# Domains required for Agent communication **Last Updated On**: 10 Jul 2026 **78 minutes read** ## US Data center (.com) ## Domains required for Agent communication This document provides the list of approved domains and IP addresses which are required for seamless agent-server communication. - [Domain Whitelist](#domain-whitelist-us) - [IP Whitelist](#ip-whitelist-us) ## Domain Whitelist {#domain-whitelist-us} Communication across remote offices is possible in the following ways: - [Endpoint Central domains to be excluded in Roaming agent](#roaming-users-us) - [Endpoint Central domains that should be whitelisted in the domain itself](#distribution-server-us) - [The following domains should be whitelisted in agents that are under the distribution server](#ds-agents-us) ### Endpoint Central domains to be excluded in Roaming agent {#roaming-users-us} Roaming users directly contact the cloud server. Since these users are constantly roaming, they can't be managed by a central server. Therefore, the roaming agents should connect to these websites: #### desktopcentral.manageengine.com This is the server's URL. The roaming agent updates the task status to the cloud server and in order to ensure seamless agent-server communication, the agent has to connect to desktopcentral.manageengine.com. [Check Domain](https://desktopcentral.manageengine.com/) #### (endpointcentral-agent)(p)?[0-9]{1,2}\.manageengine\.com Endpoint Central agents will use these domains to contact Endpoint Central servers. If regex based domain whitelisting is not supported, whitelist the following domains: - **endpointcentral-agent0.manageengine.com** [Check Domain](https://endpointcentral-agent0.manageengine.com/) - **endpointcentral-agent1.manageengine.com** [Check Domain](https://endpointcentral-agent1.manageengine.com/) - **endpointcentral-agent2.manageengine.com** [Check Domain](https://endpointcentral-agent2.manageengine.com/) - **endpointcentral-agent3.manageengine.com** [Check Domain](https://endpointcentral-agent3.manageengine.com/) - **endpointcentral-agent4.manageengine.com** [Check Domain](https://endpointcentral-agent4.manageengine.com/) - **endpointcentral-agentp1.manageengine.com** [Check Domain](https://endpointcentral-agentp1.manageengine.com/) - **endpointcentral-agentp2.manageengine.com** [Check Domain](https://endpointcentral-agentp2.manageengine.com/) - **endpointcentral-agentp3.manageengine.com** [Check Domain](https://endpointcentral-agentp3.manageengine.com/) - **endpointcentral-agentp5.manageengine.com** [Check Domain](https://endpointcentral-agentp5.manageengine.com/) - **endpointcentral-agent5.manageengine.com** [Check Domain](https://endpointcentral-agent5.manageengine.com/) - **endpointcentral-agent6.manageengine.com** [Check Domain](https://endpointcentral-agent6.manageengine.com/) - **endpointcentral-agent7.manageengine.com** [Check Domain](https://endpointcentral-agent7.manageengine.com/) - **endpointcentral-agent8.manageengine.com** [Check Domain](https://endpointcentral-agent8.manageengine.com/) - **endpointcentral-agent9.manageengine.com** [Check Domain](https://endpointcentral-agent9.manageengine.com/) #### bonitas.zohocorp.com This is the cloud server's URL. To upload logs for analysis and troubleshooting, you need to connect to bonitas.zohocorp.com. [Check Domain](https://bonitas.zohocorp.com/) #### us3-dms.zoho.com The roaming agent has to connect to us3-dms.zoho.com to perform on-demand operations. [Check Domain](https://us3-dms.zoho.com/) #### us4-dms.zoho.com The agent should connect to this domain for the user to be able to scan his system immediately. [Check Domain](https://us4-dms.zoho.com/) #### download-accl.zoho.com The agent should connect to download-accl.zoho.com in order to download the manually uploaded packages in Software Deployment module. [Check Domain](https://download-accl.zoho.com/) #### downloads.zohocdn.com The roaming agent should connect to downloads.zohocdn.com in order to download new agent binaries that are required during upgrade process. [Check Domain](https://downloads.zohocdn.com/) #### files-me-accl.zoho.com The agent should connect to files-me-accl.zoho.com in order to download files from server. [Check Domain](https://files-me-accl.zoho.com/) ### Endpoint Central domains that should be whitelisted in the domain itself {#distribution-server-us} Distribution server is a component which allows you to download patch binaries from the respective vendor websites and distribute it to all the remote office computers managed under the DS. The Distribution server should connect to these websites: - desktopcentral.manageengine.com [Check Domain](https://desktopcentral.manageengine.com/) - (endpointcentral-agent)(p)?[0-9]{1,2}\.manageengine\.com (see list above) - bonitas.zohocorp.com [Check Domain](https://bonitas.zohocorp.com/) - us3-dms.zoho.com [Check Domain](https://us3-dms.zoho.com/) - us4-dms.zoho.com [Check Domain](https://us4-dms.zoho.com/) - download-accl.zoho.com [Check Domain](https://download-accl.zoho.com/) - downloads.zohocdn.com [Check Domain](https://downloads.zohocdn.com/) - files-me-accl.zoho.com [Check Domain](https://files-me-accl.zoho.com/) ### Domains to be whitelisted in agents under the Distribution Server {#ds-agents-us} The agents which belong to remote office/WAN should connect to these domains: - desktopcentral.manageengine.com [Check Domain](https://desktopcentral.manageengine.com/) - (endpointcentral-agent)(p)?[0-9]{1,2}\.manageengine\.com (see list above) - us3-dms.zoho.com [Check Domain](https://us3-dms.zoho.com/) - bonitas.zohocorp.com [Check Domain](https://bonitas.zohocorp.com/) - us4-dms.zoho.com [Check Domain](https://us4-dms.zoho.com/) - download-accl.zoho.com [Check Domain](https://download-accl.zoho.com/) - downloads.zohocdn.com [Check Domain](https://downloads.zohocdn.com/) - files-me-accl.zoho.com [Check Domain](https://files-me-accl.zoho.com/) ## IP Whitelist {#ip-whitelist-us} Here's the list of IP addresses that are required to be added to the whitelist. ### US region data centre IP's - `204.141.42.0/23` - 136.143.190.0/23 - 136.143.186.0/23 - 136.143.189.0/24 - 204.141.32.0/23 - 136.143.182.0/23 - 136.143.180.0/23 - 136.143.185.0/24 ### Geo DNS Domains **It is strongly recommended to whitelist the domain instead of whitelisting the IP address as these domains are using GeoDNS, i.e. the IP address of the domains will change based on geolocation of the user.** However, if you still wish to whitelist IP for the domains: Navigate to the command prompt and execute the command: ``` nslookup ``` 1. downloads.zohocdn.com ![“GeoDNS domains](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/administration/us1.webp) 2. download-accl.zoho.com ![“GeoDNS domains](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/administration/us2.webp) 3. files-me-accl.zoho.com ![“GeoDNS domains](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/administration/us3.webp) --- > The same structure (Domain Whitelist and IP Whitelist) applies for the following data centers with region-specific domains and IP ranges: > > - EU Data center (.eu) > - AU Data center (.com.au) > - IN Data center (.in) > - JP Data center (.jp) > - CN Data center (.cn) > - CA Data center (.ca) > - UK Data center (.uk) > - SA Data center (.sa) > > Each region requires whitelisting its respective: > - `desktopcentral.manageengine.` > - `endpointcentral-agent*.` > - Regional DMS domains (e.g., `eu1-dms.zoho.eu`, `au1-dms.zoho.com.au`, etc.) > - Zoho download domains > - Corresponding region-specific IP ranges as listed in the original documentation ## Ports These ports must be enabled for communication between the agent and the server. | Port | Purpose | Type | Connection | |---|---|---|---| | 443 | For communication between the agent or distribution server and the Endpoint Central server.

Source: Agent/Distribution server
Destination: Endpoint Central server | HTTPS | Outbound from Agent/DS | | 443 | The Notification server port is responsible for communicating on-demand operations from the server to the agent.

Source: Agent/Distribution server
Destination: Notification server | WSS | Outbound from Agent/DS | | 8384 | For communication between remote agent and distribution server.

Source: Agent
Destination: Distribution server | HTTPS | Inbound to distribution server
Outbound from Agent/DS |