Because of the dynamic nature of cloud environments, Salesforce recommends using mTLS or a domain allowlist as described in Preferred Alternatives to IP Allowlisting on Hyperforce, rather than IP allowlists. For customers who must use IP allowlists, follow these instructions to access Hyperforce outbound IPs, maintain your allowlist, and receive change notifications.
Note: If you make outbound Apex callouts, we still recommend using an IP allowlist because Salesforce outbound IPs may not be registered in DNS under *.salesforce.com.
Hyperforce public IP ranges are available for download in JSON format at:
https://ip-ranges.salesforce.com/ip-ranges.json
This list currently contains the full set of IP addresses for outbound traffic originating from Hyperforce and going to third-party infrastructure, such as customers’ networks. It also includes IPs for inbound traffic to Hyperforce from external sources, including Salesforce Edge IPs. These addresses are for products built on the Salesforce platform, including Sales, Service, Industries, and Tableau Clouds. These addresses are not for email, and not for Marketing Cloud, Commerce Cloud, or Slack. IPs for other traffic patterns such mail traffic may be included in this list in the future.
Some clouds and products publish IPs in separate articles. See the Additional Resources section for links to other IP articles.
NOTE: This information is subject to change, and we recommend that you check back quarterly for the addition of new IP ranges for Salesforce-operated data centers.
As of July 21, 2026, Salesforce relocated all Edge IPs into the Hyperforce Public IP ranges list at https://ip-ranges.salesforce.com/ip-ranges.json. If you previously allowlisted the short-term AWS IP ranges for Hyperforce Edge, you can now retire those IPs. See Remove Short-term AWS IP Ranges for Hyperforce Edge from Allowlists for more info.
As Hyperforce evolves, Salesforce adds and modifies IP addresses in the JSON file at least 30 days before using the IPs.
To ensure optimal performance, availability, and security of your Hyperforce org, it's crucial to update your allowlist promptly when there are changes to the Hyperforce IP address list.
The JSON file categorizes IPs by region and infrastructure provider. At this time, the provider for instances on Hyperforce is AWS. Customers are advised to allow all the IPs in the file. If you only allow the ranges in your country or region, you will block incoming traffic from users in other locations.
When Salesforce updates the IP list, we change the included publication date. To track changes, save successive versions of the JSON file locally, and compare the publication date of the current file with the one you previously saved.
You can subscribe to notifications about IP address updates, so that you can proactively update your network firewall and security configurations. This notification is sent for changes to Sales, Service, and Industries Cloud IPs when IPs in the JSON file are added or changed. Notifications are not yet supported for Tableau Cloud IPs. We recommend that Tableau Cloud customers poll the IP list at least twice in each 30-day period to stay informed of IP changes.
If you are experiencing problems resulting from incorrect IP geolocation data, please contact customer support with the IPs and geolocation database in question.
Note:
Salesforce's strong recommendation remains to use preferred alternatives to IP allowlisting (mTLS, Private Connect, domain allowlisting) due to the dynamic nature of cloud IPs.
If you use other services beyond Hyperforce, you must enable all these other services' IP ranges. This list may not be exhaustive, so be sure to search for all of your specific non-Hyperforce services.
003876184

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.