Skip to content

CNAMEAlreadyExistsException — orphaned CloudFront distribution holding smartcleanerapp.com

0

Account / region: 895512451006 / us-east-1 I'm connecting the custom domain smartcleanerapp.com (apex + www) to Amplify Hosting app d52mtvuk1b629, but every domain association fails with "One or more of the CNAMEs you provided are already associated with a different resource" (CNAMEAlreadyExistsException). I identified the conflict myself with ListConflictingAliases: aliases smartcleanerapp.com and www.smartcleanerapp.com are held by CloudFront distribution ending U7IZHOK in account ending 002710 — which is not my account (mine is 895512451006), it's an Amplify service account. Evidence it's an orphan on your side: the domain is brand new (WHOIS Creation Date 2026-07-10, never previously used); DNS is delegated to my Route 53 zone Z01710401RMS6ODI25VDZ (single zone, no duplicates); the ACM cert validates fine so it's not SSL; there is no CloudFront distribution in my account carrying this alias; and the lock survived repeated association deletes, an 8-hour wait, and a full app delete+recreate. I also attempted the self-service associate-alias move — DNS ownership verification passed, but it's blocked with "Alias move is not allowed since the source distribution is enabled," and I can't disable a distribution in your service account. Request: Please disable/delete the orphaned CloudFront distribution ending U7IZHOK in account ending 002710 (or otherwise release the alternate domain names smartcleanerapp.com and www.smartcleanerapp.com) so I can associate the custom domain to app d52mtvuk1b629 in us-east-1.

1 Answer
0

I understand you're experiencing a CNAMEAlreadyExistsException when trying to associate your custom domain with your Amplify Hosting app, and you've identified that the conflict is with a CloudFront distribution in an AWS service account rather than your own account.

This situation occurs when alternate domain names (CNAMEs) are associated with a CloudFront distribution that Amplify Hosting manages internally. When you see a distribution in an account ending in a different number than yours, this is typically an AWS-managed service account used by Amplify.

For issues where domain associations are blocked by resources in AWS service accounts that you cannot directly access or modify, you'll need to work with AWS Support to resolve the conflict. Since you've already performed thorough troubleshooting (verifying DNS delegation, checking for duplicate zones, attempting the associate-alias API, and recreating your app), the next step is to engage support directly.

Please visit the AWS Support Center at https://console.aws.amazon.com/support/ to create a new support case or add correspondence to your existing case. When you do:

  • Select Amplify Hosting as the service
  • Provide the Amplify app ID, domain names, and the CloudFront distribution ID you identified
  • Include the ListConflictingAliases output showing the conflict
  • Explain that the blocking distribution is in an AWS service account you cannot access

The support team will have the tools to investigate the service account resources and help release the domain names so you can complete your association. Depending on your AWS Support plan, you may receive faster response times with higher-tier plans.

I cannot directly disable or delete resources in AWS service accounts, but AWS Support will be able to assist you with resolving this orphaned distribution issue.

answered a month ago

EXPERT

reviewed a month ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.