List of Ports, IP Ranges, and Domains
All connections are outbound and initiated by the test-taker's browser. No inbound firewall rules are required. Unless noted otherwise, traffic is HTTPS / WSS over TCP 443.
If your firewall/proxy supports wildcards, the shortest working allowlist is:
Wildcard | Destination Port(s) | Purpose |
|
| SmarterProctoring app, APIs, session UI, onboarding |
|
| Platform app (session UI, second camera, sign-on, support/help center) |
|
| Media/recording servers and playback |
|
| Live audio/video/screen streaming (WebRTC) |
|
| Real-time data sync |
|
| Remote-control support (Upscope) |
|
| Extension version checks, agreements script, downloads |
|
| In-session calculator |
|
| Chrome Web Store, extension install/updates, fonts |
|
| In-session support chat |
Notes for network administrators
Proxies: Forward proxies must pass WebSockets (WSS) through without inspection. UDP media should bypass the proxy entirely.
SSL inspection: Exclude
*.livekit.cloud,*.twilio.com,*.proctoring.media, and*.upscope.iofrom TLS inspection; TURN-over-TLS and DTLS will fail otherwise.SIP ALG / NGFW: Disable SIP ALG; add explicit allow rules for STUN, TURN and DTLS protocols.
Idle timeouts: WebSocket idle timeout ≥ 300 s for signaling hosts.
Screen sharing and webcam are captured locally via Chrome (
desktopCapture) and streamed to the media hosts above; no other endpoints are involved.This list is subject to change as vendors update their infrastructure (LiveKit and Twilio both publish "subject to change" notices). Re-verify against the vendor links above when reviewing.
Emails
All automated emails come from SendGrid. These will be coming from one of the following domains:
*@smarterservices.com
*@smarterproctoring.com
*@email.smarterservices.com
*@email.smarterproctoring.com