Loading

Hyperforce IPs to Allow - Sales, Service, Industries, and Tableau Clouds

Udgivelsesdato: Aug 12, 2026
Beskrivelse

Because of the dynamic nature of cloud environments, Salesforce recommends using mTLS or a domain allowlist as described in Preferred Alternatives to IP Allowlisting on Hyperforce, rather than IP allowlists. For customers who must use IP allowlists, follow these instructions to access Hyperforce outbound IPs, maintain your allowlist, and receive change notifications.

Note: If you make outbound Apex callouts, we still recommend using an IP allowlist because Salesforce outbound IPs may not be registered in DNS under *.salesforce.com.

Løsning

Access the IP List

Hyperforce public IP ranges are available for download in JSON format at:

https://ip-ranges.salesforce.com/ip-ranges.json

This list currently contains the full set of IP addresses for outbound traffic originating from Hyperforce and going to third-party infrastructure, such as customers’ networks. It also includes IPs for inbound traffic to Hyperforce from external sources, including Salesforce Edge IPs. These addresses are for products built on the Salesforce platform, including Sales, Service, Industries, and Tableau Clouds. These addresses are not for email, and not for Marketing Cloud, Commerce Cloud, or Slack. IPs for other traffic patterns such mail traffic may be included in this list in the future.

Some clouds and products publish IPs in separate articles. See the Additional Resources section for links to other IP articles.

Hyperforce is available primarily in AWS with IPv4, but there is limited support for AWS with IPv6. There are specific locations where Hyperforce is available on GCP.

NOTE: This information is subject to change, and we recommend that you check back quarterly for the addition of new IP ranges for Salesforce-operated data centers.

 

Short-term Edge IP Ranges

As of July 21, 2026, Salesforce relocated all Edge IPs into the Hyperforce Public IP ranges list at https://ip-ranges.salesforce.com/ip-ranges.json. If you previously allowlisted the short-term AWS IP ranges for Hyperforce Edge, you can now retire 141.163.216.224/28 and 141.163.214.224/28 . These IP ranges no longer need to be polled, allowed or filtered.

 

Lead Time for Updates

As Hyperforce evolves, Salesforce adds and modifies IP addresses in the JSON file at least 30 days before using the IPs.

Maintain Your Allowlist

To ensure optimal performance, availability, and security of your Hyperforce org, it's crucial to update your allowlist promptly when there are changes to the Hyperforce IP address list.

The JSON file categorizes IPs by region and infrastructure provider. At this time, the provider for instances on Hyperforce is AWS. Customers are advised to allow all the IPs in the file. If you only allow the ranges in your country or region, you will block incoming traffic from users in other locations.

When Salesforce updates the IP list, we change the included publication date. To track changes, save successive versions of the JSON file locally, and compare the publication date of the current file with the one you previously saved.

Receive Notifications for IP List Changes for Sales and Service Cloud

You can subscribe to notifications about IP address updates, so that you can proactively update your network firewall and security configurations. This notification is sent for changes to Sales, Service, and Industries Cloud IPs when IPs in the JSON file are added or changed. Notifications are not yet supported for Tableau Cloud IPs. We recommend that Tableau Cloud customers poll the IP list at least twice in each 30-day period to stay informed of IP changes.

  1. Sign Up for Trust Notifications
    1. Follow the instructions in Subscribe to Trust Notifications to sign up for notifications for your instance. If you're unsure of your instance, see View instance information for your Salesforce Organization.
    2. When selecting the services and events that you want to receive notifications about, be sure to find the Core Service row, and select the Maintenance checkbox.
  2. Ongoing
    1. When the IP List changes for your instance, you receive notifications with the subject line "UPCOMING MAINTENANCE - External IP List Update - [Your Region] - Core Service."
    2. Within 30 days of receiving a notification, review the updated IP address list and make necessary adjustments to your network configurations, such as firewall rules and security policies. By taking proactive steps, you can minimize any potential disruptions to your Salesforce services.

IP Geolocation

If you are experiencing problems resulting from incorrect IP geolocation data, please contact customer support with the IPs and geolocation database in question.

 

Note:
Salesforce's strong recommendation remains to use preferred alternatives to IP allowlisting (mTLS, Private Connect, domain allowlisting) due to the dynamic nature of cloud IPs.

Yderligere ressourcer

Allowlist All Non-Hyperforce Services

If you use other services beyond Hyperforce, you must enable all these other services' IP ranges. This list may not be exhaustive, so be sure to search for all of your specific non-Hyperforce services.

 

Vidensartikelnummer

003876184

 
Indlæser
Salesforce Help | Article