Whitelisting

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors

Of course security is a big thing, and that's good news. If you find that Tickets or notification emails (Hey -- you have a new Ticket! Hey -- you've been added to a team!) aren't getting to your users, that's not good news.

If that's the case, it's possible that whitelisting will sort out your delivery issue. If you already know what whitelisting is, great. Skip ahead to the details below. In general, for the rest of us: whitelisting lets your firewall know which kinds of messages should be allowed through. Think of your firewall as the bouncer at a really exclusive club. Only those on the list get in -- and you want to be on that list.

Here's what you need to know [or pass along to someone else on your team!]:

The Details: Setting Up Whitelisting

Web Server

If your firewall blocks access to all traffic except for certain domains or IPs, you’ll need to grant access to our domains and IPs as listed below.

Site Domain
*.k12insight.com
*.k12-lets-talk.com
*.k12insightllc.com
*.onflo.com (new)
*.discover-onflo.com (new)
*.email-onflo.com (new)

IP Addresses to Whitelist
52.226.152.64/28
20.62.181.248/29
52.152.191.192
4.255.21.32/28 (new)
52.146.31.128/29 (new)

Mail Server

Certain filters and firewalls may prevent emails from reaching inboxes. This may be the case if you’re not receiving K12 Insight emails. You (or typically IT Department) should add our sender domains and email IP addresses to your list of allowed emails.

Hostnames
*.k12insightllc.com
*.k12-lets-talk.com
*.discover-onflo.com (new)
*.email-onflo.com (new)

IP Addresses to Whitelist
52.226.152.64/28
20.62.181.248/29
4.255.21.32/28 (new)
52.146.31.128/29 (new)
4.246.249.64/28 (new)
13.92.8.112/28 (new)

If you've set up whitelisting and still seem to be having issues, check in with our Client Services team for further investigation.

Frequently Asked Questions

1. What is changing?

We are expanding our infrastructure and introducing new Onflo domains and IP addresses. To ensure uninterrupted access to the platform, email delivery, and integrations, customers should review and update their allowlists/whitelists with the new entries identified as (new) on this page.

2. Why are these changes being made?

These changes are part of our ongoing efforts to improve platform scalability, reliability, performance, and support future product enhancements.

3. When will these changes take effect?

The transition will begin 1st July, 2026. We recommend updating your firewall, email security, and network allowlists as soon as possible to avoid any disruption.

4. Do I need to remove the existing domains and IP addresses?

No. Existing domains and IP addresses should remain whitelisted. The new domains and IP addresses are being added in addition to the current ones.

5. Which new domains should be added?

Please add the following domains to your allowlists:

  • *.onflo.com
  • *.discover-onflo.com
  • *.email-onflo.com

Please refer to the attached document for the complete and most current list.

6. Which new IP addresses should be added?

Please add the following IP ranges to your allowlists:

Web Server

  • 4.255.21.32/28
  • 52.146.31.128/29

Mail Server

  • 4.255.21.32/28
  • 52.146.31.128/29
  • 4.255.21.32/28
  • 52.146.31.128/29
  • 4.246.249.64/28
  • 13.92.8.112/28

7. What happens if we do not update our allowlists?

Failure to whitelist the new domains and IP addresses may result in:

  • Inability to access certain platform services
  • Issues with email delivery
  • Problems with integrations and notifications
  • Potential interruptions as traffic begins utilizing the new infrastructure

8. Will there be any downtime during this transition?

No downtime is expected. The transition is designed to be seamless; however, updating allowlists in advance is strongly recommended.

9. Will email communications be affected?

Email delivery should continue to function normally as long as the new mail server domains and IP addresses are added to your email security and spam filtering systems.

10. Will DKIM settings change as part of this transition?

No. The existing DKIM keys and selectors will remain unchanged. No updates to your DKIM records are required as part of this transition.

11. Are SPF changes required?

No. Emails sent from our platform use domains that maintain their own SPF records, and email authentication continues to rely on DKIM. As a result, no SPF record changes are required on your end for email delivery to continue functioning normally.
Organizations that maintain allowlists at their email gateway may optionally add the following sending domains and IP ranges:

Sending Domains
*.discover-onflo.com
*.email-onflo.com

IP Addresses to Whitelist
4.246.249.64/28
13.92.8.112/28
4.255.21.32/28
52.146.31.128/29
4.246.249.64/28
13.92.8.112/28


12. Do we need to update firewall rules?

Yes. Organizations using firewalls, network filtering, web proxies, or email security gateways should review the attached document and update their rules accordingly.

13. Are there any changes required to integrations or APIs?

In most cases, no application-level changes are required. However, if your organization restricts traffic based on domains or IP addresses, those allowlists should be updated.

14. How can we verify that the changes have been applied successfully?

After updating your allowlists:

  • Verify users can access the platform normally.
  • Confirm emails are being received successfully.
  • Test any integrations that communicate with the platform.
  • Contact our support team if any issues are identified.

15. Who should perform these updates?

Typically, these updates are handled by your:

  • IT Department
  • Network Administrators
  • Security Team
  • Email Administrators

16. What should we do if we continue to experience issues after updating our allowlists?

Please contact our Client Services team and provide:

  • The issue being experienced
  • Date and time of occurrence
  • Screenshots or error messages (if available)
  • Relevant firewall or email logs (if available)

Our team will investigate and assist with resolution.

17. Is any action required if we already allow all outbound and inbound traffic?

If your organization does not restrict traffic based on domains or IP addresses, no action may be required. However, we recommend reviewing the changes with your IT team to confirm.

Related Post

Bulk Edit IT Assets

Build a custom list of assets by searching, pasting, or scanning — then run bulk operations on them Overview Edit Assets lets you assemble an exact list of assets without building filters. You can search for assets one at a

Read More ➜

IT Workflow Enhancements

New triggers, stop-after control, and execution sequencing for Ticket and Asset workflows Overview This release introduces three enhancements to Workflows that give you finer control over when a workflow runs and in what order. You can now target ticket creation

Read More ➜