| Your Situation | Recommended Approach |
|---|---|
| New Hyperforce org, no legacy firewall rules | Domain allowlisting + mTLS |
| Existing org migrating from classic instance | Update IP allowlist to Hyperforce JSON + add IPv6 |
| API integrations from your servers to Salesforce | Outbound IP allowlist from JSON file |
| Salesforce calling back to your servers (webhooks, callbacks) | Inbound IP allowlist from JSON file |
| Using Salesforce Edge Network | Domain allowlisting only — IP allowlisting will not work |
| Named Credentials calling external endpoints | Update the external endpoint's allowlist with new Hyperforce outbound IPs |
| Regulated industry requiring IP-based controls | IP allowlist + IPv6 + automate JSON file refresh |
| Government Cloud org (USA-GOV or similar instance prefix) | Contact your Account Executive — standard JSON file does not apply |
Common diagnostic: If connectivity works from your corporate office but fails for remote workers or VPN users, a missing IPv6 allowlist on the proxy or VPN is the most likely cause. Test by temporarily disabling the VPN for an affected user and retesting connectivity directly.
Hyperforce public IP ranges now include inbound address blocks for traffic directed to your Salesforce org. If your security architecture restricts inbound traffic by IP, add the inbound IP blocks from the JSON file.
*.salesforce.com and *.force.com on port 443 (HTTPS)*.my.salesforce.comhttps://ip-ranges.salesforce.com/ip-ranges.jsonNote: This applies to any external system that Salesforce calls outbound — REST APIs, SOAP services, external authentication providers, and event notification endpoints.
https://ip-ranges.salesforce.com/ip-ranges.json. The two most common causes of this failure are: (1) the allowlist was updated with classic instance IPs rather than Hyperforce IPs, and (2) IPv6 addresses were not included. Hyperforce connectivity requires IPv6 in addition to IPv4 — an IPv4-only allowlist will cause intermittent or complete connectivity failures depending on how traffic is routed.USA1xxx, AUS1xxx, DEU1xxx, GBR1xxx, IND1xxx. For the most authoritative confirmation, check the Salesforce Trust site, search for your instance, and confirm its platform is listed as Hyperforce.Note: If you have a custom My Domain and cannot identify your instance name from Setup, go to Setup → My Domain and look at the domain routing details, or contact Salesforce Support to confirm your instance.
*.salesforce.com, *.force.com, *.my.salesforce.com on port 443) or mTLS instead. Attempting to maintain an IP allowlist for Edge Network traffic will result in an incomplete ruleset that breaks whenever Anycast routing changes.
005385560

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.