Allowlisting

Allowlist our monitors

If your target sits behind a firewall or WAF, allow our checks so they aren't blocked or rate-limited. Uptime, TCP and header checks run on Cloudflare's global edge from many locations, so they don't share a single fixed IP. TLS certificate checks always come from one static IP.

HTTP, TCP & header checks

Cloudflare edge

These run from Cloudflare's published IP ranges (many locations, no single address). Allow the full list — Cloudflare keeps it current:

cloudflare.com/ips

TLS certificate checks

Static IP

Certificate expiry and TLS checks always originate from this single IP.

87.99.135.108

User-Agent

Optional

Prefer header-based rules? HTTP checks send this User-Agent. It doesn't cover TCP or header checks, so pair it with the IP rules above for full coverage.

SYNAPSE-Monitor/1.0

For complete coverage

Allow both Cloudflare's ranges and 87.99.135.108. Together they cover every address a monitor can check from. The User-Agent is a tighter, optional alternative for HTTP checks only.