Skip to main content

Ports and Domain Allow List Requirements

Written by Jason Fill

List of Ports, IP Ranges, and Domains

All connections are outbound and initiated by the test-taker's browser. No inbound firewall rules are required. Unless noted otherwise, traffic is HTTPS / WSS over TCP 443.

If your firewall/proxy supports wildcards, the shortest working allowlist is:

Wildcard

Destination Port(s)

Purpose

  • *.smarterproctoring.com

  • UDP/TCP 80

  • UDP/TCP 443

SmarterProctoring app, APIs, session UI, onboarding

  • *.smarterservices.com

  • UDP/TCP 80

  • UDP/TCP 443

Platform app (session UI, second camera, sign-on, support/help center)

  • *.proctoring.media

  • UDP/TCP 80

  • UDP/TCP 443

Media/recording servers and playback

  • *.livekit.cloud

  • *.turn.livekit.cloud

  • *.host.livekit.cloud

  • UDP/TCP 80

  • UDP/TCP 443

  • UDP/TCP 3478

Live audio/video/screen streaming (WebRTC)

  • *.twilio.com

  • UDP/TCP 80

  • UDP/TCP 443

Real-time data sync

  • *.upscope.io

  • *.upscopeproxy.com

  • UDP/TCP 80

  • UDP/TCP 443

Remote-control support (Upscope)

  • *.amazonaws.com

  • UDP/TCP 80

  • UDP/TCP 443

Extension version checks, agreements script, downloads

  • *.classcalc.com

  • UDP/TCP 80

  • UDP/TCP 443

In-session calculator

  • *.google.com

  • *.googleapis.com

  • *.gstatic.com

  • .googleusercontent.com

  • UDP/TCP 80

  • UDP/TCP 443

Chrome Web Store, extension install/updates, fonts

  • *.intercom.io

  • *.intercomcdn.com

  • intercom.help

  • UDP/TCP 80

  • UDP/TCP 443

In-session support chat

Notes for network administrators

  • Proxies: Forward proxies must pass WebSockets (WSS) through without inspection. UDP media should bypass the proxy entirely.

  • SSL inspection: Exclude *.livekit.cloud, *.twilio.com, *.proctoring.media, and *.upscope.io from TLS inspection; TURN-over-TLS and DTLS will fail otherwise.

  • SIP ALG / NGFW: Disable SIP ALG; add explicit allow rules for STUN, TURN and DTLS protocols.

  • Idle timeouts: WebSocket idle timeout ≥ 300 s for signaling hosts.

  • Screen sharing and webcam are captured locally via Chrome (desktopCapture) and streamed to the media hosts above; no other endpoints are involved.

  • This list is subject to change as vendors update their infrastructure (LiveKit and Twilio both publish "subject to change" notices). Re-verify against the vendor links above when reviewing.

Emails

All automated emails come from SendGrid. These will be coming from one of the following domains:

  • *@smarterservices.com

  • *@smarterproctoring.com

  • *@email.smarterservices.com

  • *@email.smarterproctoring.com

Did this answer your question?