Comment on page
IP Allow Keeper
IP Allow lists for Keeper network communications
If you have deployed a firewall or zero trust network which restricts end-user network traffic to specific services, you can add Keeper to your AllowList based on FQDN. We recommend using FQDN since some of Keeper's services use dynamic IPs.
Outbound TCP port 443 should be open to your users for the following endpoints, depending on your tenant location.
Global - All Customers
- gitbook.io (documentation portal)
- PLUS.. add additional endpoints listed below.
US Hosted Customers
US / GovCloud Hosted Customers
EU Hosted Customers
AU Hosted Customers
CA / Canada Hosted Customers
JP / Tokyo Hosted Customers
Keeper sends several types of transactional emails.
- If the role enforcement policy is enabled, email invitations are sent to newly provisioned end-users via the Admin Console, Bridge or SCIM methods. The content of the email invites can be customized by the Admin in the console configurations screen.
- Keeper does not send marketing communications or any other product marketing emails to end-users.
- Users with Administrative rights will receive emails related to account status and billing. End-users will not receive account related emails.
- The primary account owner who signs up for Keeper will receive an onboarding email and documentation links, as well as direct communication from a Keeper customer success manager.
- Device verification emails (when logging into a new device) are sent to end-users for authentication purposes.
- Alerts configured by the Keeper Admin in the Advanced Reporting & Alerts application can be optionally sent to end-users, but this is not activated by default.
Keeper's email services are hosted with Amazon SES using dedicated IPs. To ensure that emails from Keeper Security are delivered to users with high success, we recommend ensuring that your mail filters accept email from the below FQDNs and IP Senders. Domains:
For customers who are receiving inbound SIEM events and Automator requests from the Keeper production environment, use the below IP addresses. This only applies to SIEM event reporting and SSO Cloud Automator where Keeper is the originator of the traffic.