelated sense of the word lives in router configuration: egress filtering of source addresses. RFC 3013 section 4.4 defines this, from the ISP's point of view, as filtering applied "from the Internet to the edge site (customer)". It has nothing to do with billing.
How it works
A provider counts the bytes that leave a boundary it owns. It totals them per month and charges the tier that total lands in. Two things move the rate: cumulative monthly volume, and the region the bytes leave from. AWS internet data transfer out of US East (N. Virginia) lists $0.09/GB for the first 10 TB, $0.085 for the next 40 TB, $0.07 for the next 100 TB and $0.05 above 150 TB. Azure internet egress from North America or Europe lists $0.087/GB for the 10 TB after a free 100 GB when routed over its premium global network, and $0.08/GB for the same tier under the transit-ISP routing preference. From South America, the first paid tier is $0.181/GB. Both give the first 100 GB each month free. AWS aggregates that allowance "across all AWS Services and Regions (except China and GovCloud)" rather than granting one per region.
Once a CDN is in the path, the same traffic is metered more than once, by different parties:
- Origin to CDN: a cache miss, a cache fill or an uncacheable response leaves your origin provider. It is billed on that provider's meter. This leg is the one most often made free. CloudFront charges nothing for origin fetches from an AWS origin such as S3, EC2 or Elastic Load Balancing. Azure lists transfer from an Azure origin to Azure Front Door Standard/Premium as free.
- CDN to user: the bytes the edge serves. CloudFront "charges for data transfers out from its edge locations". In the United States, Mexico and Canada, and in Europe, Israel and Türkiye, the first 1 TB per month is free. The next 9 TB is $0.085/GB, falling to $0.020/GB above 5 PB. This is the leg people mean by "CDN egress".
- CDN back to origin: easy to forget and separately priced. CloudFront bills POST and PUT bodies, and client-to-server WebSocket and gRPC traffic, at its data-transfer-out-to-origin rate: $0.020/GB in the United States, Mexico and Canada and in Europe. It bills $0.125/GB from South America and $0.160/GB from India.
So egress is a volume, charged in tiers, on as many meters as there are boundaries the bytes cross. If you can hold only one idea, hold this: the CDN bill and the cloud bill measure different legs of the same request. Cutting one does not cut the other.
Why it matters for a CDN
A CDN changes both where egress is paid and how much of it there is. A CDN's delivery rates are set against its own interconnection footprint: peering at internet exchange points rather than paid transit. That is why edge egress is priced on a different, generally cheaper schedule than the same provider's general internet egress. For example, CloudFront charges $0.085/GB after a free first terabyte, against AWS's $0.09/GB first-10 TB internet rate. But the headline rate is the smaller half of the saving. The larger half is that the origin leg can be zero, and that the edge answers most requests at all, so fewer bytes ever cross the origin boundary. That makes cache hit ratio an egress control, not just a latency one. Every miss, every fill after a purge and every uncacheable response is origin egress you pay for. That is on top of the edge egress you were always going to pay. An origin shield collapses many edge fills into one origin fetch. It applies the same lever to the fills you cannot avoid.
What CDNs do
- AWS CloudFront prices edge egress in per-region tiers: first 1 TB free, next 9 TB at $0.085/GB in the US, Mexico and Canada and in Europe, Israel and Türkiye. It makes AWS-origin fetches free. It discounts for "minimum traffic commits of typically 10 TB/month or higher", or up to 30% through its Security Savings Bundle in exchange for a monthly spend commitment on a one-year term. AWS also waives egress for customers moving all their data off AWS. It invites EU customers to request reduced data transfer rates under the European Data Act.
- Azure lists Data Transfer In as free, Azure-origin-to-Front-Door transfer as free, and internet egress in five volume tiers for each of three source continents. Like AWS, it gives the first 100 GB each month free. It also gives free egress to customers taking all their data off Azure.
- Cloudflare waives egress on R2 object storage: "There are no charges for egress bandwidth for any storage class". It also waives egress on Workers: "There are no additional charges for data transfer (egress) or throughput (bandwidth)." Zero egress is not blanket across the platform, though. Containers egress is priced, at $0.025/GB in North America and Europe after a 1 TB monthly allotment and $0.04 to $0.05 elsewhere. Its Bandwidth Alliance page still describes partners "committed to discounting or waiving data transfer (also known as bandwidth) fees for shared customers". But the page no longer names any, so confirm the offer with the provider instead of planning around it.
- Fastly does publish a per-gigabyte delivery bandwidth table, billed per region per month after 100 GB free. In North America and Europe this is $0.12/GB from 100 GB to 10 TB and $0.08/GB for the next 10 TB. In Asia and Australia it is $0.19/GB then $0.14/GB. In Africa, India and South Korea it is $0.28/GB then $0.24/GB. Its Object Storage offers "direct access to all of your data at the edge with zero egress fees" and charges for storage instead, from $0.02/GB-month.
Watch out for
- A free origin leg is scoped narrowly. CloudFront's free origin fetch covers fetches to CloudFront only. Add a second CDN, such as a multi-CDN setup pulling from the same bucket. AWS then states that "data transfer out from AWS services for all non-origin fetch traffic (such as multi-CDN traffic) to CloudFront will incur their respective regional data transfer out charges". This reintroduces an origin egress bill you thought you had removed.
- Zero-egress storage is provider-scoped. R2's no-egress rate applies to egress direct from R2. Cloudflare warns: "If you connect other metered services to an R2 bucket, you may be charged by those services." Free egress on one provider does nothing for the origin egress of a different provider feeding your CDN.
- The free tier is one allowance, not several. CloudFront's 1 TB per month is the same terabyte as the "First 1TB Free" row in its rate table. It is not an extra one. The page's own worked example bills 1 TB at $0 and only the gigabytes after it at $0.085.
- Read the fine print on "free". Azure lists origin-to-Front-Door as unconditionally free. But origin-to-Azure-CDN carries a footnote: free "in specific cases". Check which of your paths qualifies before you plan around it.
- Region and direction change the price several-fold. Egress from Africa, Asia, Australia, India or South America costs materially more than from North America or Europe on every provider above. Inter-region movement is billed too, and not at one flat rate. Out of N. Virginia, AWS lists $0.01/GB to Ohio, $0.02/GB to most regions and $0.08/GB to Asia Pacific (Thailand). Azure lists $0.02/GB between regions within North America or Europe and $0.05/GB from either to another continent.
Best practice
- Put the origin on a provider that has a free path to your CDN. Examples: CloudFront with an AWS origin, Front Door with an Azure origin, or R2 or Fastly Object Storage behind their own edge. This way, one of the meters reads zero.
- Treat the hit ratio as the egress budget. Long TTLs, cacheable responses and an origin shield reduce the number of times a byte crosses the origin boundary at all. That beats any per-gigabyte negotiation.
- Shrink the bytes themselves. Compression and image optimization cut the edge egress you are billed for and the origin egress on every fill.
- Meter both legs yourself rather than waiting for the invoice: bytes sent per response in your origin logs, and the CDN's own bytes-downloaded metric. A gap between them is your cache doing its job. A gap that closes is a bill arriving.
- Know where your tier boundaries fall. Once volume is predictable, trade it for a committed rate. Do not model egress as a flat per-gigabyte price: no major provider charges one.
Examples
# Estimate monthly egress costs
# AWS S3 → Internet: ~$0.09/GB
# AWS S3 → CloudFront: $0.00/GB (free to CF)
# CloudFront → Internet: ~$0.085/GB (varies by region)
# Check AWS egress with Cost Explorer
aws ce get-cost-and-usage \
--time-period Start=2026-02-01,End=2026-03-01 \
--granularity MONTHLY \
--metrics BlendedCost \
--filter '{"Dimensions":{"Key":"USAGE_TYPE","Values":["DataTransfer-Out-Bytes"]}}'
# Monitor egress with CloudWatch
aws cloudwatch get-metric-statistics \
--namespace AWS/CloudFront \
--metric-name BytesDownloaded \
--period 86400 --statistics Sum \
--start-time 2026-03-01 --end-time 2026-03-15
# Nginx: track egress per response
log_format egress '$remote_addr $body_bytes_sent '
'$upstream_bytes_sent $request_uri';
# Quick egress estimate from access logs
awk '{sum += $2} END {printf "%.2f GB\n", sum/1073741824}' \
/var/log/nginx/access.log
Frequently Asked Questions
Egress is the volume of data leaving a network, metered per gigabyte in volume-stepped tiers as "data transfer out" (AWS) or "internet egress" (Azure). It is not bandwidth (a rate, not a volume) and not ingress (inbound, listed free). A CDN splits it across two or three separate meters.
# Estimate monthly egress costs
# AWS S3 → Internet: ~$0.09/GB
# AWS S3 → CloudFront: $0.00/GB (free to CF)
# CloudFront → Internet: ~$0.085/GB (varies by region)
# Check AWS egress with Cost Explorer
aws ce get-cost-and-usage \
--time-period Start=2026-02-01,End=2026-03-01 \
--granularity MONTHLY \
--metrics BlendedCost \
--filter '{"Dimensions":{"Key":"USAGE_TYPE","Values":["DataTransfer-Out-Bytes"]}}'
# Monitor egress with CloudWatch
aws cloudwatch get-metric-statistics \
--namespace AWS/CloudFront \
--metric-name BytesDownloaded \
--period 86400 --statistics Sum \
--start-time 2026-03-01 --end-time 2026-03-15
# Nginx: track egress per response
log_format egress '$remote_addr $body_bytes_sent '
'$upstream_bytes_sent $request_uri';
# Quick egress estimate from access logs
awk '{sum += $2} END {printf "%.2f GB\n", sum/1073741824}' \
/var/log/nginx/access.log
Yes. Egress is also known as Data transfer out, Internet egress. Egress is the volume of data leaving a network, metered per gigabyte in volume-stepped tiers as "data transfer out" (AWS) or "internet egress" (Azure). It is not bandwidth (a rate, not a volume) and not ingress (inbound, listed free). A CDN splits it across two or three separate meters.
Related CDN concepts include:
- Origin Shield — A cache tier a CDN places between its edge servers and its origin. Cache misses …
- Bandwidth — Bandwidth is the maximum rate a network link can carry data, in bits per second …
- Cache Hit Ratio (CHR) — The share of requests a cache answers from its own stored copies instead of fetching …
- Throughput — Throughput is the rate at which data actually crosses a link in a measured interval …