NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • Contact Us
English (US)
NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish
  • Home
  • CyberFOX DNS Filtering
  • Network Requirements

IP Addresses, URLs, and Ports to Allowlist

Written by Owen Parry

Updated at May 19th, 2026

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • AutoElevate Knowledgebase
    New to AutoElevate? START HERE General & Troubleshooting Managing Rules Integrations Announcements FAQ Sales & Marketing
  • Password Boss Knowledgebase
    Using Password Boss Administrating Password Boss Legacy Password Boss
  • CyberFOX DNS Filtering
    Getting Started Concepts Network Requirements Company and Location Setup Filtering Policies Roaming Clients Reporting and Logging Troubleshooting
  • Marketing Toolkit
    MSP Marketing & Education Toolkit CyberFOX Brand Guidelines
  • Changelogs for Autoelevate and Password Boss
  • CyberFOX Product Roadmap
  • Current Status
+ More

This article lists the IP addresses, URLs, and ports required for CyberFOX DNS Filtering to operate correctly. The endpoints you need to allowlist depend on your deployment type:

  • Static Locations (router/firewall): DNS Anycast IPs and DNS Forwarding Servers on port 53 UDP, plus the Management Portal on 443 TCP.
  • Roaming Devices (DoH/DoT): DoH Anycast IPs on ports 80, 443, and 853 TCP, plus the DNS Service and Registration/Update service.
  • Roaming Client (Windows agent): All of the above, plus the Roaming Client Loopback Listener on 127.0.0.1:53 UDP.

All endpoints in the table below must be reachable for their respective deployment type. Port usage summary:

  • Ports 80 and 443 — HTTP, HTTPS, and DNS over HTTPS (DoH)
  • Port 53 — Standard DNS (UDP; also TCP for large responses)
  • Port 853 — DNS over TLS (DoT)
Site or service IP Addresses Ports
Management Portal app.cyberfox.com 443 TCP
DNS Service *.dns.cyberfox.com 80,443,853 TCP
DNS Forwarding Servers

166.117.83.181

166.117.241.23

53 UDP/TCP*
DNS Anycast IPs

166.117.75.142

166.117.157.16

53 UDP/TCP*
DOH Anycast IPs

v4

166.117.51.148

166.117.130.22
 

v6
2600:9000:a616:97b7:20fb:d007:db6a:d342 2600:9000:a718:563:adb:7194:368e:4d6e

53 UDP

80,443,853 TCP

Registration / Update service msapidns.cyberfox.com 80,443 TCP
Roaming Client Loopback Listener 127.0.0.1 53 UDP

*DNS uses UDP for most queries but falls back to TCP for responses exceeding 512 bytes, zone transfers, and EDNS0 payloads. Enterprise firewalls with strict rules need TCP 53 open as well.

whitelist ips permitted links trusted sites exempt urls approved addresses

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • Choosing a Deployment Type: Static Locations vs Roaming Devices
  • Configuring DNS for Locations
  • DNS Filtering Troubleshooting Guide
Request a Demo
  • Get Pricing
  • Start Trial
  • Contact
  • Support Center
  • Login
Solutions
AutoElevate
  • AutoElevate Overview
  • Remove Admin Privilege
  • Just-in-Time Admin
  • Blocker
Password Manager
  • Password Manager Overview
  • Features
DNS Filtering
  • DNS Filtering Overview
MSPs
IT Departments
  • Overview
  • State and Local Government
  • K-12 Education
  • Manufacturing
  • Higher Education
Resources
  • Resource Center
  • Group Demos
  • Events
  • The Simple 7™
Company
  • About
  • Leadership
  • Culture & Values
  • News & Press
  • Awards
  • Partnerships
  • Referral Program
  • Trust Center
CyberFox Logo

CALL US (813) 578-8200

© 2025 CYBERFOX LLC ALL RIGHTS RESERVED | Privacy Policy | Terms of Service | Sitemap


Knowledge Base Software powered by Helpjuice

Expand