No reason it can't check any hostname, but all my custom SSL certs are on CloudFront.
You're only cool if you're paying Amazon.
I run almost everything on AWS, but I don't see why this should be a checker at the AWS level when SSL certs are typically exposed for any reader. I would still run it in lambda, but I would check the cert over the public route.