What are the outbound IP addresses for a FusionAuth Cloud deployment?
-
We want to restrict inbound access to our SMTP server to only allow connections from our FusionAuth Cloud deployment. Our logs show SMTP connections from certain IP addresses we want to confirm.
Questions:
- How can we obtain the complete list of outbound IP addresses for our FusionAuth Cloud deployment?
- Are these IP addresses static, or can they change during upgrades, scaling, maintenance, or region moves?
- Do webhooks and other outbound HTTP calls from the deployment use the same IP addresses as SMTP traffic?
We need this information to properly configure our firewall rules and SMTP server allowlists.
-
For FusionAuth Cloud deployments, you can obtain the outbound IP address list by opening a support ticket in the FusionAuth Account Portal and providing your deployment hostname.
Key facts about FusionAuth Cloud outbound IPs:
-
Complete list: FusionAuth will provide the complete list of outbound IP addresses for your specific deployment. These are the only addresses your deployment will use. Note that IP addresses are not exposed through the user interface—opening a support ticket is the only way to obtain them.
-
Static addresses: The outbound IP addresses are static and will not change during:
- Upgrades
- Maintenance windows
- Normal scaling operations
For new FusionAuth Cloud deployments, static IP addresses are already configured. If the IP addresses ever need to change, FusionAuth will notify you in advance.
-
All outbound traffic: All outbound traffic from your FusionAuth Cloud deployment originates from the same set of IP addresses, including:
- SMTP/email traffic
- Webhooks
- HTTP calls from Lambdas
- Any other outbound connections
You can safely use these IP addresses to configure firewall rules, SMTP server allowlists, and other security restrictions for services that need to accept connections from your FusionAuth Cloud deployment.
Important: The provided IP addresses should only be used to allow outbound traffic through firewalls and network control layers. Do not use them for HTTP/API calls, as they won't respond to such requests. In addition to IP allowlisting, consider using custom headers, TLS transport, and client certificates to further secure outbound traffic.
Related Documentation
- Deployment IP Addresses - Official documentation on obtaining IP addresses for FusionAuth Cloud deployments
- FusionAuth Account Portal - Support - How to access the support portal to request IP addresses
- FusionAuth Cloud Overview - General information about FusionAuth Cloud deployments
-
-
D dan has marked this topic as solved