Loading
Prepare for Email to Become the Default Login ExperienceRead More
Secure Your Salesforce Org
Specify Trusted URLs for Redirections

Specify Trusted URLs for Redirections

Help your users access ‌external and cross-org URLs via redirections. Add your trusted URLs to the Trusted URLs for Redirects allowlist. Redirections from Salesforce to URLs in that allowlist are always allowed without a warning.

Required Editions

Available in: all editions
User Permissions Needed
To set up trusted URLs for redirects: Customize Application AND Modify All Data

Determine Valid External URLs for Redirections

To understand where and when this allowlist is used, see External Redirection Restrictions in Salesforce.

To determine the URLs to trust, consider the sites that your users access to perform their daily work. For example, your company website, trusted partners, and tools hosted on the internet. See Identify Cross-Org Urls to Allow for Redirections.

To identify blocked redirections from components and pages that were built in Salesforce Classic, use the Trusted URL and Browser Policy Violations list in Setup. See Manage Trusted URL and Browser Policy Violations.

To get details about blocked redirections, use the Blocked Redirect event type object. The blocked redirect event is free for all customers with a 24-hour data retention period. The event is available in the API but not in the Event Monitoring Analytics app. To collect details for blocked redirections over multiple days, schedule a daily query of the Blocked Redirect event type via REST API.See Blocked Redirect Event Type in Object Reference for the Salesforce Platform.

Warning
Warning To protect your users, we strongly discourage adding top-level Salesforce domains, such as *.salesforce.com, *.force.com or *.file.force.com, to the Trusted URLs for Redirects allowlist.

Update the Trusted URLs for Redirects Allowlist

Redirections from Salesforce to URLs in this allowlist are always allowed without a warning.

  1. From Setup, use the Quick Find box to find and select Trusted URLs for Redirects.
  2. Click New URL.
  3. Enter a valid URL, and save your changes. For example, example.com, *.example.com, and https://example.com. For detailed formatting rules, including how to use wildcards or add Chrome extensions, see Manage Trusted URL and Browser Policy Violations.
    Don't include placeholders or invalid characters, such as malformed^url.example.com and https://{subdomain}.example.com.
 
Loading
Salesforce Help | Article