Override Blocked Domains with a Domain Allow List
Configure a Domain Allow List in a CloudConnexa Shield Policy to ensure specific domains are always accessible, even if a content category blocks them— add domains manually or via .txt upload, search and download the list, and manage Block and Allow List interactions.
Overview
Configure a Domain Allow List per Shield Policy to make specific domains always allowed for users covered by that policy. On the policy's Domain Allow List tab, you can add individual domains or use a .txt file for batch upload.
An allow-listed domain remains always accessible even when its content category is blocked by the policy's Domain Filtering configuration. The Domain Allow List works only while Domain Filtering is on for the policy.
Each Domain Allow List supports up to 150,000 characters.
For more information about how filtering settings apply per policy, refer to About Shield Policies. To determine which User Groups receive the Allow List settings, refer to Assign User Groups to a Shield Policy.
Before you begin
Ensure you have a Shield Policy to configure.
You can configure the Default Policy or a custom Shield Policy. To create a custom policy, refer to Create or Edit a Shield Policy.
Add domains to the Domain Allow List
Add domains directly when you have a small number of entries to configure.
Navigate to Shield → Policies.
Select the Edit policy icon for an existing policy with Domain Filtering turned on.
Select Domain Allow List.
Turn on Enable Allow List.
Enter the domains you want to allow, with one domain per line.
Review the list of domains you want to keep always accessible.
Select Save changes.
The Domain Allow List applies to users covered by the Shield Policy.
Note
Changes may not apply immediately to domains that were previously visited because of local caching.
Upload a Domain Allow List
Use Upload List to perform a batch upload of domains from a .txt file.
Open the Shield Policy and select the Domain Allow List tab.
Turn on Enable allow list, if it isn't already on.
Select Upload List.
Select the
.txtfile containing your Domain Allow List.Important
Upload List replaces the current Domain Allow List. It doesn't append the uploaded domains to the existing list.
Note
The list can contain up to 150,000 characters. Entries must use valid domain formats and ASCII characters.
Review the uploaded domains.
Save your changes.
Add a comment to the Domain Allow List
Use # to add comments to the Domain Allow List. Comments can help identify or organize groups of domains and aren't treated as domain entries.
Open the Shield Policy and select the Domain Allow List tab.
Add
#at the beginning of the line (or useCTRL+on Windows or⌘+/on macOS), followed by your comment. For example:# Corporate applications example.com internal.example.com # Development services dev.example.com
Add or edit the domain entries as needed.
Save your changes.
Tip
You can include comments when you enter domains directly or in a
.txtfile used with Upload List.
Search the Domain Allow List
Use search to find a domain or comment in the current Domain Allow List.
Open the Shield Policy and select the Domain Allow List tab.
Select anywhere inside the Allowed Domains field.
Press
Ctrl+Fon Windows or⌘+Fon macOS.Enter the domain or text you want to find.
Use the search bar arrows to move through matching entries.
Download the Domain Allow List
Use Download List to save a copy of the policy's current Domain Allow List.
Open the Shield Policy and select the Domain Allow List tab.
Select Download List.
allow-list.txtdownloads the current list.
Turn the Domain Allow List on or off
Use Enable allow list to control whether the policy uses its configured Domain Allow List.
Open the Shield Policy and select the Domain Allow List tab.
Turn Enable allow list on or off.
Save your changes.
Turning off Enable allow list retains the configured domains but stops the Allow List from affecting Domain Filtering.
Important
The Domain Allow List works only while Domain Filtering is on. If you turn off Domain Filtering for the Shield Policy, Enable allow list turns off and is disabled.
How Domain Allow List and Block List entries match
The Domain Allow List and Domain Block List use domain name matching to determine whether an entry applies to a domain or its subdomains.
A domain entry applies to that domain and its subdomains. You can create an exception for a specific subdomain by adding it to the opposite list.
Domain name matching examples
Domain Allow List | Domain Block List | Result |
|---|---|---|
| — |
|
|
|
|
— |
|
|
|
|
|
CloudConnexa evaluates domain names from right to left, beginning with the top-level domain (TLD). A more specific subdomain entry on the opposite list overrides the broader parent-domain entry.
How the lists affect Domain Filtering
The Domain Allow List and Domain Block List also take precedence over the policy's content-category settings:
A domain on the Domain Allow List is always allowed, even if its content category is blocked.
A domain on the Domain Block List is always blocked.
Important
Don't add the same domain to both lists. CloudConnexa reports a conflict when an identical domain appears on both the Domain Allow List and Domain Block List. Remove the domain from one list before saving your changes.
Resolve Domain Allow List validation errors
If CloudConnexa reports an error or warning, check the Domain Allow List for:
Invalid domain formats.
Non-ASCII characters.
Duplicate domains.
Domains that are also on the Domain Block List.
A list that exceeds the 150,000-character limit.
Correct the entries, then save your changes.
What happens next
Domains on the enabled Domain Allow List are always allowed for users covered by the Shield Policy, even when the domains belong to content categories that the policy blocks.
To always block a specific domain instead, refer to Domain Block List.
Tip
Changes may not apply immediately to previously visited domains because of local caching.