---
title: New Relic network traffic
source: https://docs.newrelic.com/docs/new-relic-solutions/get-started/networks
---

> #### ⚠️ IMPORTANT
>
> New Relic has discontinued the use of the following IP ranges: 3.145.244.128/25, 3.77.79.0/25, 3.27.118.128/25, 20.51.136.0/25, 4.197.217.128/25, 18.246.82.0/25, 158.177.65.64/29, 159.122.103.184/29, 161.156.125.32/28. As of May 1, 2025 these ranges may be reallocated by the cloud provider to other customers for purposes out of our control. Please update your network configurations accordingly.

**This list is current. Networks, IPs, domains, ports, and endpoints last updated March 4, 2025.**

This is a list of the networks, IP addresses, domains, ports, and endpoints used by API clients or agents to communicate with New Relic. [TLS is required for all domains](#tls).

> #### 💡 TIP
>
> This doc provides information for ensuring our integrations can access New Relic domains. To monitor the performance of your network, see [Get started with network monitoring](https://docs.newrelic.com/docs/network-performance-monitoring/get-started/npm-introduction).

## TLS encryption [#tls]

To ensure data security for our customers and to be in compliance with [FedRAMP](https://marketplace.fedramp.gov/#/product/new-relic?sort=productName&productNameSearch=new%20relic) and other standards for [data encryption](https://docs.newrelic.com/docs/security/new-relic-security/compliance/data-encryption), all inbound connections for all domains require Transport Layer Security (TLS) 1.2. For more details, see [our Support Forum post about TLS 1.2](https://support.newrelic.com/s/hubtopic/aAX8W0000008dM6WAI/tls-1011-has-been-disabled-for-all-inbound-connections-on-feb-2nd-2023).

For future updates to required and supported protocol versions, follow the [`Security Notifications` tag in New Relic's Support Forum](https://support.newrelic.com/s/hubtopic/Topic__c/Default?c__categories=%5B%7B%22icon%22%3A%22standard%3Adefault%22%2C%22id%22%3A%22a6c8W000000Eet5QAC%22%2C%22sObjectType%22%3A%22Category__c%22%2C%22title%22%3A%22Security%20Notifications%22%2C%22titleFormatted%22%3A%22Security%20Notifications%22%7D%5D).

## New Relic telemetry endpoints [#new-relic-endpoints]

This table contains the endpoints for New Relic telemetry data ingest, and other functionality related to telemetry monitoring. (For an easy-to-copy list of these endpoints, see [Endpoint list](#endpoint-list).)

For more detail on specific agents and integrations, and about ports, keep reading below the table.

Do NOT change these endpoints unless you have the approval of the team that owns the endpoints.

| Capability                                                                                                                                                                                                                                                                                             | US data center endpoint (default)            | EU data center endpoint                                   | Japan data center endpoint                      |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------- | --------------------------------------------------------- | ----------------------------------------------- |
| **APM**                                                                                                                                                                                                                                                                                                |                                              |                                                           |                                                 |
| [APM agent](https://docs.newrelic.com/docs/apm/new-relic-apm/getting-started/introduction-apm/) ingest                                                                                                                                                                                                 | `collector.newrelic.com`                     | `collector.eu.newrelic.com`  `collector.eu01.nr-data.net` | `collector.jp.nr-data.net`                      |
| APM agent ingest, when you [forward logs](https://docs.newrelic.com/docs/logs/logs-context/get-started-logs-context/) through our APM agents                                                                                                                                                           | `log-api.newrelic.com`                       | `collector.eu.newrelic.com`  `collector.eu01.nr-data.net` | `collector.jp.nr-data.net`                      |
| **AWS**                                                                                                                                                                                                                                                                                                |                                              |                                                           |                                                 |
| [AWS Metric Streams](https://docs.newrelic.com/docs/infrastructure/amazon-integrations/connect/aws-metric-stream) ingest                                                                                                                                                                               | `aws-api.newrelic.com`                       | `aws-api.eu.newrelic.com`  `aws-api.eu01.nr-data.net`     | `aws-api.jp.nr-data.net`                        |
| [AWS VPC Flow Logs](https://docs.newrelic.com/docs/infrastructure/amazon-integrations/aws-integrations-list/aws-vpc-monitoring-integration) and [RDS Enhanced](https://docs.newrelic.com/docs/infrastructure/amazon-integrations/aws-integrations-list/aws-rds-enhanced-monitoring-integration) ingest | `cloud-collector.newrelic.com`               | `cloud-collector.eu.newrelic.com`                         | `cloud-collector.jp.nr-data.net`                |
| **Browser**                                                                                                                                                                                                                                                                                            |                                              |                                                           |                                                 |
| [Browser monitoring](https://docs.newrelic.com/docs/browser/browser-monitoring/getting-started/introduction-browser-monitoring) ingest                                                                                                                                                                 | `bam.nr-data.net`  `bam-cell.nr-data.net`    | `bam.eu01.nr-data.net`                                    | `bam.jp.nr-data.net`                            |
| **IAST**                                                                                                                                                                                                                                                                                               |                                              |                                                           |                                                 |
| Validator Service URL  (Requires secure WebSocket connection)                                                                                                                                                                                                                                          | `csec.nr-data.net`                           | `csec.eu01.nr-data.net`                                   | `csec.jp.nr-data.net`                           |
| **Ingest APIs**                                                                                                                                                                                                                                                                                        |                                              |                                                           |                                                 |
| Our [Event API](https://docs.newrelic.com/docs/data-apis/ingest-apis/event-api/introduction-event-api)                                                                                                                                                                                                 | `insights-collector.newrelic.com`            | `insights-collector.eu01.nr-data.net`                     | `insights-collector.jp.nr-data.net`             |
| Our [Log API](https://docs.newrelic.com/docs/logs/log-api/introduction-log-api)                                                                                                                                                                                                                        | `log-api.newrelic.com`                       | `log-api.eu.newrelic.com`                                 | `log-api.jp.nr-data.net`                        |
| Our [Metric API](https://docs.newrelic.com/docs/data-apis/ingest-apis/metric-api/introduction-metric-api)                                                                                                                                                                                              | `metric-api.newrelic.com`                    | `metric-api.eu.newrelic.com`                              | `metric-api.jp.nr-data.net`                     |
| Our [Trace API](https://docs.newrelic.com/docs/distributed-tracing/trace-api/introduction-trace-api)                                                                                                                                                                                                   | `trace-api.newrelic.com`                     | `trace-api.eu.newrelic.com`                               | `trace-api.jp.nr-data.net`                      |
| **Infrastructure**                                                                                                                                                                                                                                                                                     |                                              |                                                           |                                                 |
| [Infrastructure agent](https://docs.newrelic.com/docs/infrastructure/infrastructure-monitoring/get-started/get-started-infrastructure-monitoring) ingest                                                                                                                                               | `infra-api.newrelic.com`                     | `infra-api.eu.newrelic.com`  `infra-api.eu01.nr-data.net` | `infra-api.jp.nr-data.net`                      |
| Infrastructure entity registration                                                                                                                                                                                                                                                                     | `identity-api.newrelic.com`                  | `identity-api.eu.newrelic.com`                            | `identity-api.jp.nr-data.net`                   |
| Infrastructure agent control                                                                                                                                                                                                                                                                           | `infrastructure-command-api.newrelic.com`    | `infrastructure-command-api.eu.newrelic.com`              | `infrastructure-command-api.jp.nr-data.net`     |
| **Agent Control (Fleet Control)**                                                                                                                                                                                                                                                                      |                                              |                                                           |                                                 |
| [Agent Control](https://docs.newrelic.com/docs/new-relic-control/agent-control/overview) OpAMP communication with Fleet Control                                                                                                                                                                        | `opamp.service.newrelic.com`                 | `opamp.service.eu.newrelic.com`                           | `opamp.service.jp.newrelic.com`                 |
| Agent Control OAuth token service (system identity authentication)                                                                                                                                                                                                                                     | `system-identity-oauth.service.newrelic.com` | `system-identity-oauth.service.eu.newrelic.com`           | `system-identity-oauth.service.jp.newrelic.com` |
| **Lookup tables**                                                                                                                                                                                                                                                                                      |                                              |                                                           |                                                 |
| [Lookup table](https://docs.newrelic.com/docs/logs/ui-data/lookup-tables-ui/) upload                                                                                                                                                                                                                   | `nrql-lookup.service.newrelic.com`           | `nrql-lookup.service.eu.newrelic.com`                     | `nrql-lookup.service.jp.newrelic.com`           |
| **Mobile**                                                                                                                                                                                                                                                                                             |                                              |                                                           |                                                 |
| [Mobile agent](https://docs.newrelic.com/docs/mobile-monitoring/new-relic-mobile/get-started/introduction-mobile-monitoring) ingest                                                                                                                                                                    | `mobile-collector.newrelic.com`              | `mobile-collector.eu01.nr-data.net`                       | `mobile-collector.jp.nr-data.net`               |
| [Mobile agent crash report](https://docs.newrelic.com/docs/mobile-monitoring/mobile-monitoring-ui/crashes/investigate-mobile-app-crash-report) ingest                                                                                                                                                  | `mobile-crash.newrelic.com`                  | `mobile-crash.eu01.nr-data.net`                           | `mobile-crash.jp.nr-data.net`                   |
| Symbolication, deobfuscation, and related                                                                                                                                                                                                                                                              | `mobile-symbol-upload.newrelic.com`          | `mobile-symbol-upload.eu01.nr-data.net`                   | `mobile-symbol-upload.jp.nr-data.net`           |
| **OpenTelemetry**                                                                                                                                                                                                                                                                                      |                                              |                                                           |                                                 |
| [OpenTelemetry](https://docs.newrelic.com/docs/more-integrations/open-source-telemetry-integrations/opentelemetry/opentelemetry-introduction) ingest                                                                                                                                                   | `otlp.nr-data.net`                           | `otlp.eu01.nr-data.net`                                   | `otlp.jp.nr-data.net`                           |

### Telemetry endpoints in simple list format [#endpoint-list]

The telemetry endpoints in the table above are included below in easy-to-copy lists:

**US data center endpoints (default)**

Here's a list of the [US data center region](https://docs.newrelic.com/docs/accounts/accounts-billing/account-setup/choose-your-data-center) (default) endpoints included in the endpoint table above in an easy-to-copy list:

Do NOT change these endpoints unless you have the approval of the team that owns the endpoints.

-   `collector.newrelic.com`
-   `aws-api.newrelic.com`
-   `cloud-collector.newrelic.com`
-   `bam.nr-data.net`
-   `bam-cell.nr-data.net`
-   `csec.nr-data.net`
-   `insights-collector.newrelic.com`
-   `log-api.newrelic.com`
-   `metric-api.newrelic.com`
-   `trace-api.newrelic.com`
-   `infra-api.newrelic.com`
-   `identity-api.newrelic.com`
-   `infrastructure-command-api.newrelic.com`
-   `opamp.service.newrelic.com`
-   `system-identity-oauth.service.newrelic.com`
-   `nrql-lookup.service.newrelic.com`
-   `mobile-collector.newrelic.com`
-   `mobile-crash.newrelic.com`
-   `mobile-symbol-upload.newrelic.com`
-   `otlp.nr-data.net`

**EU data center endpoints**

Here's a list of the [EU data center region](https://docs.newrelic.com/docs/accounts/accounts-billing/account-setup/choose-your-data-center) endpoints included in the endpoint table above in an easy-to-copy list:

Do NOT change these endpoints unless you have the approval of the team that owns the endpoints.

-   `collector.eu.newrelic.com`
-   `collector.eu01.nr-data.net`
-   `aws-api.eu.newrelic.com`
-   `aws-api.eu01.nr-data.net`
-   `cloud-collector.eu.newrelic.com`
-   `bam.eu01.nr-data.net`
-   `csec.eu01.nr-data.net`
-   `insights-collector.eu01.nr-data.net`
-   `log-api.eu.newrelic.com`
-   `metric-api.eu.newrelic.com`
-   `trace-api.eu.newrelic.com`
-   `infra-api.eu.newrelic.com`
-   `infra-api.eu01.nr-data.net`
-   `identity-api.eu.newrelic.com`
-   `infrastructure-command-api.eu.newrelic.com`
-   `opamp.service.eu.newrelic.com`
-   `system-identity-oauth.service.eu.newrelic.com`
-   `nrql-lookup.service.eu.newrelic.com`
-   `mobile-collector.eu01.nr-data.net`
-   `mobile-crash.eu01.nr-data.net`
-   `mobile-symbol-upload.eu01.nr-data.net`
-   `otlp.eu01.nr-data.net`

**Japan data center endpoints**

Here's a list of the [Japan data center region](https://docs.newrelic.com/docs/accounts/accounts-billing/account-setup/choose-your-data-center) endpoints included in the endpoint table above in an easy-to-copy list:

Do NOT change these endpoints unless you have the approval of the team that owns the endpoints.

-   `collector.jp.nr-data.net`
-   `aws-api.jp.nr-data.net`
-   `cloud-collector.jp.nr-data.net`
-   `bam.jp.nr-data.net`
-   `csec.jp.nr-data.net`
-   `insights-collector.jp.nr-data.net`
-   `log-api.jp.nr-data.net`
-   `metric-api.jp.nr-data.net`
-   `trace-api.jp.nr-data.net`
-   `infra-api.jp.nr-data.net`
-   `identity-api.jp.nr-data.net`
-   `infrastructure-command-api.jp.nr-data.net`
-   `opamp.service.jp.newrelic.com`
-   `system-identity-oauth.service.jp.newrelic.com`
-   `nrql-lookup.service.jp.newrelic.com`
-   `mobile-collector.jp.nr-data.net`
-   `mobile-crash.jp.nr-data.net`
-   `mobile-symbol-upload.jp.nr-data.net`
-   `otlp.jp.nr-data.net`

### FedRAMP ingest endpoints [#fedramp]

See [FedRAMP endpoints](https://docs.newrelic.com/docs/security/security-privacy/compliance/fedramp-compliant-endpoints).

### Ports [#ports]

For all data ingest applications, with the [exception of OpenTelemetry](#otel-ports), use port 443, a secure channel for encrypted HTTPS traffic and our default.

If you have an existing configuration that uses port 80, we recommend updating it to use 443.

#### OpenTelemetry ports [#otel-ports]

The ports used for `otlp.nr-data.net`, `otlp.eu01.nr-data.net`, and `otlp.jp.nr-data.net` are:

-   443
-   4317 (HTTP/2)
-   4318 (HTTP/1.1)

### Data ingest IP blocks [#ingest-blocks]

Do NOT change these endpoints unless you have the approval of the team that owns the endpoints.

We use these blocks for data ingestion:

-   `162.247.240.0/22`
-   `152.38.128.0/19`
-   `185.221.84.0/22`
-   `212.32.0.0/20`
-   `64.251.192.0/20`

## New Relic telemetry dualstack endpoints [#new-relic-dualstack-endpoints]

JP data center endpoints natively accept both IPv4 and IPv6, so no alternate endpoints are required for JP. For the US and EU data centers, the following dualstack endpoints are available that support both IPv4 and IPv6, and have HTTP/2 and HTTP/3 enabled.

| Capability                                                                                                                                                                                                                                                                                             | US data center endpoint (default)                   | EU data center endpoint                                |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------- | ------------------------------------------------------ |
| **APM**                                                                                                                                                                                                                                                                                                |                                                     |                                                        |
| APM agent ingest                                                                                                                                                                                                                                                                                       | `collector.dualstack.nr-data.net`                   | `collector.dualstack.eu01.nr-data.net`                 |
| **AWS**                                                                                                                                                                                                                                                                                                |                                                     |                                                        |
| [AWS Metric Streams](https://docs.newrelic.com/docs/infrastructure/amazon-integrations/connect/aws-metric-stream) ingest                                                                                                                                                                               | `aws-api.dualstack.nr-data.net`                     | `aws-api.dualstack.eu01.nr-data.net`                   |
| [AWS VPC Flow Logs](https://docs.newrelic.com/docs/infrastructure/amazon-integrations/aws-integrations-list/aws-vpc-monitoring-integration) and [RDS Enhanced](https://docs.newrelic.com/docs/infrastructure/amazon-integrations/aws-integrations-list/aws-rds-enhanced-monitoring-integration) ingest | `cloud-collector.dualstack.nr-data.net`             | `cloud-collector.dualstack.eu01.nr-data.net`           |
| **Browser**                                                                                                                                                                                                                                                                                            |                                                     |                                                        |
| [Browser monitoring](https://docs.newrelic.com/docs/browser/browser-monitoring/getting-started/introduction-browser-monitoring) ingest                                                                                                                                                                 | `bam.dualstack.nr-data.net`                         | `bam.dualstack.eu01.nr-data.net`                       |
| **Ingest APIs**                                                                                                                                                                                                                                                                                        |                                                     |                                                        |
| Our [Event API](https://docs.newrelic.com/docs/data-apis/ingest-apis/event-api/introduction-event-api)                                                                                                                                                                                                 | `insights-collector.dualstack.nr-data.net`          | `insights-collector.dualstack.eu01.nr-data.net`        |
| Our [Log API](https://docs.newrelic.com/docs/logs/log-api/introduction-log-api)                                                                                                                                                                                                                        | `log-api.dualstack.nr-data.net`                     | `log-api.dualstack.eu01.nr-data.net`                   |
| Our [Metric API](https://docs.newrelic.com/docs/data-apis/ingest-apis/metric-api/introduction-metric-api)                                                                                                                                                                                              | `metric-api.dualstack.nr-data.net`                  | `metric-api.dualstack.eu01.nr-data.net`                |
| Our [Trace API](https://docs.newrelic.com/docs/distributed-tracing/trace-api/introduction-trace-api)                                                                                                                                                                                                   | `trace-api.dualstack.nr-data.net`                   | `trace-api.dualstack.eu01.nr-data.net`                 |
| **Infrastructure**                                                                                                                                                                                                                                                                                     |                                                     |                                                        |
| [Infrastructure agent](https://docs.newrelic.com/docs/infrastructure/infrastructure-monitoring/get-started/get-started-infrastructure-monitoring) ingest                                                                                                                                               | `infra-api.dualstack.nr-data.net`                   | `infra-api.dualstack.eu01.nr-data.net`                 |
| Infrastructure entity registration                                                                                                                                                                                                                                                                     | `identity-api.dualstack.newrelic.com`               | `identity-api.dualstack.eu.newrelic.com`               |
| Infrastructure agent control                                                                                                                                                                                                                                                                           | `infrastructure-command-api.dualstack.newrelic.com` | `infrastructure-command-api.dualstack.eu.newrelic.com` |
| **Mobile**                                                                                                                                                                                                                                                                                             |                                                     |                                                        |
| [Mobile agent](https://docs.newrelic.com/docs/mobile-monitoring/new-relic-mobile/get-started/introduction-mobile-monitoring) ingest                                                                                                                                                                    | `mobile-collector.dualstack.nr-data.net`            | `mobile-collector.dualstack.eu01.nr-data.net`          |
| [Mobile agent crash report](https://docs.newrelic.com/docs/mobile-monitoring/mobile-monitoring-ui/crashes/investigate-mobile-app-crash-report) ingest                                                                                                                                                  | `mobile-crash.dualstack.nr-data.net`                | `mobile-crash.dualstack.eu01.nr-data.net`              |
| **OpenTelemetry**                                                                                                                                                                                                                                                                                      |                                                     |                                                        |
| [OpenTelemetry](https://docs.newrelic.com/docs/more-integrations/open-source-telemetry-integrations/opentelemetry/opentelemetry-introduction) ingest                                                                                                                                                   | `otlp.dualstack.nr-data.net`                        | `otlp.dualstack.eu01.nr-data.net`                      |

### Dualstack data ingest IP blocks [#dualstack-ingest-blocks]

We use these blocks for data ingestion:

IPv4

-   US data center endpoints (default): `162.247.240.0/22` and `152.38.128.0/21`
-   EU data center endpoints: `185.221.84.0/22` and `212.32.0.0/21`
-   JP data center endpoints: `64.251.192.0/20`

IPv6

-   US data center endpoints (default): `2602:816:5000::/40` and `2620:16:4000::/48`
-   EU data center endpoints: `2a0d:8000::/29`
-   JP data center endpoints: `2401:7c60::/32`

## User-facing domains [#user-facing-domains]

Your browser must be able to communicate with a number of domains for New Relic to work properly. Update your allow list to ensure New Relic can communicate with a number of integral domains listed in this section. Blocking domains can cause issues with individual product features or prevent pages from loading altogether.

This list doesn't cover domains that New Relic connects to that can be blocked without affecting your usage of the product. It also doesn't cover Nerdpacks or other features that communicate with external services that have additional domain requirements.

If your organization uses a firewall that restricts outbound traffic, follow the specific procedures for the operating system and the firewall you use to add the following domains to the allow list.

| Domain                                                        | Description                                                           |
| ------------------------------------------------------------- | --------------------------------------------------------------------- |
| `\*.newrelic.com`                                             | New Relic and supporting services                                     |
| `\*.nr-assets.net`                                            | Static New Relic assets                                               |
| `\*.nr-ext.net`                                               | New Relic Nerdpacks and assets                                        |
| `secure.gravatar.com`                                         | Support for Gravatar avatars                                          |
| `fonts.googleapis.com`                                        | Support for Google Fonts                                              |
| `fonts.gstatic.com`                                           | Support for Google Fonts                                              |
| `www.google.com`                                              | Support for reCAPTCHA                                                 |
| `www.gstatic.com`                                             | Support for reCAPTCHA                                                 |
| `\*.nr-data.net`                                              | OpenTelemetry and Pixie                                               |
| `onenr.io`                                                    | New Relic sharing permalinks                                          |
| `\*.typescript.azureedge.net`                                 | Synthetics code editor autocompletion functionality                   |
| `nr-synthetics-production.s3.amazonaws.com`                   | Synthetics screenshots, logs, and similar assets (US region, default) |
| `nr-synthetics-production-eu.s3.eu-central-1.amazonaws.com`   | Synthetics screenshots, logs, and similar assets (EU region)          |
| `nr-synthetics-production-jp.s3.ap-northeast-1.amazonaws.com` | Synthetics screenshots, logs, and similar assets (JP region)          |
| `pa-api.newrelic-external.com`                                | New Relic Partner API                                                 |
| `newrelic.github.io`                                          | Public New Relic Github Pages                                         |

## Agent downloads [#agent-download]

[TLS](#tls) is required for all domains. Service for `download.newrelic.com` is provided through CDN and is subject to change without warning.

> #### ⚠️ IMPORTANT
>
> New Relic is updating its IP configuration for agent downloads. Starting April 22, 2025, `download.newrelic.com` will use IP addresses from the block `162.247.240.0/22`. Please update your network settings to accommodate this change.

## Infrastructure details [#infrastructure]

In order to report data to New Relic, our [infrastructure monitoring](https://docs.newrelic.com/docs/infrastructure/new-relic-infrastructure/getting-started/welcome-new-relic-infrastructure) needs outbound access to endpoints in [the endpoints table](#new-relic-endpoints). [TLS](#tls) is required for all domains.

If your system needs a proxy to connect to New Relic, use the [Infrastructure `proxy` setting](https://docs.newrelic.com/docs/infrastructure/new-relic-infrastructure/configuration/configure-infrastructure-agent#proxy).

Our infrastructure monitoring makes use of several other ingest endpoints, including the Metric API endpoint and the Log API endpoint (included in [the endpoint table](#new-relic-endpoints)).

Do NOT change these endpoints unless you have the approval of the team that owns the endpoints.

Details about the non-ingest-related endpoints:

-   `identity-api.newrelic.com` \| `identity-api.eu.newrelic.com` \| `identity-api.jp.nr-data.net`: Required for entity registration (for example, a `host` entity).
-   `infrastructure-command-api.newrelic.com` \| `infrastructure-command-api.eu.newrelic.com` \| `infrastructure-command-api.jp.nr-data.net`: Used by the agent to control aspects of agent behavior (for example, use of feature flags).

## APM agent details [#apm]

To enhance network performance and [data security](https://docs.newrelic.com/docs/security/new-relic-security/data-privacy/new-relic-security-protecting-your-data-content), New Relic uses a CDN and DDoS prevention service with a large IP range. New Relic agents require your firewall to allow outgoing connections to the APM-related endpoints in the [ingest endpoints table](#new-relic-endpoints). To add them to your allow list, follow the specific procedures for the operating system and the firewall you use.

[TLS](#tls) is required for all domains.

## Browser monitoring details [#browser]

In addition to the [endpoints used by our browser monitoring agent and our APM agents](#new-relic-endpoints), applications monitored by our browser agent use outgoing connections to `js-agent.newrelic.com`.

For more information about CDN access for the `js-agent.newrelic.com` file to the domain `bam.nr-data.net` or to one of the New Relic beacons, see [Security for browser monitoring](https://docs.newrelic.com/docs/browser/new-relic-browser/performance-quality/security-new-relic-browser).

[TLS](#tls) is required for all domains.

## Security data endpoints [#security]

See [Security data API](https://docs.newrelic.com/docs/data-apis/ingest-apis/security-data-api).

## Synthetic monitors [#synthetics]

### Public locations [#synthetics-public]

To configure your firewall to allow synthetic monitors to access your monitored URL, use [Synthetic public minion IPs](https://docs.newrelic.com/docs/synthetics/new-relic-synthetics/using-monitors/synthetics-public-minion-ips). [TLS](#tls) is required for all domains.

### Private locations [#synthetics-private]

Synthetic private minions report to a specific endpoint based on region. To allow the private minion to access the endpoint or the static IP addresses associated with the endpoint, follow the specific procedures for the operating system and the firewall you use. These IP addresses may change in the future.

[TLS](#tls) is required for all domains. Use the IP connections for your [data center region](https://docs.newrelic.com/docs/accounts/accounts-billing/account-setup/choose-your-data-center):

Do NOT change these endpoints unless you have the approval of the team that owns the endpoints.

| IP connections | Synthetics private location data                                                                                                                                                                                     |
| -------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Endpoint       | US data center region (default): - `https://synthetics-horde.nr-data.net/` EU data center region: - `https://synthetics-horde.eu01.nr-data.net/` JP data center region: - `https://synthetics-horde.jp.nr-data.net/` |
| IP addresses   | - `162.247.240.0/22` - `152.38.128.0/19` - `185.221.84.0/22` - `212.32.0.0/20` - `64.251.192.0/20`                                                                                                                   |

## Alerts webhooks, api.newrelic.com, cloud integrations, and ticketing integrations [#webhooks]

Endpoints that use `api.newrelic.com` (such as our [NerdGraph API](https://docs.newrelic.com/docs/apis/nerdgraph/get-started/introduction-new-relic-nerdgraph)) and our New Relic-generated [webhooks for alert policies](https://docs.newrelic.com/docs/alerts/get-notified/notification-integrations/#webhook) use an IP address from designated network blocks for the US or [EU region](https://docs.newrelic.com/docs/using-new-relic/welcome-new-relic/get-started/introduction-eu-region-data-center). [TLS is required](#tls) for all addresses in these blocks.

> #### ⚠️ IMPORTANT
>
> New Relic has discontinued the use of the following IP ranges: 3.145.244.128/25, 3.77.79.0/25, 3.27.118.128/25, 20.51.136.0/25, 4.197.217.128/25, 18.246.82.0/25, 158.177.65.64/29, 159.122.103.184/29, 161.156.125.32/28. As of May 1, 2025 these ranges may be reallocated by the cloud provider to other customers for purposes out of our control. Please update your network configurations accordingly.

Network blocks:

-   `162.247.240.0/22`
-   `152.38.128.0/19` (effective June 20, 2024)
-   `185.221.84.0/22`
-   `212.32.0.0/20` (effective June 20, 2024)
-   `64.251.192.0/20` (effective June 20, 2024)

JSON file of New Relic public IP addresses

-   You can automate your allow lists based on this file: [IP range list](https://nr-downloads-main.s3.us-east-1.amazonaws.com/networking/newrelic-ip-ranges.json)

These network blocks also apply to third-party ticketing integrations and [New Relic cloud integrations](https://docs.newrelic.com/docs/integrations/infrastructure-integrations/get-started/introduction-infrastructure-integrations/#cloud-integrations). However, they don't apply to the [Azure Monitor integration](https://docs.newrelic.com/docs/infrastructure/microsoft-azure-integrations/azure-integrations-list/azure-monitor/).

## Pixie integration [#pixie-integration]

The [Pixie integration](https://github.com/newrelic/newrelic-pixie-integration) runs in your Kubernetes cluster and pulls a set of curated observability data from Pixie to send it to New Relic using the OpenTelemetry Protocol (OTLP).

The Pixie integration requires outbound network access to the following:

-   `work.withpixie.ai:443`
-   `withpixie.ai:443`
-   `otlp.nr-data.net:4317` (US data center, default)
-   `otlp.eu01.nr-data.net:4317` (EU data center)

> #### 💡 TIP
>
> If the `4317` port doesn't work, you can use port `443`.

The Pixie community project uses container images hosted in [Google Container Registry](https://cloud.google.com/container-registry). Ensure your cluster can pull images from `gcr.io`.

## CodeStream [#codestream]

New Relic [CodeStream](https://docs.newrelic.com/docs/codestream/start-here/what-is-codestream) is a developer collaboration platform that enables your development team to discuss and review code in a natural and contextual way.

It uses the following domains:

-   `*.newrelic.com`
-   `*.eu.newrelic.com`
-   `*.pubnub.com`
-   `*.pubnub.net`
-   `*.pndsn.com`
-   `*.pubnubapi.com`
