Loading
Salesforce Enforces New Security Requirements in Summer 2026Read More
Marketing Cloud Engagement
Add Recommended IP Ranges to the Login Allowlist

Add Recommended IP Ranges to the Login Allowlist

Review recommended IP address ranges and quickly add them to your login IP allowlist. Marketing Cloud Engagement tracks the IP addresses of users who log in to your org, and then suggests trusted IP ranges for your allowlist. Instead of entering IP ranges by hand, you review the suggested ranges and add the ones you trust to your allowlist.

Required Editions

Available in: All Marketing Cloud Engagement editions
User Permissions Needed
To add IP ranges to the login IP allowlist: Marketing Cloud Administrator

To accept suggested login IP ranges, log in to your top-level Enterprise business unit. If you log in to a child business unit, you can view suggested ranges, but you can’t add the ranges to the allowlist.

Important
Important Before you enable the login allowlist, review the recommended ranges and confirm with your network team that the ranges are correct for your environment. If you’re logged in with an IP address that isn’t in a configured range and you turn on enforcement, Marketing Cloud Engagement blocks your session.
  1. Log in to the top-level Enterprise business unit.
  2. In Setup, search for and select Login IP Allowlist.
  3. In the Salesforce Recommended IP Ranges section at the bottom of the page, review each recommended range and its login source.

    Each row in the Salesforce Recommended IP Ranges section contains this information.

    • Start IP Address—The first IP address in the recommended range.
    • End IP Address—The last IP address in the recommended range. If the range includes a single address, this value is the same as the Start IP Address.
    • Login Source—The source of the logins for the IP range. Possible values are API Calls, User Interface, or API Calls + User Interface.
  4. Select the checkbox next to each range that you want to add.
  5. Click Accept Selected.
  6. Review the information on the confirmation window, and then click Accept IP Ranges.

A message appears, confirming the number of IP ranges successfully added to the login allowlist. The ranges you accepted move from the Salesforce Recommended IP Ranges section to the Login IP Allowlist table at the top of the page. For each IP range you add this way, the value in the Description column is Recommendation accepted based on tenant traffic patterns.

For best results, after you add suggested IP ranges to the allowlist, configure your account to log allowlist violations without denying access. Observe the log and adjust your allowlist over the next few weeks. When there aren’t any violations from known IP ranges, configure your account to log violations and deny access to IP addresses that aren’t on the allowlist.

 
Loading
Salesforce Help | Article